
Summary
The 'GitHub Dependabot Vulnerability Dismissed' rule is designed to alert security teams when vulnerabilities reported by GitHub's Dependabot are dismissed without remediation. It focuses on actions taken in the GitHub Audit log, specifically monitoring for the dismissal of vulnerability alerts. If an alert is dismissed and the corresponding fix is not applied, the rule flags this as a significant security concern, given that unmanaged vulnerabilities can escalate risks within an organization. The rule operates using specific log actions to verify dismissal events, ensuring that a monitoring and response mechanism is in place for security vulnerabilities that remain unaddressed.
Categories
- Web
- Cloud
- Application
Data Sources
- Web Credential
- Application Log
Created: 2024-08-05