---
title: "Update a Dependabot alert"
method: PATCH
path: "/repos/{owner}/{repo}/dependabot/alerts/{alert_number}"
tags: ["dependabot"]
---

# Update a Dependabot alert

`PATCH /repos/{owner}/{repo}/dependabot/alerts/{alert_number}`

The authenticated user must have access to security alerts for the repository to use this endpoint. For more information, see "[Granting access to security alerts](https://docs.github.com/enterprise-cloud@latest/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-security-and-analysis-settings-for-your-repository#granting-access-to-security-alerts)."

OAuth app tokens and personal access tokens (classic) need the `security_events` scope to use this endpoint. If this endpoint is only used with public repositories, the token can use the `public_repo` scope instead.

## Path parameters

- `owner` string, required
- `repo` string, required
- `alert_number` integer, required — The security alert number.

## Request body

- union
  - object
    - `state` 'dismissed' | 'open', required — The state of the Dependabot alert. A `dismissed_reason` must be provided when setting the state to `dismissed`.
    - `dismissed_reason` 'fix_started' | 'inaccurate' | 'no_bandwidth' | 'not_used' | 'tolerable_risk' — **Required when `state` is `dismissed`.** A reason for dismissing the alert.
    - `dismissed_comment` string — An optional comment associated with dismissing the alert.
    - `assignees` string[] — Usernames to assign to this Dependabot Alert. Pass one or more user logins to _replace_ the set of assignees on this alert. Send an empty array (`[]`) to clear all assignees from the alert. To assign an AI agent, include the bot login (for example, `copilot-swe-agent[bot]`).
    - `agent_assignment` object — Parameters for AI agent assignment. Only used when an agent bot login is included in `assignees`. Ignored when no agent is being assigned.
      - `custom_instructions` string — Custom instructions for the agent.
      - `custom_agent` string — A custom agent identifier.
      - `model` string — The model to use for the agent.
  - object
    - `state` 'dismissed' | 'open' — The state of the Dependabot alert. A `dismissed_reason` must be provided when setting the state to `dismissed`.
    - `dismissed_reason` 'fix_started' | 'inaccurate' | 'no_bandwidth' | 'not_used' | 'tolerable_risk' — **Required when `state` is `dismissed`.** A reason for dismissing the alert.
    - `dismissed_comment` string — An optional comment associated with dismissing the alert.
    - `assignees` string[], required — Usernames to assign to this Dependabot Alert. Pass one or more user logins to _replace_ the set of assignees on this alert. Send an empty array (`[]`) to clear all assignees from the alert. To assign an AI agent, include the bot login (for example, `copilot-swe-agent[bot]`).
    - `agent_assignment` object — Parameters for AI agent assignment. Only used when an agent bot login is included in `assignees`. Ignored when no agent is being assigned.
      - `custom_instructions` string — Custom instructions for the agent.
      - `custom_agent` string — A custom agent identifier.
      - `model` string — The model to use for the agent.

## Response `200`

Response

- DependabotAlert — A Dependabot alert.
  - `number` integer, required — The security alert number.
  - `state` 'auto_dismissed' | 'dismissed' | 'fixed' | 'open', required — The state of the Dependabot alert.
  - `dependency` object, required — Details for the vulnerable dependency.
    - `package` DependabotAlertPackage — Details for the vulnerable package.
      - `ecosystem` string, required — The package's language or package management ecosystem.
      - `name` string, required — The unique package name within its ecosystem.
    - `manifest_path` string — The full path to the dependency manifest file, relative to the root of the repository.
    - `scope` 'development' | 'runtime', nullable — The execution scope of the vulnerable dependency.
    - `relationship` 'unknown' | 'direct' | 'transitive' | 'inconclusive', nullable — The vulnerable dependency's relationship to your project. > [!NOTE] > We are rolling out support for dependency relationship across ecosystems. This value will be "unknown" for all dependencies in unsupported ecosystems.
  - `security_advisory` DependabotAlertSecurityAdvisory, required — Details for the GitHub Security Advisory.
    - `ghsa_id` string, required — The unique GitHub Security Advisory ID assigned to the advisory.
    - `cve_id` string, nullable, required — The unique CVE ID assigned to the advisory.
    - `summary` string, required — A short, plain text summary of the advisory.
    - `description` string, required — A long-form Markdown-supported description of the advisory.
    - `vulnerabilities` DependabotAlertSecurityVulnerability[], required — Vulnerable version range information for the advisory.
      - `package` DependabotAlertPackage, required — Details for the vulnerable package.
        - `ecosystem` string, required — The package's language or package management ecosystem.
        - `name` string, required — The unique package name within its ecosystem.
      - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the vulnerability.
      - `vulnerable_version_range` string, required — Conditions that identify vulnerable versions of this vulnerability's package.
      - `first_patched_version` object, nullable, required — Details pertaining to the package version that patches this vulnerability.
        - `identifier` string, required — The package version that patches this vulnerability.
    - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the advisory.
    - `classification` 'general' | 'malware' — The classification of the advisory.
    - `cvss` object, required — Details for the advisory pertaining to the Common Vulnerability Scoring System.
      - `score` number, required — The overall CVSS score of the advisory.
      - `vector_string` string, nullable, required — The full CVSS vector string for the advisory.
    - `cvss_severities` CvssSeverities, nullable
      - `cvss_v3` object, nullable
        - `vector_string` string, nullable, required — The CVSS 3 vector string.
        - `score` number, nullable, required — The CVSS 3 score.
      - `cvss_v4` object, nullable
        - `vector_string` string, nullable, required — The CVSS 4 vector string.
        - `score` number, nullable, required — The CVSS 4 score.
    - `epss` SecurityAdvisoryEpss, nullable — The EPSS scores as calculated by the [Exploit Prediction Scoring System](https://www.first.org/epss).
      - `percentage` number
      - `percentile` number
    - `cwes` object[], required — Details for the advisory pertaining to Common Weakness Enumeration.
      - `cwe_id` string, required — The unique CWE ID.
      - `name` string, required — The short, plain text name of the CWE.
    - `identifiers` object[], required — Values that identify this advisory among security information sources.
      - `type` 'CVE' | 'GHSA', required — The type of advisory identifier.
      - `value` string, required — The value of the advisory identifer.
    - `references` object[], required — Links to additional advisory information.
      - `url` string, uri, required — The URL of the reference.
    - `published_at` string, date-time, required — The time that the advisory was published in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
    - `updated_at` string, date-time, required — The time that the advisory was last modified in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
    - `withdrawn_at` string, date-time, nullable, required — The time that the advisory was withdrawn in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `security_vulnerability` DependabotAlertSecurityVulnerability, required — Details pertaining to one vulnerable version range for the advisory.
    - `package` DependabotAlertPackage, required — Details for the vulnerable package.
      - `ecosystem` string, required — The package's language or package management ecosystem.
      - `name` string, required — The unique package name within its ecosystem.
    - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the vulnerability.
    - `vulnerable_version_range` string, required — Conditions that identify vulnerable versions of this vulnerability's package.
    - `first_patched_version` object, nullable, required — Details pertaining to the package version that patches this vulnerability.
      - `identifier` string, required — The package version that patches this vulnerability.
  - `url` string, uri, required — The REST API URL of the alert resource.
  - `html_url` string, uri, required — The GitHub URL of the alert resource.
  - `created_at` string, date-time, required — The time that the alert was created in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `updated_at` string, date-time, required — The time that the alert was last updated in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissed_at` string, date-time, nullable, required — The time that the alert was dismissed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissed_by` NullableSimpleUser, nullable, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `dismissed_reason` 'fix_started' | 'inaccurate' | 'no_bandwidth' | 'not_used' | 'tolerable_risk', nullable, required — The reason that the alert was dismissed.
  - `dismissed_comment` string, nullable, required — An optional comment associated with the alert's dismissal.
  - `fixed_at` string, date-time, nullable, required — The time that the alert was no longer detected and was considered fixed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `auto_dismissed_at` string, date-time, nullable — The time that the alert was auto-dismissed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissal_request` DependabotAlertDismissalRequestSimple, nullable — Information about an active dismissal request for this Dependabot alert.
    - `id` integer — The unique identifier of the dismissal request.
    - `status` 'pending' | 'approved' | 'rejected' | 'cancelled' — The current status of the dismissal request.
    - `requester` object — The user who requested the dismissal.
      - `id` integer — The unique identifier of the user.
      - `login` string — The login name of the user.
    - `created_at` string, date-time — The date and time when the dismissal request was created.
    - `url` string, uri — The API URL to get more information about this dismissal request.
  - `assignees` SimpleUser[] — The users assigned to this alert.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string

## Other responses

- `400` — Bad Request
- `403` — Forbidden
- `404` — Resource not found
- `409` — Conflict
- `422` — Validation failed, or the endpoint has been spammed.

---

[API](https://skmtc.net/github/apis/github-v3-rest-api-3.md) · [All operations](https://skmtc.net/github/apis/github-v3-rest-api-3/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/github-v3-rest-api-3/versions/dc0584ac4e13/schema)
