Back to integrations
    SCA

    Dependabot integration

    Get an exploitability verdict for each Dependabot alert, and dismiss the false positives in GitHub with the evidence linked.

    Integration details

    Primary category

    Software Composition Analysis

    Sync direction

    Dependabot ↔ Konvu

    Konvu reads Dependabot alerts through its GitHub App once a day and on demand. Dismissals made in Konvu dismiss the alert in GitHub.

    Status

    Available

    Which Dependabot alerts matter in your code?

    Dependabot raises an alert for every vulnerable version in your manifests, whether or not your code uses the vulnerable part. Konvu reads those alerts through the Konvu GitHub App, checks each one against the repository, and returns a verdict with evidence. When your team dismisses an alert in Konvu, Konvu dismisses it in GitHub with a link back to the evidence.

    Dependabot findings Konvu analyzes

    SCA

    Dependabot alerts

    Vulnerable dependencies in open, fixed, and dismissed states, tied to the manifest file that declares them.

    Not imported today

    • Alerts without a manifest path
    • Dependabot version and security update pull requests

    Access and setup

    Install the Konvu GitHub App on the repositories you want covered and turn on Import SCA issues. Dependabot alerts must be enabled in each repository's security settings.

    To read findings

    • Metadata: read
    • Contents: read
    • Dependabot alerts: read

    To write back

    • Dependabot alerts: write, to dismiss alerts from Konvu
    • An older read-only installation of the app can read alerts but cannot dismiss them

    How Konvu investigates Dependabot findings

    What Konvu receives

    The Dependabot alert: the package, the vulnerable version range, the advisory, and the manifest file.

    What Konvu checks

    • Whether the vulnerable package is installed and shipped, or only used in development and tests.
    • Whether your runtime and configuration match what the vulnerability needs.
    • Whether the vulnerable function is called, and whether input an attacker controls reaches it.

    What decides the verdict

    Konvu returns exploitable, false positive, or inconclusive, with the reasoning behind it: the code it read, the conditions it tested, and what settled the call. When the answer depends on something only your team knows, Konvu asks a question instead of guessing.

    Illustrative example

    A PyYAML alert from Dependabot

    A made-up service, written to show how an investigation reads. Not a customer result.

    1. 1

      Scanner finding

      Dependabot alerts on CVE-2020-14343 in PyYAML 5.3.1, declared in a service's requirements.txt. PyYAML before 5.4 can run arbitrary code when it loads untrusted YAML with full_load or the FullLoader.

    2. 2

      Application context

      The service reads one YAML file at startup: its own configuration.

    3. 3

      Investigation

      Konvu finds every YAML load in the repository. There is one, a yaml.safe_load call on a file path fixed in the code. Nothing calls yaml.load, full_load, or FullLoader.

    4. 4

      Verdict

      False positive. The unsafe loaders are never used, and the one file parsed is not attacker-controlled.

    5. 5

      Evidence

      The installed version, the single safe_load call and its file path, and the search for unsafe loaders.

    6. 6

      Where it ends up

      An engineer dismisses the alert in Konvu. Konvu dismisses it in GitHub with the reason "Vulnerable code not in use" and a comment linking to the evidence.

    Writeback and controls

    What changes in Dependabot

    • Dismissing a finding in Konvu dismisses the Dependabot alert in GitHub, with the reason "Vulnerable code not in use" and a comment linking to the evidence in Konvu.
    • Reopening it in Konvu reopens the alert.

    Who triggers it

    A person. Konvu dismisses an alert only when someone on your team dismisses the finding in Konvu. It does not dismiss alerts on its own.

    What stays with your team

    • Merging or closing Dependabot's own update pull requests.
    • Alert severity in GitHub, which Konvu does not change.

    Evaluation questions

    The technical detail