Dependabot integration
Get an exploitability verdict for each Dependabot alert, and dismiss the false positives in GitHub with the evidence linked.
Integration details
Primary category
Software Composition Analysis
Sync direction
Dependabot ↔ Konvu
Konvu reads Dependabot alerts through its GitHub App once a day and on demand. Dismissals made in Konvu dismiss the alert in GitHub.
Status
Available
Which Dependabot alerts matter in your code?
Dependabot raises an alert for every vulnerable version in your manifests, whether or not your code uses the vulnerable part. Konvu reads those alerts through the Konvu GitHub App, checks each one against the repository, and returns a verdict with evidence. When your team dismisses an alert in Konvu, Konvu dismisses it in GitHub with a link back to the evidence.
Dependabot findings Konvu analyzes
SCA
Dependabot alerts
Vulnerable dependencies in open, fixed, and dismissed states, tied to the manifest file that declares them.
Not imported today
- Alerts without a manifest path
- Dependabot version and security update pull requests
Access and setup
Install the Konvu GitHub App on the repositories you want covered and turn on Import SCA issues. Dependabot alerts must be enabled in each repository's security settings.
To read findings
Metadata: readContents: readDependabot alerts: read
To write back
Dependabot alerts: write, to dismiss alerts from Konvu- An older read-only installation of the app can read alerts but cannot dismiss them
How Konvu investigates Dependabot findings
What Konvu receives
The Dependabot alert: the package, the vulnerable version range, the advisory, and the manifest file.
What Konvu checks
- Whether the vulnerable package is installed and shipped, or only used in development and tests.
- Whether your runtime and configuration match what the vulnerability needs.
- Whether the vulnerable function is called, and whether input an attacker controls reaches it.
What decides the verdict
Konvu returns exploitable, false positive, or inconclusive, with the reasoning behind it: the code it read, the conditions it tested, and what settled the call. When the answer depends on something only your team knows, Konvu asks a question instead of guessing.
Illustrative example
A PyYAML alert from Dependabot
A made-up service, written to show how an investigation reads. Not a customer result.
- 1
Scanner finding
Dependabot alerts on CVE-2020-14343 in PyYAML 5.3.1, declared in a service's requirements.txt. PyYAML before 5.4 can run arbitrary code when it loads untrusted YAML with full_load or the FullLoader.
- 2
Application context
The service reads one YAML file at startup: its own configuration.
- 3
Investigation
Konvu finds every YAML load in the repository. There is one, a yaml.safe_load call on a file path fixed in the code. Nothing calls yaml.load, full_load, or FullLoader.
- 4
Verdict
False positive. The unsafe loaders are never used, and the one file parsed is not attacker-controlled.
- 5
Evidence
The installed version, the single safe_load call and its file path, and the search for unsafe loaders.
- 6
Where it ends up
An engineer dismisses the alert in Konvu. Konvu dismisses it in GitHub with the reason "Vulnerable code not in use" and a comment linking to the evidence.
Writeback and controls
What changes in Dependabot
- Dismissing a finding in Konvu dismisses the Dependabot alert in GitHub, with the reason "Vulnerable code not in use" and a comment linking to the evidence in Konvu.
- Reopening it in Konvu reopens the alert.
Who triggers it
A person. Konvu dismisses an alert only when someone on your team dismisses the finding in Konvu. It does not dismiss alerts on its own.
What stays with your team
- Merging or closing Dependabot's own update pull requests.
- Alert severity in GitHub, which Konvu does not change.
Evaluation questions
The technical detail
More integrations
View allArnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
Black Duck
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
- SCA
- SAST
Checkmarx
Send Checkmarx One SCA and SAST results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SAST
- SCA
Endor Labs
Add an exploitability verdict with evidence to Endor Labs SCA findings, on top of Endor's own reachability.
- SCA
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
- SAST
- SCA
- Ticketing & Messaging
GitLab
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.
- SCA
- SAST
- Ticketing & Messaging