Dependabotアラートの担当者割り当て機能が一般提供開始
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
GitHub Changelog
GitHubが、Dependabotアラートを特定ユーザーに割り当てる機能をリリースした。これにより、チームは依存関係の脆弱性を明確な担当者を設定して効果的に追跡・修正できるようになる。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
特定のユーザーにDependabotアラートを割り当てられるようになりました。アラートの明確な担当者を設定することで、チームが依存関係の脆弱性をより効果的に追跡・修復できます。
仕組み
アラート詳細ページから、リポジトリへの書き込み権限を持つユーザーに、あらゆるDependabotアラートを割り当てられるようになりました。Dependabotアラートにユーザーを割り当てることで、セキュリティ作業を、コードスキャンやシークレットスキャンのアラートで既に使用しているワークフローに統合できます。担当者を設定することで、チームは以下のことが可能になります:
特定の依存関係の脆弱性に対する明確な責任を担える。
GitHub内で直接修復作業を追跡できる。
責任を可視化し実行可能にすることで、修正を迅速化できる。
修復責任が移った際に、担当者を解除または再割り当てできる。
担当者は、アラート詳細ページ、およびリポジトリ、組織、エンタープライズのアラート一覧で確認できます。担当者は監査ログにも表示され、メール通知を受け取ります。
REST APIとウェブフック
REST APIを使用して、Dependabotアラートの担当者をプログラムで表示、割り当て、解除できます。これにより、一括操作やカスタム統合が可能になります。担当者変更のウェブフックイベントを利用すれば、既存のワークフローや自動化にアラート割り当てを組み込めます。
この機能を使用できるユーザー
Dependabotアラートの担当者機能は、github.comでGitHub Advanced Securityをご利用のお客様が使用でき、GitHub Enterprise Serverではバージョン3.22から提供開始されます。
Dependabotアラートの管理とアラートの割り当てについては、ドキュメントで詳しくご確認いただけます。
GitHubコミュニティで議論に参加しましょう。
投稿「Dependabotアラートの担当者割り当て機能が一般提供開始」は、The GitHub Blogで最初に公開されました。
原文を表示
You can now assign Dependabot alerts to specific users, helping your team track and remediate dependency vulnerabilities more effectively by assigning clear ownership of alerts.
How it works
From the alert detail page, you can now assign any Dependabot alert to users who have write access to the repository. Assigning users to Dependabot alerts brings security work into the same workflow you already use for code scanning and secret scanning alerts. With assignees, your team can:
Take clear ownership of specific dependency vulnerabilities.
Track remediation work directly within GitHub.
Accelerate fixes by making responsibility visible and actionable.
Remove and reassign as remediation responsibilities shift.
You can view assignees on alert detail pages and across repository, organization, and enterprise alert lists. Assignees are also visible in the audit log and get email notifications.
REST API and webhooks
You can programmatically view, assign, and unassign users to Dependabot alerts using the REST API, enabling bulk operations and custom integrations. Webhook events for assignee changes let you integrate alert assignment into your existing workflows and automation.
Who can use this feature?
Dependabot alert assignees are available to customers with GitHub Advanced Security on github.com and will be available for GitHub Enterprise Server customers starting with version 3.22.
Learn more about managing Dependabot alerts and assigning alerts in the documentation.
Join the discussion within GitHub Community.
The post Dependabot alert assignees are now generally available appeared first on The GitHub Blog.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み