Can the Dependabot REST API for security alerts return a link to the pull request opened by dependabot? #172989
Replies: 4 comments
-
|
🕒 Discussion Activity Reminder 🕒 This Discussion has been labeled as dormant by an automated system for having no activity in the last 60 days. Please consider one the following actions: 1️⃣ Close as Out of Date: If the topic is no longer relevant, close the Discussion as 2️⃣ Provide More Information: Share additional details or context — or let the community know if you've found a solution on your own. 3️⃣ Mark a Reply as Answer: If your question has been answered by a reply, mark the most helpful reply as the solution. Note: This dormant notification will only apply to Discussions with the Thank you for helping bring this Discussion to a resolution! 💬 |
Beta Was this translation helpful? Give feedback.
-
|
This category doesn't seem to work well for this purpose. I'd suggest using: https://github.com/dependabot/dependabot-core/discussions |
Beta Was this translation helpful? Give feedback.
-
|
🕒 Discussion Activity Reminder 🕒 This Discussion has been labeled as dormant by an automated system for having no activity in the last 60 days. Please consider one the following actions: 1️⃣ Close as Out of Date: If the topic is no longer relevant, close the Discussion as 2️⃣ Provide More Information: Share additional details or context — or let the community know if you've found a solution on your own. 3️⃣ Mark a Reply as Answer: If your question has been answered by a reply, mark the most helpful reply as the solution. Note: This dormant notification will only apply to Discussions with the Thank you for helping bring this Discussion to a resolution! 💬 |
Beta Was this translation helpful? Give feedback.
-
|
I think that this actually exists. I think it's |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Question
Body
Currently, when a Dependabot security alert is created in a repository, the REST API response (reference) does not provide any information about whether a pull request has been opened to address the alert.
However, in the GitHub UI, when viewing a security alert, there is a linked pull request (viewable by clicking "Review security update")

Is there any way to directly map the Dependabot security alert to the pull request? If not, could a field be added?
This feature would benefit anyone building security dashboards, compliance tooling, or CI/CD integrations that need to know when a vulnerability has been automatically addressed by a Dependabot PR.
Beta Was this translation helpful? Give feedback.
All reactions