GitHub has updated its code scanning feature to include a specific dismissal reason called “Mitigated.” (Vendor claim) This option is intended for cases where a vulnerability remains in the codebase but is managed by external controls, such as a web application firewall or network policy.
The addition allows security teams to distinguish between vulnerabilities marked as “Won't fix” and those actively managed by infrastructure. (Vendor claim) The changelog states that this update helps align dismissals with formal exception and risk-acceptance processes while reducing the administrative overhead of tracking these decisions outside the GitHub interface.