Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
Discussion options

Starting today, you can now assign users directly to both code scanning and secret scanning alerts. Now available in public preview, assignable alerts empower teams and individuals to:

  • Take direct ownership of specific security issues
  • Track remediation work within GitHub, integrating alert management with regular development tasks
  • Accelerate remediation cycles and developer engagement by making responsibility clear and actionable

Alert assignees are available to customers with GitHub Code Security, GitHub Secret Protection, or GitHub Advanced Security.

Example of assignment on a code scanning alert

Together, these updates move teams from simply finding vulnerabilities to actually fixing them—helping organizations reduce risk and remediate security debt faster, all within GitHub.

You must be logged in to vote

Replies: 6 comments · 9 replies

Comment options

Great feature! It would be useful if the multi-select options in list view would allow bulk assignment and also if the REST API ${BASE_URL}/repos/${ORG}/${REPO}/code-scanning/alerts/${alert.number} would accept assignee in the PATCH payload to allow scripting the assignment of alerts.

You must be logged in to vote
2 replies
@jf205
Comment options

Hi @felsteadd

Thanks for the feedback. API support for updating the alert assignee is very much on our radar. When we have a firm timeline it'll appear on the GitHub public roadmap 👍🏻

@linhhuynh2
Comment options

I was assigned this password but no longer need this. Please remove.

Comment options

This is great! I was sad to see that Copilot wasn't an option to assign to. It would be awesome if I could just assign Copilot a security alert and it could go create a PR to fix it.

You must be logged in to vote
1 reply
@jf205
Comment options

Hi @wreiske

I totally agree that this would be awesome. We are always thinking about ways to make it easier to resolve security alerts and i think this would be a big difference. Definitely something for us to work on!

Comment options

I'd like to be able to filter by assignee using the drop down section...

Here's an alert:
image

Here's an alert with me as an assignee (note that I'd like to be able to filter on assignees other than me as well as alerts without an assignee):
image

Here are some alerts in a repository (for a PR...):
image

It turns out I can filter by using assignee:...
image

And I can exclude using -assignee:...
image

But having to add each and every possible user to a list of -assignee:... would be rather painful. -- I'd much rather be able to select (unassigned) and preferably from a dropdown -- compare the issues filter:
image

You must be logged in to vote
1 reply
@jf205
Comment options

Hi @jsoref

Thanks for the feedback. We'll look into this!

Comment options

Great feature! is there a way for the assignee to receive a notification of the assignment ?

You must be logged in to vote
1 reply
@jf205
Comment options

Hi @cedriclecoz

At the moment only secret scanning alert assignees are notified, but we are going to add notifications for code scanning alert assignees as soon as possible. I hope that helps!

Comment options

It would be super beneficial if there was a way to assign teams also, instead of only one individual.
This would help assignments when working in large orgs.

You must be logged in to vote
4 replies
@jf205
Comment options

Thanks for the feedback @utsav-bhagat. For now, code scanning alerts support up to 10 assignees and secret scanning alerts support a single assignee -- but team assignment is something we are thinking about adding in the future 👍🏻

@jsoref
Comment options

Is that 10 assignees per alert or 10 assignees for all code scanning alerts in a repository?

@jf205
Comment options

@jsoref: it's 10 assignees per code scanning alert

@utsav-bhagat
Comment options

@jf205 sweet, will keep an eye out for the new feature.

Comment options

This is a good feature, with this we can track the alerts directly here without Jira tickets or Issues, but if a developer have assigned multiple alerts and he already submit the alert for review, should be good have in the screen where all the Alerts are listed the status, if the alert is waiting approval or was not submitted yet.
Should be good have an option to stablish a default assignee for all the alerts per repo, we have Repository Owners, in that way we can define per repo who should get assigned automatically for new alerts.
As other mentioned multiple assignees is not working.

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🚀 Shipped A feature has been released 📣 ANNOUNCEMENT Announcements from the GitHub Community team Code Scanning Code scanning: our code analysis features, powered by the CodeQL engine Secret Scanning Detect and prevent the exposure of sensitive information in your code Code Security Build security into your GitHub workflow with features to keep your codebase secure Changelog A discussion post associated with a Changelog post
9 participants
Morty Proxy This is a proxified and sanitized view of the page, visit original site.