GitHub Code scanning 新增“已缓解”警报关闭原因,区分外部缓解与不修复
Code scanning adds a mitigated alert dismissal reason
You can now dismiss a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls, such as a web application firewall or network policy, mitigate its risk.
您现在可以在代码扫描警报中,当漏洞仍存在于代码中,但外部控制(如Web应用防火墙或网络策略)已缓解其风险时,选择“已缓解”作为关闭原因。
The new dismissal reason helps you distinguish mitigated vulnerabilities from alerts marked Won’t fix, align dismissals with formal exception and risk-acceptance processes, and reduce the need to track these decisions outside GitHub.
新的关闭原因有助于您区分已缓解的漏洞与标记为“不修复”的警报,使关闭操作与正式的例外和风险接受流程保持一致,并减少在GitHub之外跟踪这些决策的需求。
For more information, see resolving code scanning alerts.
更多信息,请参阅解决代码扫描警报。
The post Code scanning adds a mitigated alert dismissal reason appeared first on The GitHub Blog.
文章《代码扫描新增“已缓解”警报关闭原因》最初出现在GitHub博客上。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力