You can now dismiss a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls, such as a web application firewall or network policy, mitigate its risk.

The new dismissal reason helps you distinguish mitigated vulnerabilities from alerts marked Won’t fix, align dismissals with formal exception and risk-acceptance processes, and reduce the need to track these decisions outside GitHub.

For more information, see resolving code scanning alerts.