About notifications for Dependabot alerts
When Dependabot detects vulnerable dependencies in your repositories, we generate a Dependabot alert and display it on the Security tab for the repository. GitHub notifies the maintainers of affected repositories about the new alert according to their notification preferences.
Dependabot doesn't generate Dependabot alerts for malware. For more information, see About the GitHub Advisory database.
Regardless of your notification preferences, when Dependabot is first enabled, GitHub does not send notifications for all vulnerable dependencies found in your repository. Instead, you will receive notifications for new vulnerable dependencies identified after Dependabot is enabled, if your notification preferences allow it.
By default, if your enterprise owner has configured email for notifications on your enterprise, you will receive Dependabot alerts by email.
Enterprise owners can also enable Dependabot alerts without notifications. For more information, see Enabling Dependabot for your enterprise.
Configuring notifications for Dependabot alerts
When a new Dependabot alert is detected, GitHub notifies all users with access to Dependabot alerts for the repository according to their notification preferences. You will receive alerts if you are watching the repository, have enabled notifications for security alerts or for all the activity on the repository, and are not ignoring the repository. For more information, see Configuring notifications.
You can configure notification settings for yourself or your organization from the Manage notifications drop-down shown at the top of each page. For more information, see Configuring notifications.
You can choose the delivery method for notifications, as well as the frequency at which the notifications are sent to you. By default, if your enterprise owner has configured email for notifications on your instance, you will receive Dependabot alerts:
- In your inbox, as web notifications. A web notification is sent when Dependabot is enabled for a repository, when a new manifest file is committed to the repository, and when a new vulnerability with a critical or high severity is found (On GitHub option).
- By email. An email is sent when Dependabot is enabled for a repository, when a new manifest file is committed to the repository, and when a new vulnerability with a critical or high severity is found (Email option).
- On the command line. Warnings are displayed as callbacks when you push to repositories with any insecure dependencies (CLI option).
- On GitHub Mobile, as web notifications. For more information, see Configuring notifications.
Примечание.
The email and web/GitHub Mobile notifications are:
- Per repository when Dependabot is enabled on the repository, or when a new manifest file is committed to the repository.
- Per organization when a new vulnerability is discovered.
- Sent when a new vulnerability is discovered. GitHub doesn't send notifications when vulnerabilities are updated.
You can customize the way you are notified about Dependabot alerts. For example, you can receive a weekly digest email summarizing alerts for up to 10 of your repositories using the Email a digest summary of vulnerabilities and Weekly security email digest options.

Примечание.
You can filter your notifications on GitHub to show Dependabot alerts. For more information, see Managing notifications from your inbox.
Email notifications for Dependabot alerts that affect one or more repositories include the X-GitHub-Severity header field. You can use the value of the X-GitHub-Severity header field to filter email notifications for Dependabot alerts. For more information, see Configuring notifications.
How to reduce the noise from notifications for Dependabot alerts
If you are concerned about receiving too many notifications for Dependabot alerts, we recommend leveraging Dependabot auto-triage rules to auto-dismiss low-risk alerts. Rules are applied before alert notifications are sent, so alerts that are auto-dismissed upon creation do not send notifications. For more information, see About Dependabot auto-triage rules.
Alternatively, you can opt into the weekly email digest, or even completely turn off notifications while keeping Dependabot alerts enabled. You can still navigate to see your Dependabot alerts in your repository's Security tab. For more information, see Viewing and updating Dependabot alerts.