Skip to content

Vulnerability alerts ​

New advisories are published every day for package versions that were safe when you last scanned. Alerts email you when one affects you.

How they work ​

  1. Every successful dashboard scan and GitHub App scan records the package versions the repository pins, replacing what was recorded for that repository before.
  2. Once a day, dagsec checks all recorded versions against OSV.dev.
  3. For each new critical or high advisory, you get an email listing the repository, the package and version, the advisory, and the version to upgrade to.

Each advisory is reported once per repository. Advisories that the scan itself already reported aren't emailed again. After you upgrade and scan again, only the new versions are watched.

Emails come from alerts@dagsec.net, go to your GitHub account's email address, and link back to the dashboard.

Turn alerts on or off ​

On the Integrations page, under Vulnerability alerts, turn them on or off. Every alert email also has a one-click Stop these emails link that works without signing in.

Alerts need an email address on your GitHub account. If it has none, the Integrations page says so.

What's not included ​

  • Moderate and low advisories.
  • Repositories scanned only through the GitHub Action, GitLab CI or the CLI, which run on your infrastructure and don't send dagsec your package list.