Hot take; they don't use their security alerts to manage dependency vulnerabilities. Sorry, taking this on a tangent but the security alerts feature as integrated into the product is WAY less usable than other features, such as actions. Just off the top of my head: * No way to assign alerts to people * No free-form comments when dismissing alerts? * Old alerts re-open if a regression introduces the change back.. With…
You're right -- we haven't invested nearly enough in Dependabot Alerts. We're working to change that, starting with some foundational improvements like alert persistence, which shipped in February. (https://github.blog/2022-02-08-improving-developer-experienc...)
After our recent ship, we're in good shape to start addressing some of your concerns, like greater clarity through an alert's lifecycle or comments with dismissal.
Would love to hear any additional feedback. Let me know!