API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-181 · Security & compliance

GitHub moves older closed Dependabot alerts to archival storage from 25 August

Starting 25 August 2026, GitHub will move closed Dependabot security alerts that have been closed for at least two years to archival storage, removing them from normal UI and API access while retaining administrator CSV export.

GitHubDependabotsecurity alertsdata retentionarchival

Previous state

Closed Dependabot security alerts remained available through the normal GitHub security-alert UI and API without the announced two-year archival boundary.

Current state

Closed Dependabot alerts closed two or more years earlier move to archival storage and leave normal UI and API access, while eligible administrators and security managers can download archived alerts as CSV.

Who needs to care

Organizations and enterprises on github.com, including GitHub Enterprise Cloud, whose audit, remediation or reporting workflows query older closed Dependabot security alerts.

What to do

Before 25 August, identify UI or API workflows that rely on Dependabot alerts closed at least two years ago and prepare to use the downloadable archive for that historical data.

What the source does not prove

Open alerts and alerts closed within two years remain accessible. The policy applies to Dependabot security alerts on github.com, including GitHub Enterprise Cloud, and excludes GitHub Enterprise Server. Archival is not deletion; alert data remains retained subject to the repository, organization, account and enterprise-agreement boundaries stated by GitHub.

Lifecycle history

Dated event sequence

  1. Retention policy announced

    GitHub announced the upcoming archival boundary for older closed Dependabot security alerts.

  2. Archival begins

    Dependabot alerts closed two or more years earlier begin moving out of normal UI and API access into archival storage.

Evidence ledger

First-party sources

  1. 01
    GitHub Changelog — Upcoming cloud data retention policy for closed security alerts

    Official GitHub security changelog · 2026-06-30

    Open official source ↗