Automatically assign vulnerabilities

Last updated: June 25, 2026

Use this article when new vulnerabilities should automatically route to a default owner for each repository.

How auto assignment works

  • A repository can have a default assignee.
  • New vulnerabilities in that repository inherit the default assignee.
  • You can still reassign or unassign any vulnerability after it is created.
  • Clearing the default assignee stops automatic routing for future vulnerabilities in that repository.

Where to configure it

  • Open the repository settings for the repository you want to route.
  • Set Default Assignee.
  • Review newly created vulnerabilities to confirm they receive the expected owner.

Important behavior

  • Auto assignment applies only to newly created vulnerabilities.
  • Existing vulnerabilities are not retroactively assigned when the default assignee changes.
  • Manual reassignment still works for individual vulnerabilities.

Canonical docs

For the maintained reference, see Auto assignment, Vulnerability list view, and Vulnerability detail view.

Contact support if

  • New vulnerabilities are not assigned to the configured default assignee.
  • A vulnerability was assigned to an unexpected owner.
  • The repository default assignee cannot be changed or cleared.