> For the complete documentation index, see [llms.txt](https://docs.nullify.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nullify.ai/configuration/configuration-dependencies.md).

# Dependency Configuration

## Overview

Software Composition Analysis (SCA) covers both **dependencies** and **container** findings. Dependency findings are configured from the Nullify dashboard — there is no checked-in config file. Query them with `GET /sca/dependencies/findings` (and `/detailed`, `/preview`); fetch or update a single finding with `GET,PATCH /sca/dependencies/findings/{findingId}`.

## Autofix

Nullify drafts dependency upgrade pull requests automatically. Autofix is enabled per tenant; its pull request volume is fixed platform behaviour and not configurable:

* **3** open Nullify pull requests per repository at a time.
* **5** new pull requests per remediation plan.

## Pull request gate

Whether a dependency finding can fail CI is controlled from **Configure → Pull Requests** (`PUT /admin/pr-gate-settings`). See [Configuration – General](/configuration/configuration-general.md).

## Ignore findings

Suppress a known advisory or defer remediation by allowlisting the specific finding — per-finding from the dashboard or via the API:

```
POST /sca/dependencies/findings/{findingId}/allowlist
```

Request body:

```json
{
  "allowlistReason": "Library only used in test harnesses",
  "allowlistType": "UserAssumeRisk"
}
```

`allowlistType` is one of `AI`, `UserFixed`, `UserAssumeRisk`, `UserFalsePositive`, or `UserOther`.

Use campaigns to track deferred work and prevent forgotten exceptions. Container hardening findings are configured separately — see [Configuration – Containers](/configuration/configuration-containers.md).
