Sometimes it's helpful to create issues in your repository that have a 1:1 relationship with dependency vulnerabilities found by Dependabot.
Typically you wouldn't want to do this in a public repository so that bad actors can't exploit it, but for private/internal repositories it's likely OK.
Note that it expects a label called dependabot-vuln