Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?
Where can you use CodeQL analysis for code scanning? (Each answer presents part of the solution. Choose two.)
Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)
What is the first step you should take to fix an alert in secret scanning?
If notification and alert recipients are not customized, which users receive notifications about new Dependabot alerts in an affected repository?
You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?
Which CodeQL query suite provides queries of lower severity than the default query suite?
Which of the following statements best describes secret scanning push protection?
Which of the following formats are used to describe a Dependabot alert? (Each answer presents a complete solution. Choose two.)
You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)
Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)