Which key is required in the update settings of the Dependabot configuration file?
In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​
What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?​
Which of the following information can be found in a repository's Security tab?
Which of the following Watch settings could you use to get Dependabot alert notifications? (Each answer presents part of the solution. Choose two.)
As a contributor, you discovered a vulnerability in a repository. Where should you look for the instructions on how to report the vulnerability?
What do you need to do before you can define a custom pattern for a repository?​
Where in the repository can you give additional users access to secret scanning alerts?
Which of the following is the best way to prevent developers from adding secrets to the repository?
Which of the following statements most accurately describes push protection for secret scanning custom patterns?​
What YAML syntax do you use to exclude certain files from secret scanning?
Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)​
Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)
Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?