Assuming that notification settings and Dependabot alert recipients have not been customized, which user account setting should you use to get an alert when a vulnerability is detected in one of your repositories?
What should you do after receiving an alert about a dependency added in a pull request?
Which of the following statements best describes secret scanning push protection?​
Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)
What YAML syntax do you use to exclude certain files from secret scanning?
Where can you use CodeQL analysis for code scanning? (Each answer presents part of the solution. Choose two.)
After investigating a code scanning alert related to injection, you determine that the input is properly sanitized using custom logic. What should be your next step?
Which syntax in a query suite tells CodeQL to look for one or more specified .ql files?
Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)
Which key is required in the update settings of the Dependabot configuration file?
Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?