Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)
A.
It generates a Dependabot alert and displays it on the Security tab for the repository.
B.
It notifies the repository administrators about the new alert.
C.
It generates Dependabot alerts by default for all private repositories.
D.
It consults with a security service and conducts a thorough vulnerability review.
When GitHub identifies a vulnerable dependency in a repository with Dependabot alerts enabled, it performs the following actions:
Generates a Dependabot alert: The alert is displayed on the repository's Security tab, providing details about the vulnerability and affected dependency.
Notifies repository maintainers: By default, GitHub notifies users with write, maintain, or admin permissions about new Dependabot alerts.
GitHub Docs
These actions ensure that responsible parties are informed promptly to address the vulnerability.
[References: GitHub Docs – About Dependabot alerts; Configuring notifications for Dependabot alerts, , , ==========, ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit