What does code scanning do?
Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?
In a private repository, what minimum requirements does GitHub need to generate a dependencygraph? (Each answer presents part of the solution. Choose two.)
Which patterns are secret scanning validity checks available to?
Which of the following secret scanning features can verify whether a secret is still active?
Which of the following Watch settings could you use to get Dependabot alert notifications? (Each answer presents part of the solution. Choose two.)
Which of the following statements most accurately describes push protection for secret scanning custom patterns?
Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)
Which of the following formats are used to describe a Dependabot alert? (Each answer presents a complete solution. Choose two.)
Why should you dismiss a code scanning alert?