From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 24,700 courses taught by industry experts.
Describe how alerts are generated for vulnerable dependencies - GitHub Tutorial
From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Describe how alerts are generated for vulnerable dependencies
- [Instructor] You'll find that as you read them and become more comfortable with interacting with Dependabot, that the alerts are very robust. There's info on the vulnerable dependency version and its details. In addition, the alerts will provide links to relevant resources for further investigation. Let's get into the demo. All right, let's start our journey here at my timothywarner-org openai-chat internal repository. We know that Security is where we can go to view our alerts. And you can see I've stacked up quite a few, almost a dozen Dependabot alerts that we'll take a look at in just a moment. Over on the Insights page is where your dependency graph formally lives. Again, I'm going to come back here in just a second. I'm just touring it now. One goal I have as your instructor is to help you get familiar with all of these commands up here on the GitHub global toolbar. It'll only make you a more efficient GitHub user. And I know that was immensely satisfying for me when I came to…
Contents
-
-
-
-
-
-
-
Learning objectives27s
-
(Locked)
Define a vulnerability1m 8s
-
(Locked)
Describe Dependabot alerts3m 51s
-
(Locked)
Describe Dependabot security updates2m 37s
-
(Locked)
Define the dependency graph2m 37s
-
(Locked)
Describe how the dependency graph is generated2m
-
(Locked)
Describe how alerts are generated for vulnerable dependencies14m 33s
-
-
-
-
-
-
-
-
-
-
-
-
-