From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 24,700 courses taught by industry experts.
Explain the role of a developer when they discover a security alert - GitHub Tutorial
From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Explain the role of a developer when they discover a security alert
- [Instructor] All right, so according to GitHub, what is the developer's duty in terms of processing these alerts? Well it's a good idea to read through the alert, and once again, I think you'll agree with me that Dependabot does a pretty nice job of educating the user. Again, you don't have to be a dedicated InfoSec professional because again, I'm filled with cliches, but I think of measure twice, cut once, learning to ride a bicycle, insert the next cliche here. But by reading through the alert, you're then better equipped to avoid this kind of alert from being raised ever again potentially. That's what I'm trying to say. Number two, collaborate with your security team. Open communication, it's easier said than done, isn't it? Especially when you're working for an org with a hundred thousand people and your IT department is a good number of that. But sure, you always want to be on the same page with your team in terms of prioritizing vulnerabilities, making sure you've got…
Contents
-
-
-
-
Learning objectives41s
-
(Locked)
Describe how vulnerable dependencies are identified2m
-
(Locked)
Explain how to act on alerts from GHAS1m 47s
-
(Locked)
Explain the implications of ignoring an alert2m 12s
-
(Locked)
Explain the role of a developer when they discover a security alert2m 2s
-
(Locked)
Describe the differences in access management to view alerts for different security features2m 48s
-
(Locked)
Describe a security policy in a GitHub repository1m 2s
-
(Locked)
Identify where to use Dependabot alerts in the software development lifecycle25m 49s
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-