Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)
What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?
Which of the following is the best way to prevent developers from adding secrets to the repository?
If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?
Which patterns are secret scanning validity checks available to?
Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)
Which of the following formats are used to describe a Dependabot alert? (Each answer presents a complete solution. Choose two.)
Assuming that no custom Dependabot behavior is configured, who has the ability to merge a pull request created via Dependabot security updates?
Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?
As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?