To be compatible with code scanning, what data format must third-party code scanning tools use for output?
Which alerts do you see in the repository's Security tab? (Each answer presents part of the solution. Choose three.)
Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?
In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)
Which of the following statements best describes secret scanning push protection?
Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:
Where can a user change a repository's code scanning severity threshold that fails a pull request status check?
You want to specify a CodeQL configuration file for a GitHub Actions workflow. Which input to the init step in the CodeQL action do you use to pass the path of the configuration file?
What role is required to change a repository's code scanning severity threshold that fails a pull request status check?
After defining a secret scanning custom pattern, what is the final step before publishing the pattern?
In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?
When does Dependabot alert you of a vulnerability in your software development process?
You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?
Where can you find the vulnerable dependencies that GitHub detected in your repository?
Which of the following is the most complete method for Dependabot to find vulnerabilities in third-party dependencies?
Which organization policy lets organizations choose whether to allow members to view dependency insights?
What should you do after receiving an alert about a dependency added in a pull request?
Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)
As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)
on:
pull_request:
branches: [main]
You are configuring a CodeQL workflow for compiled languages. What happens if your workflow uses a language matrix?