GH-500 Exam Question 11
Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)
GH-500 Exam Question 12
What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?
GH-500 Exam Question 13
Which key is required in the update settings of the Dependabot configuration file?
GH-500 Exam Question 14
Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:
GH-500 Exam Question 15
What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?
