GH-500 Exam Question 11

Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)
  • GH-500 Exam Question 12

    What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?
  • GH-500 Exam Question 13

    Which key is required in the update settings of the Dependabot configuration file?
  • GH-500 Exam Question 14

    Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:
  • GH-500 Exam Question 15

    What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?