From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 25,500 courses taught by industry experts.
Enable Dependabot security updates - GitHub Tutorial
From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Enable Dependabot security updates
- [Instructor] Well, we've been over this ground before a couple times. Dependabot upon does offer that option, at the repo or org level, to have Dependabot automatically open a pull request, called a security update, that bumps one or more versions of your vulnerable dependencies in a codebase. You can also manually review and apply recommended updates before merging the Dependabot pull request. Yeah, just another... You can look at Dependabot as another teammate. Just like if you're familiar with GitHub Copilot and OpenAI's GPT models. OpenAI likes to pose GPT as your own chief of staff, your own personal staff. I like that idea a lot. Another case study, "Enabling Automatic Security Updates at Tailspin Toys." Well, here, Tailspin enables Dependabot's automatic security updates for their drone control software to ensure that ongoing checks for vulnerable dependencies just happens. It's great to be able to schedule these things via Dependabot.yml. And by enabling security updates…
Contents
-
-
-
-
-
-
-
-
-
Learning objectives33s
-
(Locked)
Identify a vulnerable dependency from a Dependabot alert2m 51s
-
(Locked)
Identify vulnerable dependencies from a pull request1m 37s
-
(Locked)
Enable Dependabot security updates1m 21s
-
(Locked)
Remedy a vulnerability from a Dependabot alert in the Security tab51s
-
(Locked)
Remedy a vulnerability from a Dependabot alert in the context of a pull request1m 17s
-
(Locked)
Act on any Dependabot alerts by testing and merging pull requests9m 26s
-
-
-
-
-
-
-
-
-
-
-