As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)
on:
pull_request:
branches: [main]
Which of the following formats are used to describe a Dependabot alert? (Each answer presents a complete solution. Choose two.)
What do you need to do before you can define a custom pattern for a repository?
Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?
When does Dependabot alert you of a vulnerability in your software development process?
When configuring code scanning with CodeQL, what are your options for specifying additional queries? (Each answer presents part of the solution. Choose two.)
What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?
If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?