You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?
How would you build your code within the CodeQL analysis workflow? (Each answer presents a complete solution. Choose two.)
Which of the following options are code scanning application programming interface (API) endpoints? (Each answer presents part of the solution. Choose two.)
What should you do after receiving an alert about a dependency added in a pull request?
In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)
You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?
Assuming that notification settings and Dependabot alert recipients have not been customized, which user account setting should you use to get an alert when a vulnerability is detected in one of your repositories?
Which of the following is the best way to prevent developers from adding secrets to the repository?