What do you need to do before you can define a custom pattern for a repository?
What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?
What filter or sort settings can be used to prioritize the secret scanning alerts that present the most risk?
When secret scanning detects a set of credentials on a public repository, what does GitHub do?
Assuming that no custom Dependabot behavior is configured, who has the ability to merge a pull request created via Dependabot security updates?
As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?
Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)
Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:
As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?
Which of the following options are code scanning application programming interface (API) endpoints? (Each answer presents part of the solution. Choose two.)
Which syntax in a query suite tells CodeQL to look for one or more specified .ql files?
Which CodeQL query suite provides queries of lower severity than the default query suite?