You manage code in GitHub and must ensure repository owners are notified if a new vulnerable dependency or malware is detected. What should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure Dependabot alerts..
Why this is the answer
Dependabot alerts automatically scan your repositories for known vulnerabilities in your dependencies and notify repository owners. This directly addresses the requirement to be notified of new vulnerable dependencies. CodeQL scanning actions perform static code analysis to find security vulnerabilities and errors in your own code, not necessarily in third-party dependencies. Branch protection rules enforce policies on branches, like requiring pull request reviews, but don't detect vulnerabilities. Subscribing to the GitHub Advisory Database provides general vulnerability information, but doesn't automatically scan your specific repositories or notify owners about vulnerabilities found within their projects.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed