Concepts for security and code quality
Learn core concepts for GitHub's security and code quality features.
- Concepts for secret security, 1 of 5
- Secret leakage risks, 1 of 13
- Secret scanning, 2 of 13
- Push protection, 3 of 13
- Secret security with GitHub, 4 of 13
- About secret scanning alerts, 5 of 13
- Custom patterns, 6 of 13
- Validity checks, 7 of 13
- Delegated bypass for push protection, 8 of 13
- Bypass requests for push protection, 9 of 13
- GitHub secret types, 10 of 13
- Secret scanning push protection metrics, 11 of 13
- Push protection from the command line, 12 of 13
- Working with push protection from the REST API, 13 of 13
- Concepts for code scanning, 2 of 5
- Code scanning, 1 of 11
- Code scanning alerts, 2 of 11
- About setup types for code scanning, 3 of 11
- Integration with code scanning, 4 of 11
- About SARIF files for code scanning, 5 of 11
- Code scanning alert tracking using issues, 6 of 11
- Code scanning merge protection, 7 of 11
- Concepts for CodeQL, 8 of 11
- About the tool status page, 9 of 11
- CodeQL pull request alert metrics, 10 of 11
- Repository properties for code scanning, 11 of 11
- Supply chain security, 3 of 5
- Supply chain security, 1 of 16
- Best practices for maintaining dependencies, 2 of 16
- Dependency graph, 3 of 16
- How the dependency graph recognizes dependencies, 4 of 16
- Dependency review, 5 of 16
- Dependabot alerts, 6 of 16
- Dependabot malware alerts, 7 of 16
- Metrics for Dependabot alerts, 8 of 16
- Dependabot security updates, 9 of 16
- Dependabot version updates, 10 of 16
- Dependabot pull requests, 11 of 16
- Multi-ecosystem updates, 12 of 16
- About the dependabot.yml file, 13 of 16
- Dependabot auto-triage rules, 14 of 16
- Dependabot job logs, 15 of 16
- Immutable releases, 16 of 16
- Concepts for vulnerability reporting and management, 4 of 5
- Concepts for security at scale, 5 of 5