Code security learning paths

Get notifications for vulnerable dependencies

Set up Dependabot to alert you to new vulnerabilities in your dependencies.

开始
Get pull requests to update your vulnerable dependencies

Set up Dependabot to create pull requests when new vulnerabilities are reported.

开始
Keep your dependencies up-to-date

Use Dependabot to check for new releases and create pull requests to update your dependencies.

开始
Scan for secrets

Set up secret scanning to guard against accidental check-ins of tokens, passwords, and other secrets to your repository.

开始
Run code scanning with GitHub Actions

Check your default branch and every pull request to keep vulnerabilities and errors out of your repository.

开始
Run CodeQL code scanning in your CI

Set up CodeQL within your existing CI and upload results to GitHub code scanning.

开始
Integrate with code scanning

Upload code analysis results from third-party systems to GitHub using SARIF.

开始

All Code security guides

此文档对您有帮助吗?隐私政策

帮助我们创建出色的文档!

所有 GitHub 文档都是开源的。看到错误或不清楚的内容了吗?提交拉取请求。

做出贡献

或, 了解如何参与。