Skip to main content
GitHub Docs
All products
Code security
Getting started
GitHub 安全功能
Secure your repository
Secure your organization
Add a security policy
Secret scanning
关于机密扫描
Configure secret scans
Manage secret alerts
机密扫描模式
Code scanning
Scan code automatically
关于代码扫描
关于代码扫描警报
Triage alerts in pull requests
Set up code scanning
Manage alerts
Track alerts in issues
Configure code scanning
Code scanning with CodeQL
Hardware resources for CodeQL
Configure compiled languages
Troubleshoot default setup
Troubleshoot CodeQL workflow
Code scanning in a container
View code scanning logs
Integrate with code scanning
About integration
Upload a SARIF file
SARIF support
Use CodeQL in CI system
Code scanning in your CI
Install CodeQL CLI
Configure CodeQL CLI
Run CodeQL runner
Migrating from the CodeQL runner
Security advisories
Global security advisories
关于 GitHub 公告数据库
关于全局安全公告
Browse Advisory Database
Edit Advisory Database
Repository security advisories
About repository security advisories
Permission levels
Configure private vulnerability reporting
Create repository advisories
Edit repository advisories
Temporary private forks
Publish repository advisories
Add collaborators
Remove collaborators
Withdraw repository advisories
Guidance on reporting and writing
Coordinated disclosure
Best practices
Privately reporting
Manage vulnerability reports
Supply chain security
Understand your supply chain
Supply chain security
Dependency graph
Configure dependency graph
Dependency submission API
Dependency review
Configure dependency review
Explore dependencies
Troubleshoot dependency graph
端到端供应链
Overview
Securing accounts
Securing code
Securing builds
Dependabot
Dependabot alerts
Dependabot alerts
Configure Dependabot alerts
View Dependabot alerts
Configure notifications
Dependabot security updates
Dependabot security updates
Configure security updates
Dependabot version updates
Dependabot version updates
Configure version updates
List configured dependencies
Customize updates
Configure dependabot.yml
Work with Dependabot
Manage Dependabot PRs
Use Dependabot with Actions
Auto-update actions
Manage encrypted secrets
Configure Dependabot to only access private registries
Troubleshoot vulnerability detection
Troubleshoot errors
Security overview
About the security overview
代码安全指南
我们经常发布文档更新,此页面的翻译可能仍在进行中。有关最新信息,请访问
英语文档
。
Code security
/
Dependabot
Free, Pro, & Team
简体中文
搜索 GitHub Docs
GitHub Docs
Code security
/
Dependabot
Code security
Get started
Account and profile
Authentication
Repositories
Enterprise administrators
Billing and payments
Site policy
Organizations
Code security
Pull requests
GitHub Issues
GitHub Actions
GitHub Copilot
GitHub Codespaces
GitHub Packages
Search on GitHub
Developers
REST API
GraphQL API
GitHub CLI
GitHub Discussions
GitHub Sponsors
Building communities
GitHub Pages
Education
GitHub Desktop
GitHub Support
Electron
CodeQL
npm
Free, Pro, & Team
Free, Pro, & Team
Enterprise Cloud
Enterprise Server 3.7
Enterprise Server 3.6
Enterprise Server 3.5
Enterprise Server 3.4
Enterprise Server 3.3
GitHub AE
所有 Enterprise Server 发行版
关于版本
简体中文
English
简体中文
Español
Português do Brasil
Русский
日本語
Français
Deutsch
한국어
搜索 GitHub Docs
使用 Dependabot 确保供应链安全
通过 Dependabot,监视项目中使用的依赖项中的漏洞,并使依赖项保持最新。
使用 Dependabot 警报识别项目依赖项中的漏洞
关于 Dependabot 警报
配置 Dependabot 警报
查看和更新 Dependabot 警报
为 Dependabot 警报配置通知
使用 Dependabot 安全更新自动更新具有已知漏洞的依赖项
关于 Dependabot 安全更新
配置 Dependabot 安全更新
使用 Dependabot 版本更新自动更新依赖项
关于 Dependabot 版本更新
配置 Dependabot 版本更新
列出为版本更新配置的依赖项
自定义依赖项更新
dependabot.yml 文件的配置选项
使用 Dependabot
管理依赖项更新的所有拉取请求
通过 GitHub Actions 自动化 Dependabot
使用 Dependabot 保持操作的最新状态
管理 Dependabot 的加密密码
Configuring Dependabot to only access private registries
漏洞依赖项检测疑难解答
排查 Dependabot 错误