Skip to main content
GitHub Docs
All products
代码安全
入门
GitHub 安全功能
Secure your repository
Secure your organization
Add a security policy
机密扫描
关于机密扫描
Configure secret scans
Manage secret alerts
机密扫描模式
代码扫描
Scan code automatically
关于代码扫描
关于代码扫描警报
Triage alerts in pull requests
配置代码扫描
管理警报
跟踪问题中的警报
Customize code scanning
Code scanning with CodeQL
Hardware resources for CodeQL
Configure compiled languages
Troubleshoot default setup
Troubleshoot advanced setup
容器中的 Code scanning
View code scanning logs
与代码扫描集成
About integration
Upload a SARIF file
SARIF support
使用 CodeQL CLI
About the CodeQL CLI
Getting started
Creating CodeQL databases
Extractor options
Analyzing databases
Using custom queries with the CodeQL CLI
Creating CodeQL query suites
Testing custom queries
Testing query help files
Creating and working with CodeQL packs
Publishing and using CodeQL packs
Specifying command options in a CodeQL configuration file
CodeQL CLI 参考
About CodeQL packs
About CodeQL workspaces
Query reference files
CodeQL CLI SARIF output
Exit codes
Use CodeQL in CI system
Code scanning in your CI
Install CodeQL CLI
Configure CodeQL CLI
Run CodeQL runner
Migrating from the CodeQL runner
安全通知
Global security advisories
关于 GitHub 公告数据库
关于全局安全公告
Browse Advisory Database
Edit Advisory Database
Repository security advisories
关于存储库安全公告
权限级别
Configure private vulnerability reporting
Create repository advisories
Edit repository advisories
Temporary private forks
Publish repository advisories
Add collaborators
Remove collaborators
Withdraw repository advisories
Guidance on reporting and writing
Coordinated disclosure
最佳实践
Privately reporting
Manage vulnerability reports
Supply chain security
Understand your supply chain
Supply chain security
Dependency graph
Configure dependency graph
Dependency submission API
依赖项检查
Configure dependency review
Explore dependencies
Troubleshoot dependency graph
端到端供应链
概述
Securing accounts
Securing code
Securing builds
Dependabot
Dependabot 警报
Dependabot 警报
Configure Dependabot alerts
View Dependabot alerts
配置通知
Dependabot 安全更新
Dependabot 安全更新
Configure security updates
Dependabot version updates
Dependabot version updates
Configure version updates
List configured dependencies
Customize updates
Configure dependabot.yml
Work with Dependabot
Manage Dependabot PRs
Use Dependabot with Actions
Auto-update actions
管理加密的机密
Configure Dependabot to only access private registries
Troubleshoot vulnerability detection
排查错误
安全概述
关于安全性概述
代码安全指南
We publish frequent updates to our documentation, and translation of this page may still be in progress. For the most current information, please visit the
English documentation
.
代码安全
/
安全通知
Free, Pro, & Team
简体中文
Search GitHub Docs
GitHub Docs
代码安全
/
安全通知
Code security
Get started
Account and profile
Authentication
Repositories
Enterprise administrators
Billing and payments
Site policy
Organizations
Code security
Pull requests
GitHub Issues
GitHub Actions
GitHub Copilot
GitHub Codespaces
GitHub Packages
Search on GitHub
Developers
REST API
GraphQL API
GitHub CLI
GitHub Discussions
GitHub Sponsors
Building communities
GitHub Pages
Education
GitHub Desktop
GitHub Support
Electron
CodeQL
npm
Free, Pro, & Team
Free, Pro, & Team
Enterprise Cloud
Enterprise Server 3.7
Enterprise Server 3.6
Enterprise Server 3.5
Enterprise Server 3.4
Enterprise Server 3.3
GitHub AE
All Enterprise Server releases
About versions
简体中文
English
简体中文
Español
Português do Brasil
Русский
日本語
Français
Deutsch
한국어
Search GitHub Docs
使用安全公告
了解如何在 GitHub, 上使用安全公告,无论是想要为现有的全局公告做出贡献,还是创建存储库安全公告,这样做都可以改进存储库维护人员和安全研究者之间的协作。
使用 GitHub 公告数据库中的全局安全公告
关于 GitHub 公告数据库
关于全局安全公告
在 GitHub Advisory Database 中浏览安全公告
在 GitHub Advisory Database 中编辑安全公告
使用存储库安全公告
关于存储库安全公告
存储库安全公告的权限级别
为存储库配置私人漏洞报告
创建存储库安全公告
编辑存储库安全通告
在临时专用分支中协作以解决存储库安全漏洞
发布存储库安全公告
将协作者添加到存储库安全通告
删除存储库安全公告中的协作者
撤销存储库安全通告
有关报告和编写漏洞相关信息的指南
关于安全漏洞的协调披露
编写存储库安全公告的最佳做法
私下报告安全漏洞
管理私下报告的安全漏洞