Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion content/code-security/concepts/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,4 +15,6 @@ topics:
- Dependencies
- Dependabot
contentType: concepts
---
children:
- /vulnerability-reporting-and-management
- supply-chain-security
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ redirect_from:
- /github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies
- /code-security/supply-chain-security/about-alerts-for-vulnerable-dependencies
- /code-security/supply-chain-security/managing-vulnerabilities-in-your-projects-dependencies/about-alerts-for-vulnerable-dependencies
- /code-security/dependabot/dependabot-alerts/about-dependabot-alerts
versions:
fpt: '*'
ghes: '*'
Expand All @@ -20,6 +21,7 @@ topics:
- Repositories
- Dependencies
shortTitle: Dependabot alerts
contentType: concepts
---
<!--Marketing-LINK: From /features/security/software-supply-chain page "About alerts for vulnerable dependencies ".-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,10 +13,12 @@ topics:
- Vulnerabilities
- Repositories
- Dependencies
shortTitle: About auto-triage rules
shortTitle: Dependabot auto-triage rules
redirect_from:
- /code-security/dependabot/dependabot-alerts/using-alert-rules-to-prioritize-dependabot-alerts
- /code-security/dependabot/dependabot-alert-rules/about-dependabot-alert-rules
- /code-security/dependabot/dependabot-auto-triage-rules/about-dependabot-auto-triage-rules
contentType: concepts
---

## About {% data variables.dependabot.auto_triage_rules %}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: About Dependabot on GitHub Actions runners
intro: '{% data variables.product.prodname_dotcom %} automatically runs the jobs that generate {% data variables.product.prodname_dependabot %} pull requests on {% data variables.product.prodname_actions %} if you have {% data variables.product.prodname_actions %} enabled for the repository. When {% data variables.product.prodname_dependabot %} is enabled, these jobs will run by bypassing Actions policy checks and disablement at the repository or organization level.'
shortTitle: About Dependabot on Actions
shortTitle: Dependabot on Actions
product: '{% data reusables.gated-features.dependabot-on-actions %}'
versions:
feature: dependabot-on-actions-opt-in
Expand All @@ -13,6 +13,9 @@ topics:
- Actions
- Dependencies
- Repositories
redirect_from:
- /code-security/dependabot/working-with-dependabot/about-dependabot-on-github-actions-runners
contentType: concepts
---

## About {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ redirect_from:
- /github/managing-security-vulnerabilities/about-dependabot-security-updates
- /code-security/supply-chain-security/about-dependabot-security-updates
- /code-security/supply-chain-security/managing-vulnerabilities-in-your-projects-dependencies/about-dependabot-security-updates
- /code-security/dependabot/dependabot-security-updates/about-dependabot-security-updates
versions:
fpt: '*'
ghec: '*'
Expand All @@ -20,6 +21,7 @@ topics:
- Repositories
- Dependencies
- Pull requests
contentType: concepts
---

<!--Marketing-LINK: From /features/security/software-supply-chain page "About Dependabot security updates".-->
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: About Dependabot version updates
intro: 'You can use {% data variables.product.prodname_dependabot %} to keep the packages you use updated to the latest versions.'
intro: You can use {% data variables.product.prodname_dependabot %} to keep the packages you use updated to the latest versions.
product: '{% data reusables.gated-features.dependabot-version-updates %}'
redirect_from:
- /github/administering-a-repository/about-dependabot
Expand All @@ -10,6 +10,7 @@ redirect_from:
- /code-security/supply-chain-security/about-dependabot-version-updates
- /code-security/supply-chain-security/keeping-your-dependencies-updated-automatically/upgrading-from-dependabotcom-to-github-native-dependabot
- /code-security/supply-chain-security/keeping-your-dependencies-updated-automatically/about-dependabot-version-updates
- /code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates
versions:
fpt: '*'
ghec: '*'
Expand All @@ -22,6 +23,7 @@ topics:
- Dependencies
- Pull requests
shortTitle: Dependabot version updates
contentType: concepts
---

{% data reusables.dependabot.enterprise-enable-dependabot %}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: About dependency review
intro: 'Dependency review lets you catch insecure dependencies before you introduce them to your environment, and provides information on license, dependents, and age of dependencies.'
intro: Dependency review lets you catch insecure dependencies before you introduce them to your environment, and provides information on license, dependents, and age of dependencies.
product: '{% data reusables.gated-features.dependency-review %}'
shortTitle: Dependency review
versions:
Expand All @@ -16,6 +16,8 @@ topics:
- Pull requests
redirect_from:
- /code-security/supply-chain-security/about-dependency-review
- /code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review
contentType: concepts
---

## About dependency review
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,10 @@
---
title: About supply chain security
intro: '{% data variables.product.github %} helps you secure your supply chain, from understanding the dependencies in your environment, to knowing about vulnerabilities in those dependencies, and patching them.'
shortTitle: Supply chain security
shortTitle: Supply chain features
redirect_from:
- /code-security/supply-chain-security/managing-vulnerabilities-in-your-projects-dependencies
- /code-security/supply-chain-security/understanding-your-software-supply-chain/about-supply-chain-security
versions:
fpt: '*'
ghes: '*'
Expand All @@ -17,6 +18,7 @@ topics:
- Dependencies
- Pull requests
- Repositories
contentType: concepts
---

## About supply chain security at GitHub
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ product: '{% data reusables.gated-features.dependency-graph %}'
redirect_from:
- /github/visualizing-repository-data-with-graphs/about-the-dependency-graph
- /code-security/supply-chain-security/about-the-dependency-graph
- /code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph
versions:
fpt: '*'
ghes: '*'
Expand All @@ -15,6 +16,7 @@ topics:
- Dependencies
- Repositories
shortTitle: Dependency graph
contentType: concepts
---
<!--Marketing-LINK: From /features/security and /features/security/software-supply-chain pages "How GitHub's dependency graph is generated".-->

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Best practices for maintaining dependencies
intro: 'Guidance and recommendations for maintaining the dependencies you use, including {% data variables.product.github %}''s security products that can help.'
intro: Guidance and recommendations for maintaining the dependencies you use, including {% data variables.product.github %}'s security products that can help.
allowTitleToDifferFromFilename: true
versions:
fpt: '*'
Expand All @@ -14,7 +14,10 @@ topics:
- Repositories
- Dependencies
- Pull requests
shortTitle: Dependency management best practices
shortTitle: Dependency best practices
redirect_from:
- /code-security/dependabot/maintain-dependencies/best-practices-for-maintaining-dependencies
contentType: concepts
---

## Best practices for maintaining dependencies
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Immutable releases
intro: 'Learn about immutable releases and how they can help you maintain the integrity of your software supply chain.'
intro: Learn about immutable releases and how they can help you maintain the integrity of your software supply chain.
versions:
fpt: '*'
ghec: '*'
Expand All @@ -9,6 +9,9 @@ topics:
- Code Security
- Vulnerabilities
- Dependencies
redirect_from:
- /code-security/supply-chain-security/understanding-your-software-supply-chain/immutable-releases
contentType: concepts
---

**Immutable releases** are releases where the assets and associated Git tag cannot be changed after publication. The use of this type of release increases security by blocking supply chain attacks. Attackers cannot:
Expand Down
21 changes: 21 additions & 0 deletions content/code-security/concepts/supply-chain-security/index.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
---
title: Supply chain security
intro: '{% data variables.product.github %}''s security features help you keep track of your projects'' dependencies and built artifacts.'
versions:
fpt: '*'
ghes: '*'
ghec: '*'
contentType: concepts
children:
- about-supply-chain-security
- best-practices-for-maintaining-dependencies
- about-the-dependency-graph
- about-dependency-review
- about-dependabot-alerts
- about-dependabot-security-updates
- about-dependabot-version-updates
- about-dependabot-auto-triage-rules
- about-dependabot-on-github-actions-runners
- immutable-releases
---

Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,11 @@ redirect_from:
- /code-security/repository-security-advisories/about-coordinated-disclosure-of-security-vulnerabilities
- /code-security/security-advisories/repository-security-advisories/about-coordinated-disclosure-of-security-vulnerabilities
- /code-security/security-advisories/guidance-on-reporting-and-writing/about-coordinated-disclosure-of-security-vulnerabilities
- /code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/about-coordinated-disclosure-of-security-vulnerabilities
versions:
fpt: '*'
ghec: '*'
type: overview
contentType: concepts
topics:
- Security advisories
- Vulnerabilities
Expand Down
Original file line number Diff line number Diff line change
@@ -1,18 +1,20 @@
---
title: About global security advisories
intro: 'Global security advisories live in the {% data variables.product.prodname_advisory_database %}, a collection of CVEs and {% data variables.product.company_short %}-originated advisories affecting the open source world. You can contribute to improving global security advisories.'
shortTitle: Global security advisories
intro: Global security advisories live in the {% data variables.product.prodname_advisory_database %}, a collection of CVEs and {% data variables.product.company_short %}-originated advisories affecting the open source world. You can contribute to improving global security advisories.
versions:
fpt: '*'
ghec: '*'
ghes: '*'
type: overview
contentType: concepts
topics:
- Security advisories
- Alerts
- Vulnerabilities
- CVEs
redirect_from:
- /code-security/security-advisories/global-security-advisories/about-global-security-advisories
- /code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-global-security-advisories
---

## About global security advisories
Expand Down
Original file line number Diff line number Diff line change
@@ -1,18 +1,19 @@
---
title: About repository security advisories
intro: 'You can use repository security advisories to privately discuss, fix, and publish information about security vulnerabilities in your public repository.'
shortTitle: About repository security advisories
intro: You can use repository security advisories to privately discuss, fix, and publish information about security vulnerabilities in your public repository.
shortTitle: Repository security advisories
redirect_from:
- /articles/about-maintainer-security-advisories
- /github/managing-security-vulnerabilities/about-maintainer-security-advisories
- /github/managing-security-vulnerabilities/about-github-security-advisories
- /code-security/security-advisories/about-github-security-advisories
- /code-security/repository-security-advisories/about-github-security-advisories-for-repositories
- /code-security/security-advisories/repository-security-advisories/about-repository-security-advisories
- /code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories
versions:
fpt: '*'
ghec: '*'
type: overview
contentType: concepts
product: '{% data reusables.gated-features.private-vulnerability-reporting %}'
topics:
- Security advisories
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,14 +5,16 @@ versions:
fpt: '*'
ghec: '*'
ghes: '*'
type: overview
contentType: concepts
shortTitle: GitHub Advisory database
topics:
- Security advisories
- Alerts
- Vulnerabilities
- CVEs
redirect_from:
- /code-security/security-advisories/global-security-advisories/about-the-github-advisory-database
- /code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-the-github-advisory-database
---

## About the {% data variables.product.prodname_advisory_database %}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: About exposure to vulnerabilities in your code and in dependencies
shortTitle: Vulnerability exposure
intro: 'Understanding your organization’s exposure to vulnerabilities in first-party code and in all dependencies is essential for enabling you to efficiently assess, prioritize, and remediate vulnerabilities, reducing the likelihood of security breaches.'
intro: Understanding your organization’s exposure to vulnerabilities in first-party code and in all dependencies is essential for enabling you to efficiently assess, prioritize, and remediate vulnerabilities, reducing the likelihood of security breaches.
allowTitleToDifferFromFilename: true
product: '{% data reusables.gated-features.ghas-billing %}'
versions:
Expand All @@ -14,6 +14,7 @@ topics:
- Security
redirect_from:
- /code-security/securing-your-organization/understanding-your-organizations-exposure-to-vulnerabilites/about-your-exposure-to-vulnerable-dependencies
- /code-security/securing-your-organization/understanding-your-organizations-exposure-to-vulnerabilities/about-your-exposure-to-vulnerable-dependencies
---

## About exposure to vulnerable code
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
title: Concepts for vulnerability reporting and management
shortTitle: Vulnerability reporting
intro: Learn core concepts relating to vulnerability reporting and management on {% data variables.product.github %}.
versions:
fpt: '*'
ghec: '*'
topics:
- Security advisories
- Vulnerabilities
contentType: concepts
children:
- /about-the-github-advisory-database
- /about-repository-security-advisories
- /about-global-security-advisories
- /about-coordinated-disclosure-of-security-vulnerabilities
- /about-your-exposure-to-vulnerabilities-in-your-code-and-in-dependencies
---
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,9 @@ topics:
- Repositories
- Dependencies
children:
- /about-dependabot-alerts
- /configuring-dependabot-alerts
- /viewing-and-updating-dependabot-alerts
- /enable-delegated-alert-dismissal
- /configuring-notifications-for-dependabot-alerts
---

Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: Prioritizing Dependabot alerts with Dependabot auto-triage rules
shortTitle: Dependabot auto-triage rules
intro: 'You can use {% data variables.dependabot.auto_triage_rules %} to prioritize {% data variables.product.prodname_dependabot_alerts %}.'
intro: You can use {% data variables.dependabot.auto_triage_rules %} to prioritize {% data variables.product.prodname_dependabot_alerts %}.
allowTitleToDifferFromFilename: true
versions:
feature: dependabot-auto-triage-rules
Expand All @@ -12,10 +12,10 @@ topics:
- Repositories
- Dependencies
children:
- /about-dependabot-auto-triage-rules
- /using-github-preset-rules-to-prioritize-dependabot-alerts
- /customizing-auto-triage-rules-to-prioritize-dependabot-alerts
- /managing-automatically-dismissed-alerts
redirect_from:
- /code-security/dependabot/dependabot-alert-rules
---

Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ topics:
- Pull requests
shortTitle: Dependabot security updates
children:
- /about-dependabot-security-updates
- /configuring-dependabot-security-updates
- /customizing-dependabot-security-prs
---

Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Keeping your dependencies updated automatically with Dependabot version updates
intro: 'You can use {% data variables.product.prodname_dependabot %} to automatically keep the dependencies and packages used in your repository updated to the latest version, even when they don’t have any known vulnerabilities.'
intro: You can use {% data variables.product.prodname_dependabot %} to automatically keep the dependencies and packages used in your repository updated to the latest version, even when they don’t have any known vulnerabilities.
allowTitleToDifferFromFilename: true
redirect_from:
- /github/administering-a-repository/keeping-your-dependencies-updated-automatically
Expand All @@ -20,10 +20,10 @@ topics:
- Dependencies
- Pull requests
children:
- /about-dependabot-version-updates
- /configuring-dependabot-version-updates
- /optimizing-pr-creation-version-updates
- /customizing-dependabot-prs
- /controlling-dependencies-updated
shortTitle: Dependabot version updates
---

Loading
Loading