GitHub Advanced Security allows you to have a “developer-first” approach to Application Security, recognizing that developers have a critical role to play in securing your applications. This training will enable developers in your organization to both understand and effectively use the features of Advanced Security.
Team Learning
Our learning experts provide private training for teams. Start a conversation about your training needs by calling us at 929.777.8102 or filling out our team training form below.
What You'll Learn
✔ Understand the key components of GitHub Advanced Security (Code Scanning, Secret Scanning and Dependabot).
✔ Enable Secret Scanning and understand how to triage and remediate results.
✔ Enable Dependabot and understand how to triage and remediate results.
✔ Enable CodeQL analysis within GitHub Actions to perform static analysis for commonly used languages.
✔ Configure GitHub Actions to trigger CodeQL analysis on both a schedule and in response to a Pull Request.
✔ Interact effectively with the Code Scanning user interface to understand, triage and remediate reported vulnerabilities.
✔ Understand how to configure CodeQL to improve the quality of results.
✔ Understand how to integrate common third party tools into Code Scanning via GitHub Actions.
Why Coveros?
- Developers
- Product Security teams
- DevSecOps teams
This engagement will consist of one session of 2 hours face-to-face time. Maximum session size is typically 20 people.
Dependabot & Dependency Graph
Create custom secrets