Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)
As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)
on:
pull_request:
branches: [main]
Secret scanning will scan:
In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?
Which patterns are secret scanning validity checks available to?
What YAML syntax do you use to exclude certain files from secret scanning?
What does code scanning do?
What does a CodeQL database of your repository contain?
A dependency has a known vulnerability. What does the warning message include?
You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?
PDF + Testing Engine
|
---|
$70 |
Testing Engine
|
---|
$54 |
PDF (Q&A)
|
---|
$46 |
Microsoft Free Exams |
---|
![]() |