How does Dependabot determine which security update PRs to open?
A.
It waits for manual triage of all CVEs.
B.
It uses the dependency graph and Dependabot alerts to open PRs for patched versions.
C.
It reads the GitHub Issues and automatically suggests fixes.
D.
It compares your codebase to the GitHub Trending list.
The Answer Is:
B
This question includes an explanation.
Explanation:
Dependabot relies on your repository’s enabled Dependency Graph and Dependabot Alerts to identify vulnerable dependencies; it then automatically opens pull requests to update to the patched versions that resolve those alerts.
GH-100 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"