Automated pull requests that help you update dependencies that have known vulnerabilities
B.
Automated pull requests that keep your dependencies updated, even when they don’t have any vulnerabilities
C.
Automated pull requests to update the manifest to the latest version of the dependency
D.
Compatibility scores to let you know whether updating a dependency could cause breaking changes to your project
The Answer Is:
A
This question includes an explanation.
Explanation:
Dependabot security updates are automated pull requests triggered when GitHub detects a vulnerability in a dependency listed in your manifest or lockfile. These PRs upgrade the dependency to the minimum safe version that fixes the vulnerability.
This is separate from regular updates (which keep versions current even if not vulnerable).
[: GitHub Docs – About Dependabot Security Updates, ==========]
GH-500 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"