{"id":43707,"date":"2022-08-11T16:18:52","date_gmt":"2022-08-11T15:18:52","guid":{"rendered":"https:\/\/www.developer-tech.com\/?p=43707"},"modified":"2022-08-11T16:18:57","modified_gmt":"2022-08-11T15:18:57","slug":"github-sends-dependabot-alerts-vulnerable-actions","status":"publish","type":"post","link":"https:\/\/www.developer-tech.com\/news\/2022\/aug\/11\/github-sends-dependabot-alerts-vulnerable-actions\/","title":{"rendered":"GitHub now sends Dependabot alerts for vulnerable Actions"},"content":{"rendered":"\n
GitHub<\/a> has announced that it will begin sending Dependabot<\/a> alerts when it detects vulnerable GitHub Actions<\/a>.<\/p>\n\n\n\n GitHub Actions makes it easy for developers to automate their workflows. Dependabot, meanwhile, automatically updates dependencies to keep your projects secure.<\/p>\n\n\n\n When an Action vulnerability is discovered, GitHub\u2019s team of security researchers will create an advisory to document it. Following the creation of an advisory, Dependabot alerts will be sent to impacted repositories.<\/p>\n\n\n\n \u201cImprovements like these strengthen GitHub and our users\u2019 security posture, which is why we continue to invest in tightening connection points between GitHub\u2019s supply chain security solutions and GitHub Actions to improve the security of our builds,\u201d explained GitHub in a blog post<\/a>.<\/p>\n\n\n\n Anyone already using Dependabot will start receiving the new alerts. If you\u2019re yet to start using the feature, you can enable Dependabot by selecting \u2018Enable all\u2019 under the \u2018Code security and analysis\u2019 tab.<\/p>\n\n\n\n If you own a GitHub Action and have discovered a vulnerability, an advisory can be created from the security tab in your repo. GitHub\u2019s team will review the advisory and then issue it globally if required.<\/p>\n\n\n\n (Photo by\u00a0Marcel Eberle<\/a>\u00a0on\u00a0Unsplash<\/a>)<\/em><\/p>\n\n\n\n Looking to revamp your digital transformation strategy?<\/strong> Learn more about Digital Transformation Week<\/a> taking place in Amsterdam, California, and London, and discover key strategies for making your digital efforts a success.<\/p>\n","protected":false},"excerpt":{"rendered":" GitHub has announced that it will begin sending Dependabot alerts when it detects vulnerable GitHub Actions. GitHub Actions makes it easy for developers to automate their workflows. Dependabot, meanwhile, automatically updates dependencies to keep your projects secure. When an Action vulnerability is discovered, GitHub\u2019s team of security researchers will create an advisory to document it.… Read more »<\/a><\/p>\n","protected":false},"author":1570,"featured_media":43710,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[42,23],"tags":[1077,317,1395,246,143,738,219],"ppma_author":[1565],"acf":[],"yoast_head":"\n<\/figure>\n\n\n\n
<\/a><\/figure>\n\n\n\n