All integrationsConnect Dependabot
Security
Dependabot
Findings from GitHub Advanced Security, placed on the services they affect, with what opened, closed and stays open.
What Waltz reads
- Dependabot alerts
- Code scanning alerts
- Secret scanning alerts
- Severity and state
What it never reads
- Secret values and code snippets
- Who introduced a finding
What it adds to your Briefs
- Risks that need a decision: vulnerable dependencies and exposed secrets
- Risk and stability: findings opened and fixed
- Exposure: open security issues and what they could mean
Connect
- 01Connect GitHub
- 02Accept the alert read permissions
- 03Repositories without scanning show as not covered