Skip to content
All integrations

Security

Dependabot

Findings from GitHub Advanced Security, placed on the services they affect, with what opened, closed and stays open.

Connect Dependabot

What Waltz reads

  • Dependabot alerts
  • Code scanning alerts
  • Secret scanning alerts
  • Severity and state

What it never reads

  • Secret values and code snippets
  • Who introduced a finding

What it adds to your Briefs

  • Risks that need a decision: vulnerable dependencies and exposed secrets
  • Risk and stability: findings opened and fixed
  • Exposure: open security issues and what they could mean

Connect

  1. 01Connect GitHub
  2. 02Accept the alert read permissions
  3. 03Repositories without scanning show as not covered