GitHub Advanced Security (GHAS)
1h 20mAdvanced2022-09-27
Authors

Rob Bos
DevOps Professional, Consultant, Speaker, Microsoft MVP.
Course details
GitHub’s security features let you implement security throughout the development process to prevent issues from happening and protect your projects from becoming the latest news story about leaking customer data. With 80 million active developers, GitHub and Microsoft are on the forefront of new security feature development with a big push after recent US government directives. In this course, instructor Rob Bos covers three main features of GitHub Advanced Security to protect your software projects from having security issues: dependency scanning, secret scanning, and code scanning. Rob shows you how to enable these features and what parts of the development process they work on, and wraps up the course with a look at the security overview feature, which gives you a high-level view of your security status.
Skills covered
Version ControlGitHubSoftware Development ToolsSoftware DevelopmentOne-Off
Concepts
0. Introduction
- 01 - GitHub Advanced Security
- 02 - General overview of GitHub Advanced Security
1. Dependency Scanning
- 03 - Overview
- 04 - Dependency graph
- 05 - Dependabot configuration
- 06 - Vulnerable alerts management
- 07 - Automatic security updates
- 08 - GitHub Advisory Database
- 09 - Limitations
- 10 - Troubleshooting
2. Secret Scanning
- 11 - Secret scanning overview
- 12 - Enabling the feature
- 13 - Push protection
- 14 - Custom patterns
- 15 - Managing alerts
3. Code Scanning
- 16 - CodeQL overview
- 17 - Set up code scanning
- 18 - Reading the alerts
- 19 - Triaging alerts
- 20 - Configuration
- 21 - Community
4. Security Overview
- 22 - The security overview
- 23 - Team View
- 24 - Filtering options
Conclusion
- 25 - Next steps