Learning GitHub Advanced Security for Azure DevOps
1h 18mAdvanced2023-12-21
Authors

Rob Bos
DevOps Professional, Consultant, Speaker, Microsoft MVP.
Course details
Are you concerned about your application security? From third-party libraries to the code you write yourself, you need to know how to protect your application from attacks. If you're using GitHub to store and share your Azure development code, you're in luck. A whole new set of tools, GitHub Advanced Security for Azure DevOps, is here to simplify your administration and management. Join instructor Rob Bos in this course to learn about the variety of powerful scanning tools that can alert you to problems and opportunities through a manageable dashboard—completely integrated in your Azure pipelines.
Skills covered
Version ControlGitHubDevOps ToolsDevOpsSoftware Development ToolsCloud ServicesCloud ComputingSoftware DevelopmentOne-Off
Concepts
0. Introduction
- 01 - Advanced security with Azure DevOps and GitHub
1. GitHub Advanced Security for Azure DevOps
- 02 - What is GitHub Advanced Security for Azure DevOps
- 03 - Enabling GHAS on your Azure DevOps organization
2. Setting Up the Environment
- 04 - Setting up the repository
- 05 - Security roles
3. Dependency Scanning
- 06 - Dependency graph
- 07 - Upload your application s dependencies
- 08 - GitHub Advisory Database
- 09 - Handle dependency alerts
4. Secret Scanning
- 10 - What is secret scanning
- 11 - Push protection
5. Code Scanning
- 12 - Code scanning overview
- 13 - Configure code scanning in your pipeline
- 14 - Uploading the SARIF file
- 15 - Triaging code scanning alerts
6. Alerts Dashboarding with Defender for Cloud
- 16 - Configuring the integration
- 17 - Effectively tracking progress with Defender for Cloud
- 18 - Dashboarding within Azure DevOps
Conclusion
- 19 - Next steps