Lesson 15 / 20

Security: 2FA, Dependabot & Secret Scanning

Secure your account and code with two-factor authentication, Dependabot updates, secret scanning and SECURITY.md.

Protect your account

Turn on two-factor authentication (a passkey, security key or authenticator app) and use SSH keys or fine-grained personal access tokens instead of your password.

Dependabot

Dependabot opens pull requests when your dependencies have updates or vulnerabilities. Enable it with a small config file.

# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"

Never commit secrets. Turn on secret scanning and push protection, rotate any key that leaks, and add a SECURITY.md that says how to report vulnerabilities privately.

Quick check

Quick check: What does Dependabot do?

  • Opens pull requests to update vulnerable or outdated dependencies
  • Deletes old branches
  • Hosts your site
  • Runs your tests only
Answer

Opens pull requests to update vulnerable or outdated dependencies — It automates dependency updates and security fixes.