Lesson 15 / 20
Security: 2FA, Dependabot & Secret Scanning
Secure your account and code with two-factor authentication, Dependabot updates, secret scanning and SECURITY.md.
Protect your account
Turn on two-factor authentication (a passkey, security key or authenticator app) and use SSH keys or fine-grained personal access tokens instead of your password.
Dependabot
Dependabot opens pull requests when your dependencies have updates or vulnerabilities. Enable it with a small config file.
# .github/dependabot.yml
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"Never commit secrets. Turn on secret scanning and push protection, rotate any key that leaks, and add a SECURITY.md that says how to report vulnerabilities privately.
Quick check
Quick check: What does Dependabot do?
- Opens pull requests to update vulnerable or outdated dependencies
- Deletes old branches
- Hosts your site
- Runs your tests only
Answer
Opens pull requests to update vulnerable or outdated dependencies — It automates dependency updates and security fixes.