# Security: 2FA, Dependabot & Secret Scanning — GitHub Fundamentals: Collaboration, Pull Requests and Actions

Source: https://www.geekswithgeeks.com/en/github/gh-security

> Secure your account and code with two-factor authentication, Dependabot updates, secret scanning and SECURITY.md.

## Protect your account

Turn on **two-factor authentication** (a passkey, security key or authenticator app) and use SSH keys or fine-grained personal access tokens instead of your password.

## Dependabot

Dependabot opens pull requests when your dependencies have updates or vulnerabilities. Enable it with a small config file.

```yaml
# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
```

Never commit secrets. Turn on secret scanning and push protection, rotate any key that leaks, and add a `SECURITY.md` that says how to report vulnerabilities privately.

Quick check

**Quiz:** What does Dependabot do?

- [x] Opens pull requests to update vulnerable or outdated dependencies
- [ ] Deletes old branches
- [ ] Hosts your site
- [ ] Runs your tests only

*Answer:* Opens pull requests to update vulnerable or outdated dependencies. It automates dependency updates and security fixes.
