पाठ 15 / 20

Security: 2FA, Dependabot और Secret Scanning

Two-factor authentication, Dependabot updates, secret scanning और SECURITY.md से अपना account और code सुरक्षित करें।

अपना account सुरक्षित करें

Two-factor authentication (passkey, security key या authenticator app) चालू करें और password की जगह SSH keys या fine-grained personal access tokens उपयोग करें।

Dependabot

Dependabot तब pull requests खोलता है जब आपकी dependencies के updates या vulnerabilities हों। इसे छोटी config file से चालू करें।

# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"

Secrets कभी commit न करें। Secret scanning और push protection चालू करें, लीक हुई किसी भी key को rotate करें और SECURITY.md जोड़ें जो बताए कि vulnerabilities निजी तौर पर कैसे report करें।

त्वरित जाँच

त्वरित जाँच: Dependabot क्या करता है?

  • Opens pull requests to update vulnerable or outdated dependencies
  • Deletes old branches
  • Hosts your site
  • Runs your tests only
Answer

Opens pull requests to update vulnerable or outdated dependencies — यह dependency updates और security fixes को automate करता है।