# Security: 2FA, Dependabot और Secret Scanning — GitHub Fundamentals: Collaboration, Pull Requests और Actions

Source: https://www.geekswithgeeks.com/hi/github/gh-security

> Two-factor authentication, Dependabot updates, secret scanning और SECURITY.md से अपना account और code सुरक्षित करें।

## अपना account सुरक्षित करें

**Two-factor authentication** (passkey, security key या authenticator app) चालू करें और password की जगह SSH keys या fine-grained personal access tokens उपयोग करें।

## Dependabot

Dependabot तब pull requests खोलता है जब आपकी dependencies के updates या vulnerabilities हों। इसे छोटी config file से चालू करें।

```yaml
# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
```

Secrets कभी commit न करें। Secret scanning और push protection चालू करें, लीक हुई किसी भी key को rotate करें और `SECURITY.md` जोड़ें जो बताए कि vulnerabilities निजी तौर पर कैसे report करें।

त्वरित जाँच

**Quiz:** Dependabot क्या करता है?

- [x] Opens pull requests to update vulnerable or outdated dependencies
- [ ] Deletes old branches
- [ ] Hosts your site
- [ ] Runs your tests only

*Answer:* Opens pull requests to update vulnerable or outdated dependencies. यह dependency updates और security fixes को automate करता है।
