# aitour-github-advanced-security-workflow **Repository Path**: mirrors_microsoft/aitour-github-advanced-security-workflow ## Basic Information - **Project Name**: aitour-github-advanced-security-workflow - **Description**: No description available - **Primary Language**: Unknown - **License**: MIT - **Default Branch**: main - **Homepage**: None - **GVP Project**: No ## Statistics - **Stars**: 0 - **Forks**: 0 - **Created**: 2024-08-25 - **Last Updated**: 2026-01-10 ## Categories & Tags **Categories**: Uncategorized **Tags**: None ## README # BRK422 - GitHub Advanced Security: Securing your workflow If you will be delivering this session, consult the [session-delivery-resources](https://github.com/microsoft/aitour-github-advanced-security-workflow/tree/main/session-delivery-resources#readme) page for slides, demo scripts, and other resources. ## Session Description GitHub Advanced Security features are built directly into the development workflow, making them easy to use and giving developers the ability to catch potential security issues as early in the software development lifecycle as possible. Learn how to prevent common security issues from being merged into your codebase, how to find and fix vulnerabilities faster with AI, and how to keep your dependencies updated via GitHub Advanced Security. ## Learning Outcomes - Learn how to enable Dependabot alerts and get notifications about vulnerable dependencies, including a link to the affected file in the project and information about a fixed version. - See how to automatically update or generate a pull request to update vulnerable dependencies. - Discover how to automatically update supported packages used by your repository on a schedule you configure. - Learn how to enable Secret scanning and Push protection proactively prevents secret leaks by scanning code on commit and blocking a push if a secret is present. - Find vulnerabilities before they are merged into the code base with automated CodeQL scans. - Learn how to get suggested code fixes powered by AI in pull requests. ## Technology Used - GitHub Advanced Security - Dependabot - Secret Scanning - CodeQL - Copilot Autofix - GitHub Actions ## Additional Resources and Continued Learning | Resources | Links | Description | |:-------------------|:----------------------------------|:-------------------| | Docs | [Docs](https://docs.github.com/en/get-started/learning-about-github/about-github-advanced-security) | About GitHub Advanced Security | | Docs | [Dependabot security updates Doc](https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/about-dependabot-security-updates) | About Dependabot security updates | | Docs | [Copilot Autofix Doc](https://docs.github.com/en/code-security/code-scanning/managing-code-scanning-alerts/about-autofix-for-codeql-code-scanning#autofix-generation-process) | About Copilot Copilot Autofix for CodeQL code scanning | | Certification | [GitHub Advanced Security Certification Program](https://examregistration.github.com/) | Learn more about GitHub Certifications | ## Content Owners
![]() Joylynn Kirui 📢 |
![]() Anthony Bartolo 📢 |