1
0
mirror of synced 2025-12-22 03:16:52 -05:00
Commit Graph

2431 Commits

Author SHA1 Message Date
Hana Harencarova
88aa138851 Remove comments 2022-08-22 15:45:55 +02:00
Hana Harencarova
59652e9298 Improve wording about fingerprints 2022-08-22 15:34:36 +02:00
mc
3c6fd404c3 Add a table listing the filters, sort options and labels available for Dependabot alerts (#29466)
* made a start

* more work

* Apply suggestions from code review

Co-authored-by: Felicity Chapman <felicitymay@github.com>

* address last comments

* adjust versioning

* ooops

* hmmm

Co-authored-by: Felicity Chapman <felicitymay@github.com>
2022-08-22 09:32:36 +01:00
de-oz
96a4779ce1 Fix indefinite articles usage 2022-08-20 10:03:23 +03:00
Junior Eluhu
b8f02ff172 adding release notes (#29927) 2022-08-16 19:03:29 +00:00
mc
b9e40e8c1f Code scanning - fix screenshot display and numbered list (#29987)
* remove screenshot

* re-add screenshot

* having fun with list

* re-add image under a different name and rename in links

* Optimize images

Co-authored-by: github-actions <github-actions@github.com>
2022-08-16 13:20:41 +00:00
mc
96af28d597 Add docs to help users remediate blocked secrets (#29720)
* document how to remediate secrets
2022-08-16 08:27:55 +00:00
Matt Pollard
02f018b418 Bug fixes for Enterprise content, 2022-08-12 (#29897) 2022-08-16 07:57:09 +00:00
Andrew Eisenberg
10c492e5d4 Fix incorrect link (#29848)
* Fix incorrect link

Lins to the codeql-action should always be to v2.

* Conditionally link to v1 or v2 of the codeql-action

Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
2022-08-12 16:12:10 +00:00
Steve Guntrip
744b0a57c5 [2022-08-12]: Secret scanning: dry-runs for custom patterns - [GA] (#29792)
Co-authored-by: github-actions <github-actions@github.com>
Co-authored-by: Vanessa <vgrl@github.com>
2022-08-11 23:32:55 +00:00
Orhan Toy
4d24a40d08 Fix typo: updatng -> updating (#29726)
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
2022-08-09 09:40:43 +00:00
Felicity Chapman
9e58b71be2 Security overview available to all enterprise users, no longer requires GHAS (#29126)
* Rename gated-feature

* Rename reusable folder

* Add feature for function

* Update for change in behavior

* Remove GHES 3.0 from gated feature

* Remove unused gated-feature

* Fix test

* Fix another test

* Apply suggestions from code review

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Improve versioning

* Tweak message

* Update data/features/security-overview-displayed-alerts.yml

* Update content/code-security/getting-started/github-security-features.md

Co-authored-by: Kelly Arwine <kellyarwine@github.com>

Co-authored-by: Laura Coursen <lecoursen@github.com>
Co-authored-by: Kelly Arwine <kellyarwine@github.com>
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
2022-08-09 05:35:27 +00:00
Jenni Christensen
63e1c8c8b3 Merge branch 'main' into ske-runner-images 2022-08-08 08:30:09 -07:00
Hana Harencarova
c928c39bd4 Update uploading-a-sarif-file-to-github.md
Change the link to 'About SARIF support for code scanning'
2022-08-08 15:36:10 +02:00
Hana Harencarova
cc80a8b182 Code Scanning integration - importance of consistent filepaths #7017 2022-08-08 15:32:07 +02:00
Kate Catlin
1db3ba5838 Adding GitHub Actions as a supported ecosystem (#29454) 2022-08-04 15:54:31 +00:00
skedwards88
7c57ea52fa change remaining instances of virtual environment to runner image 2022-08-03 11:47:05 -07:00
Simon Engledew
65e373924a code-scanning: Add a section on rules and results (#29161) 2022-08-02 09:58:41 +00:00
Courtney Wilson
982ae82ff7 Merge branch 'main' into patch-2 2022-08-01 16:44:32 -05:00
mc
780fe200ef Merge branch 'main' into patch-2 2022-08-01 16:32:28 +01:00
mc
03f868d8ac Update content/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file.md 2022-08-01 16:03:37 +01:00
mc
e98383c13a Update content/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file.md 2022-08-01 15:48:53 +01:00
AlonaHlobina
64c49437d9 Obtaining detailed logs and debugging artifacts for the CodeQL Action (#29425)
* Create codeql-action-debug-logging.yml

* Update troubleshooting-the-codeql-workflow.md

* Update viewing-code-scanning-logs.md

* Update troubleshooting-the-codeql-workflow.md

* Apply suggestions from code review

Co-authored-by: Aditya Sharad <6874315+adityasharad@users.noreply.github.com>

* Update troubleshooting-the-codeql-workflow.md

* Don't use NWO

* Apply suggestions from code review

* Update content/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/troubleshooting-the-codeql-workflow.md

* Apply suggestions from code review

* Update content/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/viewing-code-scanning-logs.md

Co-authored-by: Aditya Sharad <6874315+adityasharad@users.noreply.github.com>
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com>
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
2022-08-01 11:14:08 +00:00
skedwards88
aea4b9c47c rename references to virual-environments repo to runner-images 2022-07-29 12:33:18 -07:00
Landon Grindheim
a9355a55c2 Note that ACR is not currently supported 2022-07-29 15:15:12 -04:00
JonZeolla
1434aec1a9 Fix github.actor examples (#19267) 2022-07-28 09:30:19 +00:00
mc
2b15269a3d [Ready to ship] Configuring the dependency review action on GHES (#29064) 2022-07-27 15:27:27 +00:00
Andy Barnes
441cfc54cf Add pull-requests: write to permissions: block (#29350) 2022-07-27 08:09:51 +00:00
Sarah Edwards
012525e673 Document triggering_actor (#28988) 2022-07-26 22:54:58 +00:00
Mariam
8aa0adbe63 Secret scanning: Make pair matches visible in docs (#29324) 2022-07-26 19:16:54 +00:00
Sophie
3df2d7b47a [2022-07-27]: Secret scanning: Email on bypass - [GA] (#29233) 2022-07-26 19:11:46 +00:00
Matt Pollard
dc2ba532b4 GitHub Enterprise Server 3.6 release candidate (#28905) 2022-07-26 18:56:17 +02:00
Benjamin Friedman Wilson
1268fee5fc small typo fix for mispelled 'updating' 2022-07-26 09:44:40 +02:00
mc
8fcb5ad8c1 Fix mention of public repos in GHAE (#29328)
* fix mention of public in GHAE

* Update content/code-security/supply-chain-security/end-to-end-supply-chain/securing-code.md

Co-authored-by: Steve Guntrip <12534592+stevecat@users.noreply.github.com>

Co-authored-by: Steve Guntrip <12534592+stevecat@users.noreply.github.com>
2022-07-25 12:24:37 +00:00
Eli Reisman
0bc93e8437 Update Rust/Cargo Dependency Graph documentation (#28976) 2022-07-21 20:21:40 +02:00
Felicity Chapman
73b085ef8e Secret scanning: fix typo in condition (#29203) 2022-07-21 10:27:19 +00:00
Felicity Chapman
40989e0ca6 "Security center" rename to "Security overview" (#29120) 2022-07-18 16:40:33 +00:00
Sarita Iyer
15c09dc0b2 Merge branch 'main' into dependabot-alerts-most-important-sort 2022-07-15 13:37:13 -04:00
Steve Guntrip
74d6918dae Add GHAS resources 2022-07-15 13:57:26 +00:00
Jurre
d738183157 Dependabot: explain how to allow rebases over appended commits (#29026)
* Depedabot: explain how to allow rebases over appended commits

By default Dependabot stops rebasing PRs that have been altered, in some cases (especially when setting up automations that add commits to PRs automatically), this is not desirable, and it's preferable for Dependabot to force push over those commits, removing them and having the automation re-generate them.

This is a feature that's been present in Dependabot for a while already, but has not been documented, so let's document it.

* Update content/code-security/dependabot/working-with-dependabot/managing-pull-requests-for-dependency-updates.md

* Update content/code-security/dependabot/working-with-dependabot/managing-pull-requests-for-dependency-updates.md

Co-authored-by: Jurre <jurre@github.com>

* Update content/code-security/dependabot/working-with-dependabot/managing-pull-requests-for-dependency-updates.md

Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
2022-07-14 14:04:12 +00:00
Sarita Iyer
ecea5682be replace tip with note 2022-07-13 09:26:34 -04:00
Sarita Iyer
3c4200f16f add variable 2022-07-12 17:30:38 -04:00
Sarita Iyer
f6776685c7 add info + screenshot about most important sort 2022-07-12 17:15:07 -04:00
Hector Alfaro
95e6f3d3ab Deprecate GHES 3.1 (#28798)
* add 3.1 to deprecated versions

* rewrite img src to use azure blob storage in archive script

Co-authored-by: rachmari <rachmari@users.noreply.github.com>

* remove static files for ghes 3.1

* remove liquid conditionals and content for ghes 3.1

* remove outdated hardware reqs reusable

* Fix liquid conditional uncaught by script

* Close liquid conditionals missed by script

* Apply @mattpollard's suggestions

Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com>

Co-authored-by: rachmari <rachmari@users.noreply.github.com>
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com>
2022-07-11 21:17:09 +00:00
Grey Baker
64266fc64e Clarify when users receive secret scanning alert notifications (#28822)
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
2022-07-11 14:11:31 +00:00
Felicity Chapman
e67f797a19 Merge branch 'main' into adityasharad/codeql-ghes-version 2022-07-11 13:46:41 +01:00
Felicity Chapman
11c6980515 Add GHAE versioning too 2022-07-01 11:59:59 +01:00
mc
d328effc2b [Already shipped] -Dependabot alerts: surface information about development dependencies - [GA] (#28615)
* made a start

* hmm hmm

* more work

* Optimize images

* improvements

* make table easier to read

* Apply suggestions from code review

Co-authored-by: Sarita Iyer <66540150+saritai@users.noreply.github.com>

* address review comments

Co-authored-by: github-actions <github-actions@github.com>
Co-authored-by: Sarita Iyer <66540150+saritai@users.noreply.github.com>
2022-06-30 07:53:12 +00:00
Janice
469e698b6a Merge branch 'main' into patch-2 2022-06-28 19:02:38 +02:00
Kate Catlin
1e48a5756d Adding Erlang as a supported language (#28754) 2022-06-28 15:44:47 +00:00