Andrew Eisenberg
10c492e5d4
Fix incorrect link ( #29848 )
...
* Fix incorrect link
Lins to the codeql-action should always be to v2.
* Conditionally link to v1 or v2 of the codeql-action
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com >
2022-08-12 16:12:10 +00:00
Steve Guntrip
744b0a57c5
[2022-08-12]: Secret scanning: dry-runs for custom patterns - [GA] ( #29792 )
...
Co-authored-by: github-actions <github-actions@github.com >
Co-authored-by: Vanessa <vgrl@github.com >
2022-08-11 23:32:55 +00:00
Orhan Toy
4d24a40d08
Fix typo: updatng -> updating ( #29726 )
...
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com >
2022-08-09 09:40:43 +00:00
Felicity Chapman
9e58b71be2
Security overview available to all enterprise users, no longer requires GHAS ( #29126 )
...
* Rename gated-feature
* Rename reusable folder
* Add feature for function
* Update for change in behavior
* Remove GHES 3.0 from gated feature
* Remove unused gated-feature
* Fix test
* Fix another test
* Apply suggestions from code review
Co-authored-by: Laura Coursen <lecoursen@github.com >
* Improve versioning
* Tweak message
* Update data/features/security-overview-displayed-alerts.yml
* Update content/code-security/getting-started/github-security-features.md
Co-authored-by: Kelly Arwine <kellyarwine@github.com >
Co-authored-by: Laura Coursen <lecoursen@github.com >
Co-authored-by: Kelly Arwine <kellyarwine@github.com >
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com >
2022-08-09 05:35:27 +00:00
Jenni Christensen
63e1c8c8b3
Merge branch 'main' into ske-runner-images
2022-08-08 08:30:09 -07:00
Kate Catlin
1db3ba5838
Adding GitHub Actions as a supported ecosystem ( #29454 )
2022-08-04 15:54:31 +00:00
skedwards88
7c57ea52fa
change remaining instances of virtual environment to runner image
2022-08-03 11:47:05 -07:00
Simon Engledew
65e373924a
code-scanning: Add a section on rules and results ( #29161 )
2022-08-02 09:58:41 +00:00
Courtney Wilson
982ae82ff7
Merge branch 'main' into patch-2
2022-08-01 16:44:32 -05:00
mc
780fe200ef
Merge branch 'main' into patch-2
2022-08-01 16:32:28 +01:00
mc
03f868d8ac
Update content/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file.md
2022-08-01 16:03:37 +01:00
mc
e98383c13a
Update content/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file.md
2022-08-01 15:48:53 +01:00
AlonaHlobina
64c49437d9
Obtaining detailed logs and debugging artifacts for the CodeQL Action ( #29425 )
...
* Create codeql-action-debug-logging.yml
* Update troubleshooting-the-codeql-workflow.md
* Update viewing-code-scanning-logs.md
* Update troubleshooting-the-codeql-workflow.md
* Apply suggestions from code review
Co-authored-by: Aditya Sharad <6874315+adityasharad@users.noreply.github.com >
* Update troubleshooting-the-codeql-workflow.md
* Don't use NWO
* Apply suggestions from code review
* Update content/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/troubleshooting-the-codeql-workflow.md
* Apply suggestions from code review
* Update content/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/viewing-code-scanning-logs.md
Co-authored-by: Aditya Sharad <6874315+adityasharad@users.noreply.github.com >
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com >
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com >
2022-08-01 11:14:08 +00:00
skedwards88
aea4b9c47c
rename references to virual-environments repo to runner-images
2022-07-29 12:33:18 -07:00
Landon Grindheim
a9355a55c2
Note that ACR is not currently supported
2022-07-29 15:15:12 -04:00
JonZeolla
1434aec1a9
Fix github.actor examples ( #19267 )
2022-07-28 09:30:19 +00:00
mc
2b15269a3d
[Ready to ship] Configuring the dependency review action on GHES ( #29064 )
2022-07-27 15:27:27 +00:00
Andy Barnes
441cfc54cf
Add pull-requests: write to permissions: block ( #29350 )
2022-07-27 08:09:51 +00:00
Sarah Edwards
012525e673
Document triggering_actor ( #28988 )
2022-07-26 22:54:58 +00:00
Mariam
8aa0adbe63
Secret scanning: Make pair matches visible in docs ( #29324 )
2022-07-26 19:16:54 +00:00
Sophie
3df2d7b47a
[2022-07-27]: Secret scanning: Email on bypass - [GA] ( #29233 )
2022-07-26 19:11:46 +00:00
Matt Pollard
dc2ba532b4
GitHub Enterprise Server 3.6 release candidate ( #28905 )
2022-07-26 18:56:17 +02:00
Benjamin Friedman Wilson
1268fee5fc
small typo fix for mispelled 'updating'
2022-07-26 09:44:40 +02:00
mc
8fcb5ad8c1
Fix mention of public repos in GHAE ( #29328 )
...
* fix mention of public in GHAE
* Update content/code-security/supply-chain-security/end-to-end-supply-chain/securing-code.md
Co-authored-by: Steve Guntrip <12534592+stevecat@users.noreply.github.com >
Co-authored-by: Steve Guntrip <12534592+stevecat@users.noreply.github.com >
2022-07-25 12:24:37 +00:00
Eli Reisman
0bc93e8437
Update Rust/Cargo Dependency Graph documentation ( #28976 )
2022-07-21 20:21:40 +02:00
Felicity Chapman
73b085ef8e
Secret scanning: fix typo in condition ( #29203 )
2022-07-21 10:27:19 +00:00
Felicity Chapman
40989e0ca6
"Security center" rename to "Security overview" ( #29120 )
2022-07-18 16:40:33 +00:00
Sarita Iyer
15c09dc0b2
Merge branch 'main' into dependabot-alerts-most-important-sort
2022-07-15 13:37:13 -04:00
Steve Guntrip
74d6918dae
Add GHAS resources
2022-07-15 13:57:26 +00:00
Jurre
d738183157
Dependabot: explain how to allow rebases over appended commits ( #29026 )
...
* Depedabot: explain how to allow rebases over appended commits
By default Dependabot stops rebasing PRs that have been altered, in some cases (especially when setting up automations that add commits to PRs automatically), this is not desirable, and it's preferable for Dependabot to force push over those commits, removing them and having the automation re-generate them.
This is a feature that's been present in Dependabot for a while already, but has not been documented, so let's document it.
* Update content/code-security/dependabot/working-with-dependabot/managing-pull-requests-for-dependency-updates.md
* Update content/code-security/dependabot/working-with-dependabot/managing-pull-requests-for-dependency-updates.md
Co-authored-by: Jurre <jurre@github.com >
* Update content/code-security/dependabot/working-with-dependabot/managing-pull-requests-for-dependency-updates.md
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com >
2022-07-14 14:04:12 +00:00
Sarita Iyer
ecea5682be
replace tip with note
2022-07-13 09:26:34 -04:00
Sarita Iyer
3c4200f16f
add variable
2022-07-12 17:30:38 -04:00
Sarita Iyer
f6776685c7
add info + screenshot about most important sort
2022-07-12 17:15:07 -04:00
Hector Alfaro
95e6f3d3ab
Deprecate GHES 3.1 ( #28798 )
...
* add 3.1 to deprecated versions
* rewrite img src to use azure blob storage in archive script
Co-authored-by: rachmari <rachmari@users.noreply.github.com >
* remove static files for ghes 3.1
* remove liquid conditionals and content for ghes 3.1
* remove outdated hardware reqs reusable
* Fix liquid conditional uncaught by script
* Close liquid conditionals missed by script
* Apply @mattpollard's suggestions
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com >
Co-authored-by: rachmari <rachmari@users.noreply.github.com >
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com >
2022-07-11 21:17:09 +00:00
Grey Baker
64266fc64e
Clarify when users receive secret scanning alert notifications ( #28822 )
...
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com >
2022-07-11 14:11:31 +00:00
Felicity Chapman
e67f797a19
Merge branch 'main' into adityasharad/codeql-ghes-version
2022-07-11 13:46:41 +01:00
Felicity Chapman
11c6980515
Add GHAE versioning too
2022-07-01 11:59:59 +01:00
mc
d328effc2b
[Already shipped] -Dependabot alerts: surface information about development dependencies - [GA] ( #28615 )
...
* made a start
* hmm hmm
* more work
* Optimize images
* improvements
* make table easier to read
* Apply suggestions from code review
Co-authored-by: Sarita Iyer <66540150+saritai@users.noreply.github.com >
* address review comments
Co-authored-by: github-actions <github-actions@github.com >
Co-authored-by: Sarita Iyer <66540150+saritai@users.noreply.github.com >
2022-06-30 07:53:12 +00:00
Janice
469e698b6a
Merge branch 'main' into patch-2
2022-06-28 19:02:38 +02:00
Kate Catlin
1e48a5756d
Adding Erlang as a supported language ( #28754 )
2022-06-28 15:44:47 +00:00
Matt Pollard
19dea423f0
Read from allVersions
2022-06-28 08:32:24 +02:00
Aditya Sharad
acaef98bb1
Update content/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/about-code-scanning-with-codeql.md
...
Co-authored-by: Felicity Chapman <felicitymay@github.com >
2022-06-27 12:46:32 -07:00
Andrew Eisenberg
8f60f05f96
Update code scanning configuration with how to run packs with paths ( #28535 )
...
Co-authored-by: Sarah Edwards <skedwards88@github.com >
2022-06-27 19:10:29 +00:00
Holmes-EH
ad478def75
Fix a typo in end of page link text
...
Change text from "updatng" to "updating"
2022-06-26 15:28:21 +02:00
Aditya Sharad
937910b32e
Code Scanning: Reference the CodeQL action by name, not URL
...
Notes do not render Markdown links.
2022-06-22 22:25:00 +00:00
Aditya Sharad
c4ff2d0579
Code Scanning: Remove unnecessary endif
2022-06-22 22:06:14 +00:00
Aditya Sharad
a82515877e
Code Scanning: State the recommended CodeQL version for GHES in the about page
2022-06-22 21:51:22 +00:00
Aditya Sharad
8154eb2f31
Code Scanning: Specify the recommended CodeQL version for each GHES version
...
Create new variables for the GHES version, and the CodeQL CLI version
recommended along with each GHES version.
Refactor the docs on installing the CodeQL CLI in a third-party CI system,
to use the CodeQL and GHES version from the variables.
These variables will need to be kept up to date with future GHES+CodeQL versions.
2022-06-22 21:36:11 +00:00
Felicity Chapman
1d2030a10a
Update information on support by Dependabot version updates for Pub as it moves from beta to GA ( #28047 )
2022-06-21 13:15:35 -07:00
Sarita Iyer
15a3beed99
Merge branch 'main' into dep-submission-api-dependency-graph-updates
2022-06-17 12:05:08 -04:00