Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft GH-500 Exam - Topic 2 Question 15 Discussion

-- [Configure and Use Dependency Management]You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?
D) When you merge a pull request that contains a security update
A) When Dependabot creates a pull request to update dependencies
B) When you dismiss the Dependabot alert
C) When the pull request checks are successful

Microsoft GH-500 Exam - Topic 2 Question 15 Discussion

Actual exam question for Microsoft's GH-500 exam
Question #: 15
Topic #: 2
[All GH-500 Questions]

-- [Configure and Use Dependency Management]

You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?

Show Suggested Answer Hide Answer
Suggested Answer: D

A Dependabot alert is marked as resolved only after the related pull request is merged into the repository. This indicates that the vulnerable dependency has been officially replaced with a secure version in the active codebase.

Simply generating a PR or passing checks does not change the alert status; merging is the key step.


Contribute your Thoughts:

0/2000 characters
Lashandra
5 days ago
Nah, it's definitely B. You can just ignore the alerts, right?
upvoted 0 times
...
Kristian
10 days ago
Definitely C, the checks need to pass first!
upvoted 0 times
...
Denise
15 days ago
Wait, so just dismissing the alert doesn't fix it? That's surprising!
upvoted 0 times
...
Brittni
20 days ago
I thought it was A at first, but D makes more sense.
upvoted 0 times
...
Stefan
25 days ago
It's D! Merging the PR resolves the alert.
upvoted 0 times
...
Sharika
1 month ago
I’m confused about this one. I thought it was when Dependabot creates a pull request, so I might go with A, but D seems plausible too.
upvoted 0 times
...
Corrina
1 month ago
I feel like I’ve seen a similar question before, and it was about the pull request checks being successful. Maybe it’s option C?
upvoted 0 times
...
Elmer
1 month ago
I’m not entirely sure, but I remember something about dismissing alerts. Could it be option B?
upvoted 0 times
...
Eura
3 months ago
I think Dependabot marks the alert as resolved when you merge a pull request that contains a security update, so I’m leaning towards option D.
upvoted 0 times
...

Save Cancel