Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft Exam GH-500 Topic 5 Question 2 Discussion

Actual exam question for Microsoft's GH-500 exam
Question #: 2
Topic #: 5
[All GH-500 Questions]

-- [Configure and Use Dependency Management]

In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?

Show Suggested Answer Hide Answer
Suggested Answer: C

To detect and block vulnerable dependencies before merge, developers should use the Dependency Review GitHub Action in their pull request workflows. It scans all proposed dependency changes and flags any packages with known vulnerabilities.

This is a preventative measure during development, unlike Dependabot, which reacts after the fact.


Contribute your Thoughts:

Currently there are no comments in this discussion, be the first to comment!


Save Cancel