Skip to content

Commit a7f6ee4

Browse files
authored
Security overview and :dependabot: fixes
1 parent 36e1a11 commit a7f6ee4

File tree

1 file changed

+33
-28
lines changed

1 file changed

+33
-28
lines changed

GHAS-on-GHES-feature-matrix.md

Lines changed: 33 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -146,17 +146,17 @@ Dependabot alerts tell you that your code depends on a package that is insecure.
146146
|Actions authors can automatically update dependencies within workflow files|||||||||||||
147147
|Dart and Flutter (using Pub) support for updates|||||||||||||
148148
|[Automatically pause pull request activity after 90 days of inactivity](https://docs.github.com/en/enterprise-server/code-security/dependabot/dependabot-security-updates/about-dependabot-security-updates#about-automatic-deactivation-of-dependabot-updates)|||||||||||||
149-
|[Grouped updates](https://docs.github.com/en/enterprise-server@3.11/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#groups)|||||||||||||
149+
|[Grouped version updates](https://docs.github.com/en/enterprise-server@3.11/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#groups)|||||||||||||
150150
|[Open pull requests for Swift and Gradle dependencies](https://docs.github.com/en/enterprise-server@3.11/code-security/dependabot/dependabot-security-updates/configuring-dependabot-security-updates)|||||||||||||
151151
|[REST API displays enablement status for Dependabot updates](https://docs.github.com/en/enterprise-server@3.11/rest/repos/repos)|||||||||||||
152-
|[Dependabot supports `devcontainer.json` files](https://docs.github.com/en/enterprise-server@3.13/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates#dev-containers)|||||||||||||
153-
|[Viewing Dependabot job logs](https://docs.github.com/en/enterprise-server@3.12/code-security/dependabot/working-with-dependabot/viewing-dependabot-job-logs)||||||||||||
154-
|[Dependabot access to Cargo private registries](https://docs.github.com/en/enterprise-server@3.14/code-security/dependabot/working-with-dependabot/guidance-for-the-configuration-of-private-registries-for-dependabot#about-configuring-private-registries-for-dependabot)||||||||||||
155-
|Dependabot pauses scheduled jobs after 15 failures.||||||||||||
152+
|[Dependabot supports `devcontainer.json` files](https://docs.github.com/en/enterprise-server@3.13/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates#dev-containers)|||||||||||||
153+
|[Viewing Dependabot job logs](https://docs.github.com/en/enterprise-server@3.12/code-security/dependabot/working-with-dependabot/viewing-dependabot-job-logs)|||||||||||||
154+
|[Dependabot access to Cargo private registries](https://docs.github.com/en/enterprise-server@3.14/code-security/dependabot/working-with-dependabot/guidance-for-the-configuration-of-private-registries-for-dependabot#about-configuring-private-registries-for-dependabot)|||||||||||||
155+
|Dependabot pauses scheduled jobs after 15 failures.|||||||||||||
156156
|[Dependabot grouped security updates](https://docs.github.com/en/enterprise-server@3.14/code-security/dependabot/dependabot-security-updates/about-dependabot-security-updates#about-grouped-security-updates)|||||||||||||
157157
|[Private registry support for target-branch configuration](https://docs.github.com/en/enterprise-server@3.14/code-security/dependabot/working-with-dependabot/configuring-access-to-private-registries-for-dependabot)|||||||||||||
158158

159-
#### Dependency Review and submission API
159+
#### Dependency Graph, Dependency Review and snapshot submission API
160160
Dependency review helps you understand dependency changes and the security impact of these changes at every pull request.
161161
* [Dependency review docs](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/configuring-dependency-review)
162162
* [Dependency review API docs](https://docs.github.com/en/rest/dependency-graph/dependency-review?apiVersion=2022-11-28)
@@ -168,35 +168,40 @@ Dependency review helps you understand dependency changes and the security impac
168168
|[Dependency Submission API](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/using-the-dependency-submission-api)||||||||||||
169169
|[Dependency Review supports transitive dependencies](https://docs.github.com/en/enterprise-server@3.11/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#best-practices-for-using-the-dependency-review-api-and-the-dependency-submission-api-together)||||||||||||
170170
|[Dependency Review supports dependencies from Dependency Submission API](https://docs.github.com/en/enterprise-server@3.11/code-security/supply-chain-security/understanding-your-software-supply-chain/using-the-dependency-submission-api)||||||||||||
171+
|SBOM generated for a package now includes the package URL for more packages||||||||||||
171172

172173
## Security Overview
173174
Security overview provides high-level summaries of the security status of an organization or enterprise and makes it easy to identify repositories that require intervention.
174175
* [Security Overview documentation](https://docs.github.com/en/enterprise-server/code-security/security-overview/about-security-overview)
175176

176-
|Feature |3.4 |3.5 |3.6 |3.7 |3.8 |3.9 |3.10| 3.11 |3.12|3.13|
177-
|------------------------------------------------------------|-----|-----|-----|-----|-----|-----|----|----|----|----|
178-
|[Security Overview](https://docs.github.com/en/enterprise-server/code-security/security-overview/about-security-overview)|||||||||||
179-
|Organization view|☑️||||||||||
180-
|Enterprise view||☑️|☑️||||||||
181-
|Organization-level Code Scanning Alert View|||||||||||
182-
|Organization-level Dependabot Alert View|||||||||||
183-
|Enterprse-level view of Dependabot alerts|||||||||||
184-
|Enterprse-level view of code scanning alerts|||||||||||
185-
|Enterprse-level view of secret scanning alerts|||||||||||
186-
|Coverage and Risk Security Overview pages|||||☑️|☑️|||||
187-
|[Filter alerts by repo topic](https://docs.github.com/en/enterprise-server/code-security/security-overview/filtering-alerts-in-security-overview)|||||||||||
188-
|[Filter alerts by team](https://docs.github.com/en/enterprise-server/code-security/security-overview/filtering-alerts-in-security-overview)|||||||||||
189-
|[Enable GHAS features in security overview](https://docs.github.com/en/enterprise-server/code-security/security-overview/about-security-overview)|||||||||||
190-
|[Enterprise-level security coverage and risk dashboards](https://docs.github.com/en/enterprise-server@3.10/code-security/security-overview/about-security-overview#about-security-overview-for-enterprises)|||||||||||
191-
|[Enablement trends dashboard is available](https://docs.github.com/en/enterprise-server@3.13/code-security/security-overview/assessing-adoption-code-security#viewing-enablement-trends-for-an-organization-beta)|||||||||||
177+
|Feature |3.4 |3.5 |3.6 |3.7 |3.8 |3.9 |3.10| 3.11 |3.12|3.13|3.14|
178+
|------------------------------------------------------------|-----|-----|-----|-----|-----|-----|-----|----|----|----|----|
179+
|[Security Overview](https://docs.github.com/en/enterprise-server/code-security/security-overview/about-security-overview)||||||||||||
180+
|Organization view|☑️|||||||||||
181+
|Enterprise view||☑️|☑️|||||||||
182+
|Organization-level Code Scanning Alert View||||||||||||
183+
|Organization-level Dependabot Alert View||||||||||||
184+
|Enterprse-level view of Dependabot alerts||||||||||||
185+
|Enterprse-level view of code scanning alerts||||||||||||
186+
|Enterprse-level view of secret scanning alerts||||||||||||
187+
|Coverage and Risk Security Overview pages|||||☑️|☑️||||||
188+
|[Filter alerts by repo topic](https://docs.github.com/en/enterprise-server/code-security/security-overview/filtering-alerts-in-security-overview)||||||||||||
189+
|[Filter alerts by team](https://docs.github.com/en/enterprise-server/code-security/security-overview/filtering-alerts-in-security-overview)||||||||||||
190+
|[Enable GHAS features in security overview](https://docs.github.com/en/enterprise-server/code-security/security-overview/about-security-overview)||||||||||||
191+
|[Enterprise-level security coverage and risk dashboards](https://docs.github.com/en/enterprise-server@3.10/code-security/security-overview/about-security-overview#about-security-overview-for-enterprises)||||||||||||
192+
|[Enablement trends dashboard is available](https://docs.github.com/en/enterprise-server@3.13/code-security/security-overview/assessing-adoption-code-security#viewing-enablement-trends-for-an-organization-beta)||||||||||||
193+
|[Enterprise level secret scanning metrics and enablement trend dashboards](https://docs.github.com/en/enterprise-server@3.14/code-security/security-overview/viewing-security-insights)||||||||||||
194+
|[Security overview dashboard group by tool](https://docs.github.com/en/enterprise-server@3.14/code-security/security-overview/viewing-security-insights#viewing-the-security-overview-dashboard-for-your-organization)||||||||||||
195+
|Security overview dashboard filter by security tool|||||||||||☑️|
192196

193-
## Administration
194-
|Feature |3.4 |3.5 |3.6 |3.7 |3.8 |3.9 |3.10 |3.11 |3.12 |3.13|
195-
|------------------------------------------------------------|-----|-----|-----|-----|-----|-----|----|----|----|----|
196-
|[Security Managers Role](https://docs.github.com/en/enterprise-server/organizations/managing-peoples-access-to-your-organization-with-roles/managing-security-managers-in-your-organization)|||||||||||
197-
|[Manage Security Managers role via the API](https://docs.github.com/en/enterprise-server/rest/orgs/security-managers?apiVersion=2022-11-28)|||||||||||
198-
|[Licensing for committers only after the migration date](https://docs.github.com/en/enterprise-server@3.12/billing/managing-billing-for-github-advanced-security/about-billing-for-github-advanced-security) |||||||||||
199197

198+
## Administration
199+
|Feature |3.4 |3.5 |3.6 |3.7 |3.8 |3.9 |3.10 |3.11 |3.12 |3.13|3.14|
200+
|------------------------------------------------------------|-----|-----|-----|-----|-----|-----|----|----|----|----|----|
201+
|[Security Managers Role](https://docs.github.com/en/enterprise-server/organizations/managing-peoples-access-to-your-organization-with-roles/managing-security-managers-in-your-organization)||||||||||||
202+
|[Manage Security Managers role via the API](https://docs.github.com/en/enterprise-server/rest/orgs/security-managers?apiVersion=2022-11-28)||||||||||||
203+
|[Licensing for committers only after the migration date](https://docs.github.com/en/enterprise-server@3.12/billing/managing-billing-for-github-advanced-security/about-billing-for-github-advanced-security) ||||||||||||
204+
|[Create and assign custom organization roles](https://docs.github.com/en/enterprise-server@3.14/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-organization-roles)||||||||||||
200205

201206
# Dependencies
202207
This section calls out the dependencies required to enable GitHub Advanced Security on GitHub Enterprise Server.

0 commit comments

Comments
 (0)