Skip to content
This repository was archived by the owner on Sep 1, 2022. It is now read-only.

Commit 124aaa4

Browse files
committed
add note about enabling Dependabot alerts
1 parent d53ee9a commit 124aaa4

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

responses/01_find-vulnerabilities.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,9 +35,10 @@ Use Dependabot alerts to identify a vulnerable NPM dependency.
3535

3636
1. Click the **Security** tab in your repository.
3737
2. On the left hand navigation bar, click **Dependabot alerts**.
38-
3. Click on the `debug` alert.
39-
4. Take note of the suggested version.
40-
5. Comment in this issue with the suggested update version.
38+
3. Follow the instructions to enable Dependabot alerts, if they're not already enabled.
39+
4. Click on the `debug` alert.
40+
5. Take note of the suggested version.
41+
6. Comment in this issue with the suggested update version.
4142

4243

4344
> _**GitHub Enterprise Server only:** This is all possible on GitHub Enterprise through GitHub Connect. It may take up to an hour to refresh the alerts and make them visible. After waiting a reasonable amount of time, if you are still not seeing the yellow bar in the Dependency Graph, you may want to contact your administrator. In the mean time, to move along with the course, we'll give you a hint - the recommended upgraded version is `2.6.9`._

0 commit comments

Comments
 (0)