問題文
A security team wants automated analysis of the organization's own source code to find vulnerabilities such as injection flaws, with results shown as alerts in each repository. Which feature provides this?
選択肢
- The dependency graph, which lists the packages a repository depends on.
- Dependabot alerts, which report known vulnerabilities in the project's dependencies and therefore also cover the injection flaws that reach the code through those libraries.
- Code scanning, which can use the CodeQL analysis engine to examine the repository's code and raise alerts.
- Secret scanning, which detects credentials committed to the repository.