Instructor

GH - 500T00 : GitHub Advanced Security Training

Curriculum

Ratings

( 4.5 Ratings )

Live Online Classes starting on 01 January, 1970

GH - 500T00 : GitHub Advanced Security

The "GH-500T00: GitHub Advanced Security" course offers an in-depth exploration of GitHub's security features, including secret scanning, code scanning with CodeQL, and dependency management. Participants will learn to configure and utilize these tools to enhance their software development security posture. The GH-500 course also covers administrative aspects, such as setting security policies and managing sensitive data within GitHub.

 

GitHub Advanced Security – GH-500 Course Objectives:

  • Understand and configure GitHub Advanced Security features.​

  • Implement Dependabot for automated dependency updates.​

  • Set up and manage secret scanning to protect sensitive information.​

  • Configure code scanning using CodeQL for vulnerability detection.​

  • Analyze and interpret CodeQL scan results.​

  • Administer security policies and manage sensitive data within GitHub

 

Target Audience for GitHub Advanced Security

GitHub Advanced Security equips professionals with the skills to secure software projects and manage vulnerabilities, catering to the growing need for security in software development.

  • DevOps Engineers

  • Software Developers

  • Security Engineers

  • Product Managers

  • Cloud Architects

  • IT Security Analysts

  • Application Security Specialists

  • Quality Assurance Engineers

  • System Administrators

  • Cybersecurity Professionals

  • Software Architects

  • Incident Response Teams

  • Compliance Officers

  • Technical Support Engineers

 

Course Outline:

GitHub Advanced Security – Part 1 of 2

1. Introduction to GitHub Advanced Security (GHAS)

  • Define GitHub Advanced Security (GHAS) and its core features: Secret Scanning, Code Scanning, and Dependabot

  • Understand the role of GHAS in enhancing security in the development lifecycle

  • Learn how to leverage GHAS to maximize security impact

2. Managing Vulnerable Dependencies with Dependabot

  • Configure Dependabot security updates on a GitHub repository

  • Explore tools for managing vulnerable dependencies

  • Enable and configure Dependabot alerts and security updates

  • Understand required permissions and roles for Dependabot

  • Identify, review, and resolve vulnerable dependencies

  • Use the GraphQL API to retrieve vulnerability information

  • Configure notifications for vulnerable dependencies

Lab:

  • Configure Dependabot Security Updates

3. Secret Scanning in GitHub

  • Understand what secret scanning is and how it helps prevent sensitive data leaks

  • Configure and enable secret scanning for a repository

  • Utilize secret scanning results effectively

4. Code Scanning on GitHub

  • Understand the concept and importance of code scanning

  • Steps to enable code scanning in a repository

  • Enable code scanning with both GitHub-native tools and third-party analysis tools

  • Compare CodeQL implementation using GitHub Actions vs third-party CI tools

  • Configure code scanning using various triggering events (scheduled or on-demand)

GitHub Advanced Security – Part 2 of 2

1. Identifying Security Vulnerabilities with CodeQL

  • Use CodeQL to create a database representation of your codebase

  • Run CodeQL queries to detect security vulnerabilities

  • Interpret scan results using built-in and custom queries

2. Code Scanning with GitHub CodeQL

  • Learn what CodeQL is and how it analyzes code

  • Understand QL, the logic programming language behind CodeQL

  • Set up CodeQL-based scanning in GitHub repositories

  • Reference and use custom CodeQL queries

  • Configure the language matrix in CodeQL workflows

  • Use the CodeQL CLI to generate and upload results

  • Implement custom build steps for effective analysis

Labs:

  • Reference a CodeQL Query

  • Configure a CodeQL Language Matrix

3. GitHub Administration for Advanced Security

  • Understand how to apply GHAS in the software development lifecycle

  • Identify features available for open-source and enterprise environments

  • Enable GHAS features across different enterprise plans

  • Assign correct access and permissions to users

  • Set organization and repository-level security policies

  • Respond effectively to security alerts

  • Monitor security alerts using the Security Overview dashboard

  • Use GitHub Advanced Security API endpoints for automation and management

4. Managing Sensitive Data and Policies

  • Create clear documentation with security guidelines

  • Set permissions and rules to protect data

  • Automate security processes to prevent breaches

  • Understand how to respond to and mitigate security incidents

(4.5 Ratings)

Download Course Contents

Still unsure?
We're just a click away


Course Outline PDF

SpireTec Unique Features

course-img
1-On-1 Training

Benefit from our 1-On-1 Training for personalized, focused, and effective learning experiences.

course-img
Customized Training

Experience our Customized Training service tailored to meet your specific learning needs and goals

course-img
4 - Hours / Weekend Session

Join our Class featuring 4 - Hours / Weekend Session for in-depth learning and expert training.

course-img
Free Demo Class

Join our Free Demo Class to experience top-notch training and expert guidance first hand!

Purchase This Course

Request More Information

CERTIFICATE

Get Ahead With SpireTec Solutions
Training Certificate

Earn your Certificate

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Differentiate yourself with Masters Certificate

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Share your achievement

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Need Customized Curriculum?

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Talk To Adviser
course-certificate

Top Certifications