{"meta":{"title":"Reference for supply chain security","intro":"Find information to apply to your work with Dependabot and the dependency graph.","product":"Security and code quality","breadcrumbs":[{"href":"/en/enterprise-cloud@latest/code-security","title":"Security and code quality"},{"href":"/en/enterprise-cloud@latest/code-security/reference","title":"Reference"},{"href":"/en/enterprise-cloud@latest/code-security/reference/supply-chain-security","title":"Supply chain security"}],"documentType":"subcategory"},"body":"# Reference for supply chain security\n\nFind information to apply to your work with Dependabot and the dependency graph.\n\n## Links\n\n* [Automatic dependency submission](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/automatic-dependency-submission)\n\n  Network access requirements, troubleshooting, and ecosystem-specific behavior for automatic dependency submission.\n\n* [Dependabot options reference](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/dependabot-options-reference)\n\n  Detailed information for all the options you can use to customize how Dependabot maintains your repositories.\n\n* [Dependabot alert filters](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/dependabot-alerts-filters)\n\n  Dependabot alerts filters help you prioritize and manage alerts for vulnerable dependencies in your repositories.\n\n* [Supported ecosystems and manifests for dependency scope](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/supported-ecosystems-and-manifests-for-dependency-scope)\n\n  Dependabot alerts supports a variety of ecosystems and manifests for dependency scope.\n\n* [Dependabot pull request comment commands](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/dependabot-pull-request-comment-commands)\n\n  Dependabot responds to commands in comments on its pull requests, making it easy to triage and manage dependency updates.\n\n* [Dependabot supported ecosystems and repositories](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories)\n\n  Dependabot supports a variety of ecosystems and repositories\n\n* [Dependabot security updates reference](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/dependabot-security-updates)\n\n  Find usage information for Dependabot security updates.\n\n* [Dependency graph supported package ecosystems](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/dependency-graph-supported-package-ecosystems)\n\n  Dependency graph supports a variety of ecosystems.\n\n* [Dependabot on GitHub Actions](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/dependabot-on-actions)\n\n  Detailed information on using Dependabot with GitHub Actions.\n\n* [CWEs used by GitHub's preset Dependabot rules](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/criteria-for-preset-rules)\n\n  GitHub uses industry-standard criteria to help you filter Dependabot alerts.\n\n* [Troubleshoot Dependabot](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/troubleshoot-dependabot)\n\n  Resolve dependency security issues with error codes, diagnostic information, and solutions for common problems.\n\n* [Java package metadata for Dependabot updates](/en/enterprise-cloud@latest/code-security/reference/supply-chain-security/java-package-metadata-dependabot)\n\n  Include metadata in your pom.xml file to provide helpful links and context in Dependabot pull requests for Java package updates."}