{"meta":{"title":"Supply chain security","intro":"GitHub's security features help you keep track of your projects' dependencies and built artifacts.","product":"Security and code quality","breadcrumbs":[{"href":"/en/enterprise-server@3.19/code-security","title":"Security and code quality"},{"href":"/en/enterprise-server@3.19/code-security/concepts","title":"Concepts"},{"href":"/en/enterprise-server@3.19/code-security/concepts/supply-chain-security","title":"Supply chain security"}],"documentType":"subcategory"},"body":"# Supply chain security\n\nGitHub's security features help you keep track of your projects' dependencies and built artifacts.\n\n## Links\n\n* [Supply chain security](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/supply-chain-security)\n\n  GitHub helps you secure your supply chain, from understanding the dependencies in your environment, to knowing about vulnerabilities in those dependencies, and patching them.\n\n* [open-source-license-compliance](open-source-license-compliance)\n\n* [Best practices for maintaining dependencies](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/best-practices-for-maintaining-dependencies)\n\n  Guidance and recommendations for maintaining the dependencies you use, including GitHub's security products that can help.\n\n* [Dependency graph](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependency-graph)\n\n  You can use the dependency graph to identify all your project's dependencies. The dependency graph supports a range of popular package ecosystems.\n\n* [How the dependency graph recognizes dependencies](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependency-graph-data)\n\n  The dependency graph automatically analyzes manifest files. You can submit data for dependencies that cannot be detected automatically.\n\n* [Dependency review](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependency-review)\n\n  Dependency review lets you catch insecure dependencies before you introduce them to your environment, and provides information on license, dependents, and age of dependencies.\n\n* [Dependabot alerts](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependabot-alerts)\n\n  Dependabot alerts help you find and fix vulnerable dependencies before they become security risks.\n\n* [malware-alerts](malware-alerts)\n\n* [Metrics for Dependabot alerts](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependabot-alert-metrics)\n\n  Use metrics to track and prioritize Dependabot alerts across your organization.\n\n* [Dependabot security updates](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependabot-security-updates)\n\n  Dependabot can fix vulnerable dependencies for you by raising pull requests with security updates.\n\n* [Dependabot version updates](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependabot-version-updates)\n\n  You can use Dependabot to keep the packages you use updated to the latest versions.\n\n* [Dependabot pull requests](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependabot-pull-requests)\n\n  Understand the frequency and customization options of pull requests for version and security updates.\n\n* [Multi-ecosystem updates](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/multi-ecosystem-updates)\n\n  Multi-ecosystem updates combine dependency updates across multiple package ecosystems into a single pull request, reducing review overhead and simplifying your update workflow.\n\n* [About the dependabot.yml file](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/about-the-dependabot-yml-file)\n\n  The dependabot.yml controls automated dependency updates in your repository.\n\n* [Dependabot auto-triage rules](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependabot-auto-triage-rules)\n\n  Control how Dependabot handles security alerts, including filtering, ignoring, snoozing, or triggering security updates.\n\n* [dependabot-on-actions](dependabot-on-actions)\n\n* [Dependabot job logs](/en/enterprise-server@3.19/code-security/concepts/supply-chain-security/dependabot-job-logs)\n\n  GitHub logs every update job run by Dependabot, giving you visibility into version updates, security patches, and automated rebases across your dependencies.\n\n* [immutable-releases](immutable-releases)\n\n* [linked-artifacts](linked-artifacts)"}