{"meta":{"title":"Supply chain security for your enterprise","intro":"You can enable enterprise-level features that help your developers understand and update the dependencies their code relies on.","product":"Security and code quality","breadcrumbs":[{"href":"/en/enterprise-server@3.22/code-security","title":"Security and code quality"},{"href":"/en/enterprise-server@3.22/code-security/concepts","title":"Concepts"},{"href":"/en/enterprise-server@3.22/code-security/concepts/security-at-scale","title":"Security at scale"},{"href":"/en/enterprise-server@3.22/code-security/concepts/security-at-scale/supply-chain-security","title":"Supply chain security"}],"documentType":"article"},"body":"# Supply chain security for your enterprise\n\nYou can enable enterprise-level features that help your developers understand and update the dependencies their code relies on.\n\nYou can allow users to identify their projects' dependencies by enabling the dependency graph for GitHub Enterprise Server. For more information, see [Enabling the dependency graph for your enterprise](/en/enterprise-server@3.22/code-security/how-tos/secure-at-scale/configure-enterprise-security/configure-specific-tools/enable-dependency-graph).\n\nAfter you enable the dependency graph, users will have access to the dependency review feature. Dependency review helps you understand dependency changes and the security impact of these changes at every pull request. For more information, see [Dependency review](/en/enterprise-server@3.22/code-security/concepts/supply-chain-security/dependency-review).\n\nYou can also allow users to find and fix vulnerabilities in their code dependencies by enabling Dependabot alerts and Dependabot updates. For more information, see [Enabling Dependabot for your enterprise](/en/enterprise-server@3.22/admin/configuring-settings/configuring-github-connect/enabling-dependabot-for-your-enterprise).\n\nAfter you enable Dependabot alerts, you can view vulnerability data from the GitHub Advisory Database on GitHub Enterprise Server and manually sync the data. For more information, see [Viewing the vulnerability data for your enterprise](/en/enterprise-server@3.22/code-security/how-tos/secure-at-scale/configure-enterprise-security/configure-specific-tools/view-vulnerability-data)."}