{"meta":{"title":"供应链安全","intro":"GitHub 的安全功能有助于帮助您跟踪项目的依赖项和构建产物。","product":"安全性和代码质量","breadcrumbs":[{"href":"/zh/enterprise-cloud@latest/code-security","title":"安全性和代码质量"},{"href":"/zh/enterprise-cloud@latest/code-security/concepts","title":"Concepts"},{"href":"/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security","title":"供应链安全"}],"documentType":"subcategory"},"body":"# 供应链安全\n\nGitHub 的安全功能有助于帮助您跟踪项目的依赖项和构建产物。\n\n## Links\n\n* [供应链安全](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/supply-chain-security)\n\n  GitHub 有助于保护供应链，从了解环境中的依赖项到了解这些依赖项中的漏洞，以及修补这些漏洞。\n\n* [关于开源许可证合规](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/open-source-license-compliance)\n\n  使用开放源代码许可证符合性定义并强制实施存储库中依赖项的许可证策略。\n\n* [维护依赖项的最佳做法](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/best-practices-for-maintaining-dependencies)\n\n  有关维护您所使用依赖项的指导和建议，以及可提供帮助的 GitHub 安全产品。\n\n* [依赖项关系图](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependency-graph)\n\n  您可以使用依赖关系图来识别项目的所有依赖项。 依赖关系图支持一系列流行的软件包生态系统。\n\n* [依赖项图如何识别依赖项](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependency-graph-data)\n\n  依赖项图会自动分析清单文件。 可以提交无法自动检测到的依赖项的数据。\n\n* [依赖项审查](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependency-review)\n\n  依赖项评审 允许在将依赖项引入环境之前捕获不安全的依赖项，并提供有关许可证、依赖项和依赖项年龄的信息。\n\n* [Dependabot 警报](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-alerts)\n\n  Dependabot alerts 帮助你查找和修复存在漏洞的依赖项，以防它们成为安全风险。\n\n* [Dependabot 恶意软件警报](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/malware-alerts)\n\n  Dependabot malware alerts 帮助你识别依赖项中的恶意软件，以保护项目及其用户。\n\n* [Dependabot 警报指标](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-alert-metrics)\n\n  使用指标跟踪和确定整个组织的优先级 Dependabot alerts 。\n\n* [Dependabot 安全更新](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-security-updates)\n\n  Dependabot 可以通过发起包含安全更新的拉取请求，为您修复存在漏洞的依赖项。\n\n* [Dependabot 版本更新](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-version-updates)\n\n  你可以使用 Dependabot 来使你使用的软件包保持更新到最新版本。\n\n* [Dependabot 拉取请求](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-pull-requests)\n\n  了解版本和安全更新的拉取请求频率及其自定义选项。\n\n* [多生态系统更新](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/multi-ecosystem-updates)\n\n  多生态系统更新将多个包生态系统中的依赖项更新合并为单个拉取请求，减少评审开销并简化更新工作流。\n\n* [关于 dependabot.yml 文件](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/about-the-dependabot-yml-file)\n\n  dependabot.yml 控制存储库中的自动依赖项更新。\n\n* [Dependabot 自动分类规则](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-auto-triage-rules)\n\n  Dependabot控制如何处理安全警报，包括筛选、忽略、阻止或触发安全更新。\n\n* [GitHub Actions 运行器上的 Dependabot](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-on-actions)\n\n  如果你为存储库启用了 GitHub，Dependabot 会自动在 GitHub Actions 上运行生成 GitHub Actions 拉取请求的工作。 启用 Dependabot 后，这些作业将在运行时绕过存储库或组织级别的 Actions 策略检查和禁用限制。\n\n* [Dependabot 作业日志](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-job-logs)\n\n  GitHub 记录由 Dependabot 运行的每次更新作业，让你清楚了解依赖项中的版本更新、安全补丁以及自动变基情况。\n\n* [不可变版本](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/immutable-releases)\n\n  了解不可变版本以及它们如何帮助维护软件供应链的完整性。\n\n* [关于关联的项目](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/linked-artifacts)\n\n  linked artifacts page 帮助你在 GitHub 上审计并优先处理组织的构建，无论制品存储在哪里。"}