PowerBI Data Analyst - Create visualizations and dashboards from scratch
40% Off Career-Building Certificates
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn to assess and manage security risks in project dependencies through this 13-minute training video from the Eclipse Foundation Security Training 2025 series. Explore real-world supply chain security threats including the XZ and Log4j incidents, and discover how to proactively mitigate risks using automated tools like Dependabot. Master the evaluation of dependency risks by understanding common security questions and utilizing resources like the Best Practices Badge system. Gain hands-on knowledge of security alert systems, learn to triage alerts effectively, and make informed decisions about dependency updates. Understand how to automate dependency updates while maintaining project stability, and access comprehensive resources for ongoing security maintenance of your software projects.
Syllabus
00:00 Introduction to Dependency Risks
00:19 Evaluating Risk of Dependencies
03:36 Common Questions
5:15 Evaluating Dependencies: Best Practices Badge
06:00 Introduction to Dependabot
07:18 Security Alerts: How They Work
09:27 Triaging Alerts & Making Informed Decisions
10:56 Automating Updates with Dependabot
11:32 Version Updates & Ongoing Maintenance
12:00 Getting Started Resources & Handbook Links
Taught by
Eclipse Foundation