View JFrog Dependabot Vulnerability Alerts

JFrog and GitHub Integration Guide

This topic outlines the steps to view vulnerability alerts.

  1. On GitHub, navigate to the main page of the repository.

  2. Under the repository name, click  Security. If you cannot see the Security tab, select the dropdown menu, and then click Security.

  3. In the Vulnerability alerts sidebar of the security overview, click Dependabot. If this option is missing, it means you don't have access to security alerts and need to be given access. For more information, see Managing security and analysis settings for your repository.

  4. In the Depedabot Alerts search field, filter by is:open package_registry:jfrog-artifactory.

    You can also add additional filters by applying is:open package_registry:jfrog-artifactory severity:critical,high

    To learn more, refer to Viewing Dependabot alerts.

    viewDependabotVulnerabilityAlerts.png