
Explanation:
Box 1: GitHub Enterprise Cloud GitHub Enterprise Cloud
Automate vulnerability code scanning for public and private repositories Configuring secret scanning for your repositories Who can use this feature:
People with admin permissions to a public repository can enable secret scanning for the repository.
Secret scanning alerts for partners runs automatically on public repositories and public npm packages to notify service providers about leaked secrets on GitHub.com.
Secret scanning alerts for users are available for free on all public repositories. Organizations using GitHub Enterprise Cloud with a license for GitHub Advanced Security can also enable secret scanning alerts for users on their private and internal repositories. For more information, see "About secret scanning" and "About GitHub Advanced Security." Box 2:
Automate the generation of pull requests that remediate identified vulnerabilities.
Automatically updating dependencies with known vulnerabilities with Dependabot security updates Dependabot can help you fix vulnerable dependencies by automatically raising pull requests to update dependencies to secure versions.
Reference:
https://docs.github.com/en/code-security/secret-scanning/configuring-secret-scanning-for-your- repositories
https://docs.github.com/en/code-security/dependabot/dependabot-security-updates