# Reference for supply chain security

Find information to apply to your work with Dependabot and the dependency graph.

## Links

* [Automatic dependency submission](/en/code-security/reference/supply-chain-security/automatic-dependency-submission)

  Network access requirements, troubleshooting, and ecosystem-specific behavior for automatic dependency submission.

* [Dependabot options reference](/en/code-security/reference/supply-chain-security/dependabot-options-reference)

  Detailed information for all the options you can use to customize how Dependabot maintains your repositories.

* [Dependabot alert filters](/en/code-security/reference/supply-chain-security/dependabot-alerts-filters)

  Dependabot alerts filters help you prioritize and manage alerts for vulnerable dependencies in your repositories.

* [Supported ecosystems and manifests for dependency scope](/en/code-security/reference/supply-chain-security/supported-ecosystems-and-manifests-for-dependency-scope)

  Dependabot alerts supports a variety of ecosystems and manifests for dependency scope.

* [Dependabot pull request comment commands](/en/code-security/reference/supply-chain-security/dependabot-pull-request-comment-commands)

  Dependabot responds to commands in comments on its pull requests, making it easy to triage and manage dependency updates.

* [Dependabot supported ecosystems and repositories](/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories)

  Dependabot supports a variety of ecosystems and repositories

* [Dependabot security updates reference](/en/code-security/reference/supply-chain-security/dependabot-security-updates)

  Find usage information for Dependabot security updates.

* [Dependency graph supported package ecosystems](/en/code-security/reference/supply-chain-security/dependency-graph-supported-package-ecosystems)

  Dependency graph supports a variety of ecosystems.

* [Dependabot on GitHub Actions](/en/code-security/reference/supply-chain-security/dependabot-on-actions)

  Detailed information on using Dependabot with GitHub Actions.

* [CWEs used by GitHub's preset Dependabot rules](/en/code-security/reference/supply-chain-security/criteria-for-preset-rules)

  GitHub uses industry-standard criteria to help you filter Dependabot alerts.

* [Troubleshoot Dependabot](/en/code-security/reference/supply-chain-security/troubleshoot-dependabot)

  Resolve dependency security issues with error codes, diagnostic information, and solutions for common problems.

* [Java package metadata for Dependabot updates](/en/code-security/reference/supply-chain-security/java-package-metadata-dependabot)

  Include metadata in your pom.xml file to provide helpful links and context in Dependabot pull requests for Java package updates.