🔥 3-day streak
GitHub Advanced Security (GH-500)6 / 144
Question 6 of 144
A security lead at a fintech company wants CodeQL code scanning to block pull requests only when a newly introduced alert has a 'critical' or 'high' severity, while allowing lower-severity alerts to be merged after review. Developers should still see all alerts in the PR conversation. Which configuration best achieves this outcome?
Reviewed for accuracy · Report an issueNext question