🔥 3-day streak
GitHub Advanced Security (GH-500)10 / 144
Question 10 of 144

A security engineer fixed a CodeQL SQL-injection alert three months ago; the alert moved to 'Fixed' after the default branch was rescanned. This week a developer reverted part of that refactor in a new commit, reintroducing the vulnerable data-flow pattern on the default branch. Assuming CodeQL analysis runs on pushes to the default branch, what happens to the alert tracking, and what is the recommended remediation practice?

Reviewed for accuracy · Report an issueNext question