🔥 3-day streak
GitHub Advanced Security (GH-500)17 / 144
Question 17 of 144

Your security team has enabled push protection and pre-merge CodeQL analysis on a critical microservice repository. A developer opens a pull request from a feature branch, and CodeQL flags a new SQL injection alert in the PR check. The developer argues the alert should not block the merge because 'the code isn't on the default branch yet, so it's not a real exposure.' As the security lead defining the org's shift-left enforcement strategy, which response best reflects correct preventive security practice?

Reviewed for accuracy · Report an issueNext question