🔥 3-day streak
GitHub Advanced Security (GH-500)25 / 144
Question 25 of 144

Your organization runs CodeQL analysis on a self-hosted Jenkins pipeline instead of GitHub Actions because your build toolchain is highly customized. After the CodeQL CLI produces a `results.sarif` file, the team needs those results to appear as code scanning alerts in the repository's Security tab on GitHub.com. Which approach correctly delivers the SARIF results into GitHub code scanning?

Reviewed for accuracy · Report an issueNext question