🔥 3-day streak
GitHub Advanced Security (GH-500)28 / 144
Question 28 of 144
Your security team ingests SARIF files produced by an external SAST tool into GitHub code scanning using the SARIF upload API. Some large SARIF uploads are being rejected or silently truncated, and developers complain that certain alerts never appear in the Security tab. Which characteristic of GitHub's SARIF ingestion should the team account for to ensure their results are reliably processed?
Reviewed for accuracy · Report an issueNext question