🔥 3-day streak
GitHub Advanced Security (GH-500)33 / 144
Question 33 of 144

An enterprise owner has enabled an allowlist of approved GitHub Actions. A security engineer wants organizations to use a shared, centrally maintained custom CodeQL workflow (rather than default setup) so that all repositories analyze code with the organization's mandated query pack. The custom workflow lives in a reusable-workflow repository and is called via a `uses:` reference. Developers report that when they add the reusable workflow reference to their repos, the CodeQL scan job never runs and Actions reports the workflow is not permitted. What is the MOST likely cause and correct remediation?

Reviewed for accuracy · Report an issueNext question