🔥 3-day streak
GitHub Advanced Security (GH-500)37 / 144
Question 37 of 144

A DevOps engineer maintains a CodeQL advanced-setup workflow for a large repository. Currently the workflow triggers only on a weekly schedule, and developers complain that vulnerabilities introduced in feature branches are not surfaced until long after merge. The team wants CodeQL to analyze code as it is proposed, blocking regressions before they reach the default branch, while keeping scheduled scans for baseline coverage. Which change to the workflow's trigger configuration best meets this goal?

Reviewed for accuracy · Report an issueNext question