🔥 3-day streak
GitHub Advanced Security (GH-500)45 / 144
Question 45 of 144

Your security team created a custom secret pattern to detect your company's proprietary API tokens (format: ACME-[A-Z0-9]{32}). After the pattern was validated with a dry run and published across the organization, developers report that these tokens are still being committed and appear only as retroactive alerts, never blocked at commit time. What must the team do so that these custom-pattern tokens are blocked before they enter the repository?

Reviewed for accuracy · Report an issueNext question