🔥 3-day streak
GitHub Advanced Security (GH-500)51 / 144
Question 51 of 144
A security team at a fintech company wants developers to be blocked from merging pull requests that introduce new high-severity code scanning alerts, but they also need a controlled escape hatch: when a genuine business emergency requires a hotfix, a specific group of designated security reviewers should be able to approve the exception rather than any developer simply overriding the block. The team wants this handled natively through GitHub's enforcement mechanisms without disabling the protection entirely. Which approach best meets these requirements?
Reviewed for accuracy · Report an issueNext question