🔥 3-day streak
GitHub Advanced Security (GH-500)54 / 144
Question 54 of 144
A security engineer at a fintech company notices that a critical vulnerability was recently disclosed in a widely-used npm logging library. Several of the company's repositories declare this library in their package-lock.json files. The engineer wants to understand which repositories are affected without manually inspecting each one. Which GitHub supply chain security mechanism identifies affected repositories by comparing their dependency data against known vulnerability records?
Reviewed for accuracy · Report an issueNext question