🔥 3-day streak
GitHub Advanced Security (GH-500)55 / 144
Question 55 of 144

A platform team enables Dependabot alerts across all repositories. In one Node.js repository, they notice that a Dependabot alert for a vulnerability affecting a package listed only under devDependencies was automatically dismissed by GitHub, even though the maintainers never manually reviewed it. The team wants to understand why this happened so they can decide whether to change the behavior. Which explanation correctly describes this auto-dismiss behavior?

Reviewed for accuracy · Report an issueNext question