🔥 3-day streak
GitHub Advanced Security (GH-500)66 / 144
Question 66 of 144

A platform team enforces the Dependency Review Action on all repositories with a policy to fail any pull request introducing a dependency with a 'high' or 'critical' vulnerability. A development team is blocked by a specific critical advisory (GHSA-xxxx-yyyy-zzzz) in a transitive dependency that has no available patch, but their security team has assessed the vulnerable code path as unreachable and approved a temporary exception. The team wants their PRs to pass the check for only this one advisory while keeping the strict severity gate active for all other vulnerabilities. Which Dependency Review Action configuration option should they use?

Reviewed for accuracy · Report an issueNext question