🔥 3-day streak
GitHub Advanced Security (GH-500)67 / 144
Question 67 of 144
A platform team wants the Dependency Review action to block pull requests only when a newly introduced dependency has a vulnerability rated 'high' or 'critical', while still surfacing lower-severity findings as informational comments without failing the check. Which configuration approach achieves this?
Reviewed for accuracy · Report an issueNext question