🔥 3-day streak
GitHub Advanced Security (GH-500)69 / 144
Question 69 of 144
Your team has added the Dependency Review Action to a repository's pull request workflow to catch vulnerable dependencies before merge. Reviewers complain that they have to open the Actions run logs to see which dependencies were flagged, and they want a concise summary posted directly on the pull request itself. Which configuration change accomplishes this without adding a separate third-party bot?
Reviewed for accuracy · Report an issueNext question