🔥 3-day streak
GitHub Advanced Security (GH-500)70 / 144
Question 70 of 144
A platform team wants to stop new pull requests from introducing dependencies with known vulnerabilities or non-compliant licenses, giving reviewers this information directly in the PR before merge. Dependabot alerts are already enabled, but the team says alerts fire only after code is merged into the default branch. Which Supply Chain Security feature should they add to enforce checks at the pull request stage?
Reviewed for accuracy · Report an issueNext question