🔥 3-day streak
GitHub Advanced Security (GH-500)73 / 144
Question 73 of 144

A platform team maintains a Node.js monorepo where devDependencies (test runners, linters, build tooling) are numerous and frequently trigger Dependency Review failures on pull requests, blocking merges for vulnerabilities that never ship to production. The security lead wants Dependency Review to still fail the PR check for vulnerable production dependencies but stop failing on issues that only affect development-time packages. Which configuration approach for the Dependency Review action best achieves this?

Reviewed for accuracy · Report an issueNext question