🔥 3-day streak
GitHub Advanced Security (GH-500)81 / 144
Question 81 of 144

You are the enterprise administrator for a GitHub Enterprise Cloud organization. Your security team wants developers to be able to run CodeQL default setup, but they also want to permit only a specific, vetted set of third-party GitHub Actions in workflows across all organizations — including a custom CodeQL Action fork the team maintains. Any other Actions should be blocked from running. What is the correct way to enforce this at scale while still allowing the approved custom CodeQL workflow?

Reviewed for accuracy · Report an issueNext question