🔥 3-day streak
GitHub Advanced Security (GH-500)88 / 144
Question 88 of 144

Your organization's dependency scanning has raised several Dependabot alerts across multiple repositories, all linked to a single GitHub Security Advisory (GHSA). Three days later, a security engineer notices that the upstream advisory has been marked as 'Withdrawn' in the GitHub Advisory Database, with a note that the vulnerability report was determined to be invalid. Some teams have already started upgrading the dependency. What is the most appropriate remediation-workflow response?

Reviewed for accuracy · Report an issueNext question