🔥 3-day streak
GitHub Advanced Security (GH-500)91 / 144
Question 91 of 144

You are the security admin for an organization on GitHub Enterprise Cloud with GitHub Advanced Security enabled. A newly formed application security team needs to view and triage Dependabot alerts across all repositories in the organization, but company policy states they must NOT be granted write/push access to code and must NOT be organization owners. Developers on individual teams should continue to see alerts only for their own repositories. What is the most appropriate way to grant the appsec team the access they need?

Reviewed for accuracy · Report an issueNext question