🔥 3-day streak
GitHub Advanced Security (GH-500)96 / 144
Question 96 of 144

A platform security engineer wants to strengthen preventive security so that newly introduced vulnerabilities in application code are caught before they reach the default branch. Developers currently rely on a nightly scheduled CodeQL scan that reports findings a day after merge. The team complains that vulnerabilities are only discovered once they are already in main, forcing costly follow-up remediation. Which change best shifts detection left for code-level vulnerabilities?

Reviewed for accuracy · Report an issueNext question