🔥 3-day streak
GitHub Advanced Security (GH-500)101 / 144
Question 101 of 144

A developer at your company is pushing a commit to a private repository that has Push Protection enabled. The push is blocked because GitHub detected a string that matches a known secret provider pattern. The developer insists the value is a fake, non-functional API key used only in a mocked unit test and is not a real credential. According to GitHub best practices, what is the MOST appropriate way for the developer to proceed so the push succeeds while maintaining a proper audit trail?

Reviewed for accuracy · Report an issueNext question