🔥 3-day streak
GitHub Advanced Security (GH-500)123 / 144
Question 123 of 144
You are a maintainer of a popular open-source library. A researcher privately reports a deserialization flaw. You create a draft GitHub Security Advisory, collaborate on a fix in a temporary private fork, and prepare to publish. Before publishing, you want Dependabot to alert downstream consumers with an accurate severity and to properly attribute the reporter. Which action ensures both a machine-readable severity for downstream Dependabot alerts and correct researcher attribution when the advisory is published?
Reviewed for accuracy · Report an issueNext question