🔥 3-day streak
GitHub Advanced Security (GH-500)124 / 144
Question 124 of 144
A maintainer of a widely-used open-source library receives a private report that a deserialization flaw allows remote code execution. They want to fix the issue without tipping off attackers before users can patch, and they want a CVE assigned through GitHub. Using the GitHub Security Advisory end-to-end workflow, which sequence of actions correctly achieves coordinated disclosure?
Reviewed for accuracy · Report an issueNext question