🔥 3-day streak
GitHub Advanced Security (GH-500)124 / 144
Question 124 of 144

A maintainer of a widely-used open-source library receives a private report that a deserialization flaw allows remote code execution. They want to fix the issue without tipping off attackers before users can patch, and they want a CVE assigned through GitHub. Using the GitHub Security Advisory end-to-end workflow, which sequence of actions correctly achieves coordinated disclosure?

Reviewed for accuracy · Report an issueNext question