🔥 3-day streak
GitHub Advanced Security (GH-500)134 / 144
Question 134 of 144
A financial services organization uses a code scanning severity ruleset that blocks merges when a high-severity alert exists. A team lead requests a permanent exception for one repository, arguing that a specific alert is a false positive tied to a legacy internal library. As the security manager responsible for governance, you want to grant relief without permanently weakening the control or losing visibility. Which approach best balances developer velocity with ongoing governance?
Reviewed for accuracy · Report an issueNext question