QuestionQ38

AI-assisted security

A detection engineering team wants to use AI to automatically keep vulnerable code from reaching production. Which of the following is the most effective approach for accomplishing this task?

Explanation

A code-analysis control executed in the CI/CD pipeline can enforce a release gate: when it identifies vulnerable code, it fails the build so the artifact cannot progress toward production. GitHub’s code-scanning documentation likewise describes code scanning as analyzable within CI/CD systems and supports blocking merges when required scans find vulnerabilities.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!