Question 1
Q1A financial services company is implementing GitHub Advanced Security for their new Go-based microservices application. The security team requires that any new dependency added to a pull request must be checked against a list of pre-approved licenses. If a non-approved license is detected, the pull request must be blocked from merging. Which GitHub feature and configuration should be used to enforce this policy?
Show answer & explanation
Correct answer: B
The Dependency Review feature, implemented as a GitHub Actions workflow (dependency-review-action), is specifically designed for this purpose. It runs on pull requests and can be configured with allow-licenses or deny-licenses to check for license compliance. By making this workflow a required status check, it can effectively block pull requests that introduce dependencies with non-compliant licenses. The dependabot.yml file is for configuring Dependabot updates, not for license checks on pull requests. Repository rulesets can enforce that the workflow runs, but the license logic is within the action itself. Secret scanning does not handle dependency licenses.