A security scan in a CI pipeline produces 200 low-severity findings and 2 critical findings. Which response aligns with DevSecOps best practices?
-
A
Fail the build only on the critical findings and require immediate remediation
-
B
Fail the build on all 202 findings regardless of severity
-
C
Ignore all findings and proceed to production
-
D
Archive findings and review them quarterly