2 min lesson
Protect an auth pull request
Configure one auth pull request so Security Reviewer runs first, policy requires human review and automated approval stays off.
Step 1 of 2
Put src/auth/APPROVAL_POLICY.md on the base branch. State that auth changes require a security-team review and cannot receive automated approval. Configure Security Reviewer for pull request opened and updated events. Configure PR Routing & Approval for the same repository with reviewer requests, Security Review Context, risk scoring and a low maximum approval risk. Open an auth pull request and wait for Security Reviewer to finish. Check that the required human reviewer is requested, the security result is visible and no automated approval appears. Inspect both Automation run histories. Test a separate copy-only pull request before widening the approval scope.
Interactive diagram. Step through it with the Next and Previous controls below, or Tab to a region to read its detail.
Run security review before the routing and approval decision.
Learn more
Full explanation