Skip to lesson
Exit
Security agents and PR routing & approval1 / 2

2 min lesson

Protect an auth pull request

Configure one auth pull request so Security Reviewer runs first, policy requires human review and automated approval stays off.

Step 1 of 2

Put src/auth/APPROVAL_POLICY.md on the base branch. State that auth changes require a security-team review and cannot receive automated approval. Configure Security Reviewer for pull request opened and updated events. Configure PR Routing & Approval for the same repository with reviewer requests, Security Review Context, risk scoring and a low maximum approval risk. Open an auth pull request and wait for Security Reviewer to finish. Check that the required human reviewer is requested, the security result is visible and no automated approval appears. Inspect both Automation run histories. Test a separate copy-only pull request before widening the approval scope.

Protect the auth pull request

Interactive diagram. Step through it with the Next and Previous controls below, or Tab to a region to read its detail.

diagram: flow

Run security review before the routing and approval decision.

Learn more

Full explanation

Security Reviewer, policy file, risk threshold, human review

Route an auth pull request and keep its approval human
Security Reviewer, policy file, risk threshold, human review
SayThis pull request changes src/auth/session.ts and marketing copy. The auth change needs a security check and a human security reviewer. The copy change can follow the normal low-risk policy.
DoCreate a Security Reviewer for pull request opened and updated events on the repository. Enable the relevant built-in checks, add the auth instructions and give it the issue-tracker tool used for findings.
SeeThe Security Reviewer runs on changed code. A Vulnerability Scanner would be the separate cron-based choice for code at rest.
DoAdd src/auth/APPROVAL_POLICY.md on the base branch. Require a security-team review for auth changes and forbid automated approval there.
SeeThe closest applicable policy governs src/auth and takes priority over the generic approval prompt and risk threshold.
DoConfigure PR Routing & Approval for the same repository. Enable reviewer requests, Security Review Context and risk scoring. Set a low maximum approval risk.
SeeThe approval run waits for the Security Reviewer. A finding that needs human review or a score above the threshold blocks automated approval.
DoOpen the auth pull request, wait for the security check and inspect both Automation run histories and the pull request review state.
SeeThe security-team reviewer is requested, the security result is visible and the pull request has no automated approval. Test a separate copy-only pull request against the low-risk criteria before widening the scope.