Proof of Presence (PoP) for Pull Requests – Re-authentication on PR merge & approval (Entra IdP) [Public Preview]
- 主要言語
- 言語のデータがありません
- スター
- 8.9k
- フォーク
- 1.8k
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
### Value Prop
When a repository policy requires it, developers approving or merging a pull request are prompted to complete a fresh, interactive MFA challenge through Microsoft Entra ID before the action goes through. This ensures that the specific person taking those high-impact actions is genuinely present and verified at the exact moment they matter — not just holding an active session. It adds a meaningful layer of identity assurance directly into the pull request workflow, without changing how teams collaborate day to day.
### Expected Outcome
Regulated organizations can now demonstrate, with a real-time identity check, that pull request approvals and merges were performed by an authorized, present individual — strengthening compliance with requirements like FDA 21 CFR Part 11. By anchoring proof of presence to the two most consequential points in the code review process, teams reduce the risk that compromised tokens or sessions could silently influence what ships to production.
コントリビューションガイド
調査の方向性
This roadmap issue describes Proof of Presence for pull request approvals and merges through Microsoft Entra ID, but it names no repository files, tests, or implementation entry points. Start by locating the pull request approval and merge authentication flows; done would mean the configured policy triggers a fresh interactive MFA challenge before either action completes.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- azure
- 領域
- authentication
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 静か
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 25/100