Proof of Presence (PoP) for Pull Requests – Re-authentication on PR merge & approval (Entra IdP) [Public Preview]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
When a repository policy requires it, developers approving or merging a pull request are prompted to complete a fresh, interactive MFA challenge through Microsoft Entra ID before the action goes through. This ensures that the specific person taking those high-impact actions is genuinely present and verified at the exact moment they matter — not just holding an active session. It adds a meaningful layer of identity assurance directly into the pull request workflow, without changing how teams collaborate day to day.
### Expected Outcome
Regulated organizations can now demonstrate, with a real-time identity check, that pull request approvals and merges were performed by an authorized, present individual — strengthening compliance with requirements like FDA 21 CFR Part 11. By anchoring proof of presence to the two most consequential points in the code review process, teams reduce the risk that compromised tokens or sessions could silently influence what ships to production.
贡献指南
调研方向
此路线图 issue 描述了通过 Microsoft Entra ID 对 pull request 批准和合并实施 Proof of Presence,但没有指出任何 repository 文件、测试或实现入口点。首先定位 pull request 批准和合并的身份验证流程;当已配置的策略在任一操作完成之前触发新的交互式 MFA 挑战时,即视为完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- azure
- 领域
- authentication
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 冷清
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100