Files
probo/controls/application-security/source-code/APP-SRC-001_patch_review.md
gearnode 523cf4dbda Add missing steps
Signed-off-by: Bryan Frimin <bryan@frimin.fr>
2025-01-07 19:31:26 +01:00

1.0 KiB

id, category, revision-version, revision-date, estimate-time, frameworks
id category revision-version revision-date estimate-time frameworks
APP-SRC-001 application-security/source-code 1 2024-01-07 15m
name sections
soc2
CC1.4
CC5.2
CC8.1

Purpose

Requiring pull requests and code reviews ensures higher code quality and security by allowing multiple team members to catch bugs, inefficiencies, and potential vulnerabilities before code is merged. It also promotes collaboration, knowledge sharing, and accountability within the team. This process helps prevent issues in production and maintains adherence to coding standards.

Implementation

Github

  1. Open your GitHub repository and go to settings.
  2. In "Branche"s, click "Add Rule".
  3. Enter the branch name (e.g. "main") in the branch name pattern field.
  4. Enable: "Require a pull request before merging"
  5. Click Create or Save to apply the rule

Evidence

  • Screenshot of branch protection rules configuration
  • Documentation of PR review process
  • Sample PR showing enforced requirements