SiteShadow
Back to vulnerability library

QP04 Code Reviews Practices

What this means

SiteShadow flagged signals that code reviews may be bypassed or not required for changes that reach mainline.

Why it matters

Code review is a core control for quality and security.

Safer examples

1) Require PRs and reviews for mainline

Protect main/master; block direct pushes.

2) Use a security checklist for risky changes

Auth, permissions, crypto, file handling, outbound requests, dependency updates.

3) Enforce "two person" rule for sensitive areas

Require additional reviewers for auth/infra/security config changes.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Request access View coverage