Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,295,628
Community Members
 
Community Events
165
Community Groups

"Suggest a Change" feature circumvents approval restrictions

It's pretty common compliance practice to prevent people from approving their own PRs, this is by default how bitbucket PRs work.   In that same vein, it's important for change management and compliance controls that all changes are approved by someone else.

 

By using the in-line "Suggest a change" feature, someone with write access can suggest an in-line code change on someone else's PR, approve that change themselves (?!), then approve the PR, and finnaly merge that PR.  That effectively allows them to add un-reviewed/tested code to a PR, and merge it.

Is there a way to disallow

  •  Suggesters from approving their own suggestion
  • Approving a PR if your user has authored ANY commit to the PR
  • or just disable the "suggest a change" feature if we can't do the above

0 answers

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Bitbucket

Git push size limits are coming to Bitbucket Cloud starting April 4th, 2022

Beginning on April 4th, we will be implementing push limits. This means that your push cannot be completed if it is over 3.5 GB. If you do attempt to complete a push that is over 3.5 GB, it will fail...

2,170 views 2 9
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you