Skip to content
GitLab
Next
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • GitLab GitLab
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 44,761
    • Issues 44,761
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 1,329
    • Merge requests 1,329
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GitLab.orgGitLab.org
  • GitLabGitLab
  • Issues
  • #5981
Closed
Open
Issue created May 11, 2018 by Paul Knopf@pauldotknopfContributor

Require password authentication for merge request approval.

CFR Part 11 compliance for digitally signed change requests. Specifically, this.

For FDA/government regulated workflows, there must be a way to ensure that the authorized user was the person who approved a merge request. Otherwise, it could be said that someone else did it on a computer that was already logged in. This improves accountability.

We have done an extensive review of the features of GitLab EE, and this is the only thing preventing medical companies from using GitLab EE for product documentation and risk management.

BitBucket server has a plugin that offers this feature. https://marketplace.atlassian.com/apps/1211303/workzone-pullrequest-workflow?hosting=server&tab=overview

Assignee
Assign to
Time tracking