I would appreciate any help to find a way to make it impossible for any single person to make changes to the master branch of a Github repository without having that change reviewed by another person. Using the usual branch protection rules, I have been unable to see how I can prevent the following scenario:
- Person A makes a legitimate PR.
- Person B inserts a malicious change to the PR. Then reviews the PR with their own malicious change, and subsequently merges to master.
I have considered raising the number of required reviews from 1->2, but I would prefer another solution.
Any help is greatly appreciated, thank you.