A PR gate is a required check on a pull request that must pass before merge. In Azure DevOps, branch policies on protected branches enforce this: required reviewers, linked work items, build validation, and external status checks that services post against the PR. Security scanners use the status-check surface to gate merges on the diff's findings.

Why the PR is a powerful surface

  • Feedback lands while the developer still has context — the cheapest moment to fix.
  • The insecure change never enters the protected branch, so nothing downstream inherits it.
  • Statuses are visible in review, making security part of the code conversation.

PR gates vs build gates

PR gates evaluate the diff before merge; build gates evaluate the assembled artifact before shipping. Each catches what the other misses — post-merge interactions on one side, late feedback on the other. The failure mode to avoid is two gates with two policies producing contradictory verdicts.

RELATED CONCEPTS