When approving an image on a pull request, the git sha is stored with the image. If a developer squashes his or her commits before merging into master, that pre-approval will slip through the cracks and it will appear on the master branch.
Maybe we can use solely the PR number to pre-approve an image