Click to fix is in early access. It’s only available to organisations that Oplane has turned it on for. If you don’t see the settings below, contact your Oplane representative.
Turn on suggested fixes
Suggested fixes are off by default. You turn them on per repository in workspace settings, so you need to be a workspace owner or an org admin. See Roles and permissions.1
Open workspace settings
Open the workspace connected to the repository and go to its settings.
2
Find the repository
Find the linked repository and make sure PR/MR analysis is enabled.
3
Choose a fix level
Under Suggest fixes for findings, select Manual. Oplane then generates a fix for each unresolved finding it can fix automatically, and nothing gets committed until you apply it.
oplane review on it.
If your organisation also has autofix turned on, the dropdown has an Autofix option. With Autofix, Oplane commits every suggested fix automatically without anyone clicking Implement.
Open the fixes from your PR or MR
After the review finishes and the fixes are ready, the Oplane Security Review comment on the PR or MR gets a Fix with Oplane button. The button only appears once Oplane has generated all the fixes, so it can take a little longer to show up than the comment itself. Click Fix with Oplane to open the fix page for that threat model in Oplane.
The Fix with Oplane button at the bottom of the Oplane Security Review comment.
Review the suggested fixes
The fix page lists the PR or MR requirements in three groups in the sidebar:
Select a requirement to see its rationale, the affected files, and a diff of the suggested change. Switch between Split and Unified to change how the diff is shown.

The fix page for a pull request, with a suggested fix selected and its diff in split view.
If a new review starts on the PR or MR while you’re on the fix page, the page is paused until the review finishes. That way you always apply fixes against the latest findings.