Skip to main content
This page covers setting up Oplane reviews on your pull requests (GitHub) and merge requests (GitLab), and what to do with the review comment. For what a review is and what triggers it, see How reviews work.

Setup

Connect your repository through a repo-connected workspace, then follow the guide for your Git provider.
See Connect GitHub to install the Oplane GitHub App and link your repositories.
Then choose a review mode for the workspace: Analyse every PR/MR, On request, or Disabled. See What triggers a review.

Read the review comment

When you open or update a PR or MR, Oplane posts a single Oplane Security Review summary comment. It lists each requirement with its status and severity, and links to the generated threat model. Oplane updates the comment as requirements are resolved, so it always reflects the current review state. See Comment structure for what the comment contains. To act on the requirements in the comment, see Respond to requirements.

Suggested fixes

If suggested fixes are turned on for the repository, Oplane also writes a code fix for each unresolved requirement it can fix. A Fix with Oplane button then appears in the review comment. Click it to review the fixes and commit them to the PR or MR source branch. See Click to fix.

Block merges on findings

By default, the Oplane Security Review check doesn’t block a merge. To block merges while unresolved requirements sit at or above a severity you choose, see Merge gating.