> ## Documentation Index
> Fetch the complete documentation index at: https://www.oplane.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Automated threat modeling on pull and merge requests

> Set up Oplane reviews on GitHub pull requests and GitLab merge requests, and act on the security feedback in code review before merging.

This page covers setting up Oplane reviews on your pull requests (GitHub) and merge requests (GitLab), and what to do with the review comment. For what a review is and what triggers it, see [How reviews work](/docs/how-it-works/reviews).

## Setup

Connect your repository through a [repo-connected workspace](/docs/how-it-works/workspaces#connecting-a-repository), then follow the guide for your Git provider.

<Tabs>
  <Tab title="GitHub">
    See [Connect GitHub](/docs/connect/github) to install the Oplane GitHub App and link your repositories.
  </Tab>

  <Tab title="GitLab">
    See [Connect GitLab](/docs/connect/gitlab) to sign in with GitLab and select your projects. If your team runs its own GitLab server, add it first as a [self-managed GitLab integration](/docs/connect/gitlab-self-managed).
  </Tab>
</Tabs>

Then choose a review mode for the workspace: **Analyse every PR/MR**, **On request**, or **Disabled**. See [What triggers a review](/docs/how-it-works/reviews#what-triggers-a-review).

## Read the review comment

When you open or update a PR or MR, Oplane posts a single **Oplane Security Review** summary comment. It lists each requirement with its status and severity, and links to the generated threat model. Oplane updates the comment as requirements are resolved, so it always reflects the current review state. See [Comment structure](/docs/reference/statuses-and-severity#comment-structure) for what the comment contains.

To act on the requirements in the comment, see [Respond to requirements](/docs/find/respond-to-requirements).

## Suggested fixes

If suggested fixes are turned on for the repository, Oplane also writes a code fix for each unresolved requirement it can fix. A **Fix with Oplane** button then appears in the review comment. Click it to review the fixes and commit them to the PR or MR source branch. See [Click to fix](/docs/fix/click-to-fix).

## Block merges on findings

By default, the **Oplane Security Review** check doesn't block a merge. To block merges while unresolved requirements sit at or above a severity you choose, see [Merge gating](/docs/prove/merge-gating).

## Read next

* [Respond to requirements](/docs/find/respond-to-requirements)
* [Merge gating](/docs/prove/merge-gating)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.