Connect Oplane to GitLab projects for automated threat modeling on merge requests. No app install required — just sign in with your GitLab account.
Connect Oplane to your GitLab projects to enable automated threat modeling on merge requests. No app installation required — just sign in with your GitLab account.
1
Open Workspaces
Navigate to Workspaces in the left sidebar and click the + Workspace button in the top right corner.
Click the + Workspace button
2
Add a repository source
On the New Workspace page, enter a name and optional description, then under Sources, click Continue with GitLab to connect your account.
3
Sign in to GitLab
Oplane redirects you to GitLab to sign in. Enter your credentials or use one of the alternative sign-in methods (Google, GitHub, Bitbucket, Salesforce, or Passkey).Once authenticated, GitLab redirects you back to Oplane with your account connected.
4
Select a project
Back in Oplane, select your group from the dropdown and search for the project you want to connect.
Oplane lists only GitLab projects where you are Maintainer or Owner. This access level is required to create a project access token.
GitLab groups already claimed by a different Oplane organisation appear greyed out in the picker and cannot be selected. See Namespace claims for details.
5
Configure the workspace
Once connected, configure your workspace settings:
Analyse Pull Requests — Enable to automatically threat model every MR. If disabled, you can still trigger reviews by mentioning @oplane in an MR comment.
Access — Add team members who should have access to this workspace.
Click Create when ready.
6
Choose threat models
Oplane analyses your repository and suggests threat models based on the codebase. Select the ones relevant to your project, or describe your own scope.
What's next?
Learn how Oplane reviews your merge requests in the Pull & Merge Requests guide.
Check failure threshold
Set a failure threshold to use the Oplane Security Review check as a merge gate in GitLab merge-request approvals.
⌘I
Assistant
Responses are generated using AI and may contain mistakes.