Skip to main content
This page explains what happens when Oplane reviews a pull request (GitHub) or merge request (GitLab). For the steps to set up reviews and act on them, see Review pull and merge requests.

What a review produces

When you open or update a PR or MR, Oplane analyses the diff, creates a threat model scoped to the changes, and posts the requirements in a single Oplane Security Review summary comment on the PR or MR. Oplane reads the diff, identifies architectural and security-relevant changes, and generates security requirements specific to what changed. All findings appear in one summary comment that lists each requirement with its status and severity, and links to the generated threat model. Oplane updates the comment as requirements are resolved, so it always reflects the current review state. See Comment structure for what the comment contains. Oplane also reports the result as an Oplane Security Review check on the reviewed commit. By default the check doesn’t block a merge. See Merge gating to make it block.

What triggers a review

You configure how Oplane reviews PRs and MRs per workspace:
  • Analyse every PR/MR: Oplane runs automatically on every new pull request or merge request. Best for projects with active development.
  • On request: Mention oplane review, @oplane review, oplane run, or @oplane run in a comment on any PR or MR to trigger a review when you need it.
  • Disabled: No automatic reviews for this workspace.