Check failure threshold
By default, the Oplane Security Review check reports Neutral when unresolved requirements exist. GitHub branch protection and GitLab merge-request approvals treat Neutral as passing, so the check surfaces findings without blocking a merge. Turn on Block merges on unresolved findings per repository to have the check block whenever an unresolved requirement sits at or above a severity you choose. Combined with your Git provider’s branch or merge rules, this acts as a merge gate to prevent unresolved requirements from slipping through.- GitHub
- GitLab
The check shows an amber Action required conclusion, which branch protection treats as non-passing, so it blocks the merge exactly like a failure. Red Fail is reserved for reviews that failed to complete.
1 of 3 security requirements need attention, and reads All 3 security requirements resolved once everything is addressed. The check’s details link opens the generated threat model.
Configure the failure threshold
- Open the workspace connected to the repository.
- Go to workspace settings and find the linked repository. Make sure PR/MR analysis is enabled. The merge-gate setting only appears while analysis is on.
- Turn on the Block merges on unresolved findings switch.
-
Pick a severity on the slider. The slider runs from Low to Critical and starts at Low the first time you enable the switch:
Info requirements are advisory and never cause the check to block, even at the Low setting.
Use as a merge gate
Oplane does not modify your branch protection or merge settings. You control which branches enforce the check by marking it as required in your Git provider.- GitHub
- GitLab
Open the repository’s Settings → Branches → Branch protection rules (or Settings → Rules → Rulesets), edit the rule for the target branch, and add
Oplane Security Review under Require status checks to pass before merging. Once you have finished editing the rule, set the Enforcement Status to Active.Once the check is required, GitHub blocks the merge whenever Oplane reports Action required.Clear a blocking check without a new push
Resolving a requirement in Oplane re-posts the Oplane Security Review check on the same commit SHA that Oplane reviewed. You do not need to push a new commit to clear a blocking check. Both of the following trigger a refresh:- Marking a requirement as resolved, out of scope, or accepted risk in the Oplane dashboard.
- Calling the MCP
update_implementation_statetool from your coding agent.
Shared repositories
When multiple workspaces subscribe to the same repository or project, Oplane posts a single Oplane Security Review check per commit. The strictest failure threshold across those workspaces wins for that repository and commit. For example, if one workspace has merge blocking turned off and another set to High, unresolved High or Critical requirements cause the check to block.Read next
- Check status, for every state the check can report.
- Respond to requirements, to resolve what’s blocking.