Requirement status
Each security requirement has a status indicating whether it has been addressed. The PR/MR comment shows each status as a colored circle:Severity levels
Severity indicates how urgent a requirement is and guides your response:
On threat model cards in a workspace, each severity with unresolved requirements appears as a compact chip showing how many are left to fix, next to a progress ring showing overall completion. Unreviewed requirements are grouped into a single “unreviewed” chip. Hover over the ring to see resolved/total counts per severity.
Check status
Oplane posts an Oplane Security Review check on each PR/MR with one of these conclusions:
By default, merge blocking is off and unresolved requirements report Neutral, which GitHub and GitLab treat as passing. Turn on Block merges on unresolved findings per repository and pick a severity on the slider to have the check report Action required when unresolved requirements reach a level you care about. GitHub branch protection treats Action required as non-passing, so it blocks the merge just like a failure. GitLab has no equivalent state, so the check reports a blocking Failed status instead. Combined with your branch protection rules, this acts as a merge gate. See Merge gating for the setup on GitHub and GitLab.
The check’s summary counts unresolved requirements, for example
1 of 3 security requirements need attention, or All 3 security requirements resolved once everything is addressed. The check’s details link opens the generated threat model.
Info severity is advisory and never contributes to the failure threshold, even at the lowest Low setting.
Comment structure
Oplane posts a single Oplane Security Review summary comment on your PR/MR and keeps it up to date as the review state changes. The comment contains:Summary headline
States how many requirements need attention and links to the generated threat model.Requirements table
Lists every requirement with its current status, title, and severity. Unresolved requirements are sorted first, ordered by severity (Critical → Info). Each unresolved row includes fix links to hand the requirement to your coding agent.Fix with Oplane button
Shown below the table when suggested fixes are turned on for the repository and Oplane has finished generating them. It opens a page where you review the fixes and commit them to the branch. See Click to fix.Agent instructions
An instruction block embedded in the comment’s markdown, hidden in the rendered view. Coding agents can pick it up to fetch the threat model and report implementation status via MCP. See MCP setup.Respond to requirements
Learn how to respond to requirements and run local checks.