> ## Documentation Index
> Fetch the complete documentation index at: https://www.oplane.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Threat model statuses and severity reference

> A quick reference for the statuses, severity levels, and check results you'll encounter in Oplane's PR/MR reviews and threat models.

A quick reference for the statuses, severity levels, and check results you'll encounter in Oplane's PR/MR reviews and threat models.

## Requirement status

Each security requirement has a status indicating whether it has been addressed. The PR/MR comment shows each status as a colored circle:

| Color | State | Meaning |
| - | - | - |
| 🔴 | Not assessed | Oplane hasn't assessed the requirement yet |
| 🔴 | Not implemented | The security requirement has not been addressed in the code |
| 🟠 | Partially implemented | Some aspects are addressed but gaps remain |
| 🟢 | Implemented | Fully addressed in the code |
| ⚪ | Out of scope | Handled at a different layer (e.g. infrastructure, gateway) |
| 🟡 | Accepted risk | Risk acknowledged with justification, not mitigated |
| ⚪ | Not applicable | Irrelevant to this context |

## Severity levels

Severity indicates how urgent a requirement is and guides your response:

| Severity | Description | Expected Response |
| - | - | - |
| Critical | Exploitable vulnerability with severe impact | Address before merging |
| High | Significant security risk | Address before merging or document accepted risk |
| Medium | Moderate risk | Address in normal workflow |
| Low | Minor risk | Address when convenient |
| Info | Informational, no direct risk | Review and acknowledge |

On threat model cards in a workspace, each severity with unresolved requirements appears as a compact chip showing how many are left to fix, next to a progress ring showing overall completion. Unreviewed requirements are grouped into a single "unreviewed" chip. Hover over the ring to see resolved/total counts per severity.

## Check status

Oplane posts an **Oplane Security Review** check on each PR/MR with one of these conclusions:

| Status | Condition |
| - | - |
| Pass (green) | No unresolved requirements, or every visible requirement is resolved |
| Neutral | Unresolved requirements exist and merge blocking is turned off, or none of them meet the configured severity threshold |
| Action required (amber on GitHub, Failed on GitLab) | Merge blocking is turned on and at least one unresolved requirement sits at or above the configured severity |
| Fail (red) | The review itself failed to complete |

By default, merge blocking is off and unresolved requirements report **Neutral**, which GitHub and GitLab treat as passing. Turn on **Block merges on unresolved findings** per repository and pick a severity on the slider to have the check report **Action required** when unresolved requirements reach a level you care about. GitHub branch protection treats **Action required** as non-passing, so it blocks the merge just like a failure. GitLab has no equivalent state, so the check reports a blocking **Failed** status instead. Combined with your branch protection rules, this acts as a merge gate. See [Merge gating](/docs/prove/merge-gating#check-failure-threshold) for the setup on GitHub and GitLab.

The check's summary counts unresolved requirements, for example `1 of 3 security requirements need attention`, or `All 3 security requirements resolved` once everything is addressed. The check's details link opens the generated threat model.

<Note>
  **Info** severity is advisory and never contributes to the failure threshold, even at the lowest **Low** setting.
</Note>

## Comment structure

Oplane posts a single **Oplane Security Review** summary comment on your PR/MR and keeps it up to date as the review state changes. The comment contains:

#### Summary headline

States how many requirements need attention and links to the generated threat model.

#### Requirements table

Lists every requirement with its current status, title, and severity. Unresolved requirements are sorted first, ordered by severity (Critical → Info). Each unresolved row includes fix links to hand the requirement to your coding agent.

#### Fix with Oplane button

Shown below the table when suggested fixes are turned on for the repository and Oplane has finished generating them. It opens a page where you review the fixes and commit them to the branch. See [Click to fix](/docs/fix/click-to-fix).

#### Agent instructions

An instruction block embedded in the comment's markdown, hidden in the rendered view. Coding agents can pick it up to fetch the threat model and report implementation status via MCP. See [MCP setup](/docs/find/mcp).

<Card title="Respond to requirements" icon="wrench" href="/docs/find/respond-to-requirements">
  Learn how to respond to requirements and run local checks.
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.