Merge Gates

Merge gates decide whether a Codity review blocks a pull request from merging. There are five, each covering one kind of result, and each can block the merge or only warn, at the severity and count you set.

The gates control the merge block described in Merge Block on Failed Review.

The Five Gates

Gate What it checks
SEC Security (SAST) findings
DEP Dependency CVEs
REV Inline review findings
LIC Copyleft licenses
QUAL A minimum composite quality score for the pull request

Settings for Each Gate

Setting What it controls
On / off Whether the gate is used
Block or warn Whether the gate blocks the merge or only warns
Severity threshold The severity a finding must reach to count against the gate
Allowed count How many of those findings the gate allows

QUAL works differently: instead of a severity threshold and a count, it takes a score floor. The default floor is 70.

Defaults

The defaults reproduce how the merge block behaved before the gates were configurable:

  • Any critical SEC, DEP or REV finding blocks the merge.
  • LIC is advisory.

Scope and History

Set the gates as an organization default, or for specific repositories. Every change is kept in a change history.

Configuring Merge Gates

Merge gates live under Settings → Policies → Merge blocking. Only account admins can edit them. Merge gates are available on the Premium plan.

On the Pull Request

The Codity comment on the pull request shows a table of the gates and links to the policy page.

A blocked pull request can still be unblocked with /codity-unblock, by anyone other than its author. See Overriding the Block with /codity-unblock for the rules and the audit trail.

Platforms

Merge gates work on GitHub, GitLab, Bitbucket and Azure DevOps.

For a block to stop the merge, your Git platform has to require Codity's status check. The setup for each platform, including the exact status name, is in Configure your VCS to require the status.

Additional Resources

  • Policy Checks: process requirements such as approvals, ticket references and tests
  • Security Scanning: what the security, dependency and license scans report