Merge Gates
Merge gates decide whether a Codity review blocks a pull request from merging. There are five, each covering one kind of result, and each can block the merge or only warn, at the severity and count you set.
The gates control the merge block described in Merge Block on Failed Review.
The Five Gates
| Gate | What it checks |
|---|---|
| SEC | Security (SAST) findings |
| DEP | Dependency CVEs |
| REV | Inline review findings |
| LIC | Copyleft licenses |
| QUAL | A minimum composite quality score for the pull request |
Settings for Each Gate
| Setting | What it controls |
|---|---|
| On / off | Whether the gate is used |
| Block or warn | Whether the gate blocks the merge or only warns |
| Severity threshold | The severity a finding must reach to count against the gate |
| Allowed count | How many of those findings the gate allows |
QUAL works differently: instead of a severity threshold and a count, it takes a score floor. The default floor is 70.
Defaults
The defaults reproduce how the merge block behaved before the gates were configurable:
- Any critical SEC, DEP or REV finding blocks the merge.
- LIC is advisory.
Scope and History
Set the gates as an organization default, or for specific repositories. Every change is kept in a change history.
Configuring Merge Gates
Merge gates live under Settings → Policies → Merge blocking. Only account admins can edit them. Merge gates are available on the Premium plan.
On the Pull Request
The Codity comment on the pull request shows a table of the gates and links to the policy page.
A blocked pull request can still be unblocked with /codity-unblock, by anyone other than its author. See Overriding the Block with /codity-unblock for the rules and the audit trail.
Platforms
Merge gates work on GitHub, GitLab, Bitbucket and Azure DevOps.
For a block to stop the merge, your Git platform has to require Codity's status check. The setup for each platform, including the exact status name, is in Configure your VCS to require the status.
Additional Resources
- Policy Checks: process requirements such as approvals, ticket references and tests
- Security Scanning: what the security, dependency and license scans report

