Skip to main content

New features

Check failure threshold

Control when the Oplane Security Review check reports Fail by setting a severity threshold. Combined with your CI pipeline’s branch protection rules, this acts as a merge gate that keeps unresolved requirements above the level you choose from slipping through. Because the check runs during code review, requirements surface before deployment rather than after. You pick the threshold that fails the check (critical, high, medium, low, or any), and info-severity findings never cause a failure. Resolving a requirement in Oplane clears the failing check on the last reviewed commit, so there’s no need to push again just to update the status. The threshold is opt-in per workspace, and your CI pipeline still decides whether a failing check actually blocks the merge. See Check failure threshold for the full setup.

Claim your Git namespace

Organisations can now claim a GitHub organisation or GitLab group so only their Oplane workspaces can subscribe to repositories under it. This keeps all threat models and security data for your repositories inside your Oplane organisation even when team members connect via personal Git accounts, so they belong to the organisation instead of ending up scattered across personal workspaces. Claiming also removes the ambiguity about which Oplane organisation owns which repositories when several teams share a Git provider. PR reviews keep working even if the person who originally connected the repository leaves or loses access. See Namespace claims for details.