Governance
Decide what can merge and what gets reviewed: configurable merge gates, process checks, overrides that take a second person, and rules that live next to the code they govern.
Five gates decide whether a PR can merge: security findings, dependency CVEs, review findings, copyleft licenses and a minimum quality score. Each blocks or warns at the severity and count you set, org-wide or per repository, with a history of every change.
A blocked PR is unblocked with
/codity-unblockby anyone except its author. Every override is recorded with who, when and the reason given, so exceptions stay auditable.Require a minimum number of approvals, a linked ticket, tests for changed code, or named sections in the PR description. Checks are re-run on every push and every approval.
A
codity-rules.yamlin any folder applies to everything beneath it: keep generated or vendored code out of review entirely, and give the reviewer instructions for that part of the codebase. The same rules can be edited in the dashboard.Review when a PR opens or on every commit, and only for PRs that target the branches you list, such as
mainorrelease/*. Skipped PRs can get a short note, and@codity reviewstill reviews any PR on request.Reply
@codity this is intentional,false positiveoraccepted riskon a finding and Codity remembers it for future reviews in that repository. Say it will be fixed later and it is deferred for the rest of that PR only.
Merge policy
Org defaultMore Features
- Code NavigationA live architecture map, component health from Repo X-Ray, and answers across every repository.
- Developer AnalyticsReview latency, rework, throughput and DORA metrics per team and repository.
- Monitoring & InsightsContinuous repository monitoring with anomaly detection and deployment insight.
- Repo ScanA one-off, whole-repository review by eight specialist reviewers.
- PentestingBlack-box and active DAST testing of your live application, with evidence-checked findings.
- Model EvaluationEvaluate your LLM feature with tests written from what it is meant to do.
- ReviewsContext-aware pull request review with summaries, requirement tracking, re-reviews and autofix.
- Security ScansSecrets, injection, auth gaps, dependency risk and an org-wide SBOM, caught before the merge.

