All features

Governance

Decide what can merge and what gets reviewed: configurable merge gates, process checks, overrides that take a second person, and rules that live next to the code they govern.

  • Five gates decide whether a PR can merge: security findings, dependency CVEs, review findings, copyleft licenses and a minimum quality score. Each blocks or warns at the severity and count you set, org-wide or per repository, with a history of every change.

  • A blocked PR is unblocked with /codity-unblock by anyone except its author. Every override is recorded with who, when and the reason given, so exceptions stay auditable.

  • Require a minimum number of approvals, a linked ticket, tests for changed code, or named sections in the PR description. Checks are re-run on every push and every approval.

  • A codity-rules.yaml in any folder applies to everything beneath it: keep generated or vendored code out of review entirely, and give the reviewer instructions for that part of the codebase. The same rules can be edited in the dashboard.

  • Review when a PR opens or on every commit, and only for PRs that target the branches you list, such as main or release/*. Skipped PRs can get a short note, and @codity review still reviews any PR on request.

  • Reply @codity this is intentional, false positive or accepted risk on a finding and Codity remembers it for future reviews in that repository. Say it will be fixed later and it is deferred for the rest of that PR only.

codity/settings⌘K

Merge policy

Org default
SEC · Security findingsblock at critical · 0 allowedBlock
DEP · Dependency CVEsblock at critical · 0 allowedBlock
REV · Review findingsblock at critical · 0 allowedBlock
LIC · Copyleft licensesadvisoryWarn
QUAL · Quality scoreblock below 70Block

More Features