diff --git a/code-review/config.mdx b/code-review/config.mdx index f831b36..28642da 100644 --- a/code-review/config.mdx +++ b/code-review/config.mdx @@ -170,7 +170,7 @@ release branches except `release/legacy/**`. ## Include scans -Use the include block to scan **only** pull and merge requests that match specific rules. Hacktron records a skip check comment on PRs/MRs it doesn't scan. +Use the include block to scan **only** pull and merge requests that match specific rules. Hacktron records a skipped check on PRs/MRs it doesn't scan and, if [code review comments](/platform/organization-settings#code-review-comments) are on, a skip comment. ```yaml include: @@ -204,7 +204,7 @@ include: ## Fail the check on findings -By default, the Hacktron check is green as long as the scan completes. Findings are posted as inline comments but don't block the merge. Configure a severity threshold to turn the check **red** when a finding is at or above that level. +By default, the Hacktron check is green as long as the scan completes, and findings are posted as inline comments but don't block the merge. Configure a severity threshold to turn the check **red** when a finding is at or above that level. ![Failed check example](/images/fail_on_failure_example.png) diff --git a/code-review/findings-feedback.mdx b/code-review/findings-feedback.mdx index 2e6b1fd..bd60a61 100644 --- a/code-review/findings-feedback.mdx +++ b/code-review/findings-feedback.mdx @@ -3,7 +3,7 @@ title: "Findings and feedback" description: "Understand where Hacktron posts Code Review findings and how feedback improves future reviews." --- -Hacktron posts Code Review findings where developers already work. +By default, Hacktron posts Code Review findings where developers already work. Admins can turn this off in [Code review comments](/platform/organization-settings#code-review-comments). ## Inline findings diff --git a/code-review/overview.mdx b/code-review/overview.mdx index e48c0ab..94be089 100644 --- a/code-review/overview.mdx +++ b/code-review/overview.mdx @@ -3,7 +3,7 @@ title: "Code Review" description: "Use Code Review to run continuous pull request security reviews across connected repositories." --- -Code Review reviews pull requests and merge requests in the repositories you enable. Hacktron reads each change with repository context, looks for exploitable vulnerabilities, and comments directly on affected code so engineers can fix issues before merge. +Code Review reviews pull requests and merge requests in the repositories you enable. Hacktron reads each change with repository context and looks for exploitable vulnerabilities. By default, Hacktron comments directly on affected code so engineers can fix issues before merge. Use Code Review for continuous security coverage on day-to-day development. For broader, scoped assessments of a repository or application, use [White-box Pentest](/white-box-pentest/overview). diff --git a/code-review/troubleshooting.mdx b/code-review/troubleshooting.mdx index 128c89d..47adaa6 100644 --- a/code-review/troubleshooting.mdx +++ b/code-review/troubleshooting.mdx @@ -36,7 +36,7 @@ If only some pull requests or merge requests are reviewed: ## Developer is not covered If a developer is not covered by a Code Review seat, -Hacktron leaves a pull request comment explaining that no seat is assigned. +Hacktron marks the check as skipped. If [code review comments](/platform/organization-settings#code-review-comments) are on, Hacktron also leaves a pull request comment explaining that no seat is assigned. Check **Billing** to confirm the organization has trial or paid review capacity available. diff --git a/images/code_review_comments.png b/images/code_review_comments.png new file mode 100644 index 0000000..246d8d2 Binary files /dev/null and b/images/code_review_comments.png differ diff --git a/platform/organization-settings.mdx b/platform/organization-settings.mdx index 01d31f3..c2d3da4 100644 --- a/platform/organization-settings.mdx +++ b/platform/organization-settings.mdx @@ -1,6 +1,6 @@ --- title: "Organization settings" -description: "Configure scan filters, the check gate, and SLA thresholds for your organization." +description: "Configure scan filters, the check gate, code review comments, and SLA thresholds for your organization." --- Organization settings apply to every repository unless a repository's `.hacktron/config.yaml` overrides them. Only organization admins and owners can change these settings. @@ -60,6 +60,28 @@ Set an org-wide severity threshold that fails a PR or MR check when a finding me See [Fail the check on findings](/code-review/config#fail-the-check-on-findings) for the full severity table and per-repository overrides. +## Code review comments + +Choose whether Hacktron posts scan results as comments on your pull requests and merge requests. This setting applies to every repository in your organization and is on by default. + +To change it, go to **Settings → Code review comments**. Only organization admins can change this setting. + +Code review comments settings card + +When comments are on, Hacktron posts findings and scan summaries directly to your pull requests and merge requests. + +When comments are off: + +- Scans still run as normal. +- Check statuses still update and can still block a merge. +- Findings remain available in Hacktron and connected tools such as Slack, Jira, and Linear. +- Hacktron does not post findings, summaries, or other comments to the pull request or merge request. + +Turning comments off does not remove comments that Hacktron has already posted. + ## SLA thresholds Set the resolution window and minimum compliance target for each severity.