Repository navigation
docs: document the Code review comments setting #83
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,6 +1,6 @@ | ||
| --- | ||
| title: "Organization settings" | ||
| description: "Configure scan filters, the check gate, and SLA thresholds for your organization." | ||
| description: "Configure scan filters, the check gate, code review comments, and SLA thresholds for your organization." | ||
| --- | ||
|
|
||
| Organization settings apply to every repository unless a repository's `.hacktron/config.yaml` overrides them. Only organization admins and owners can change these settings. | ||
|
|
@@ -60,6 +60,28 @@ Set an org-wide severity threshold that fails a PR or MR check when a finding me | |
|
|
||
| See [Fail the check on findings](/code-review/config#fail-the-check-on-findings) for the full severity table and per-repository overrides. | ||
|
|
||
| ## Code review comments | ||
|
|
||
| Choose whether Hacktron posts scan results as comments on your pull requests and merge requests. This setting applies to every repository in your organization and is on by default. | ||
|
|
||
| To change it, go to **Settings → Code review comments**. Only organization admins can change this setting. | ||
|
|
||
| <img | ||
| src="/images/code_review_comments.png" | ||
| alt="Code review comments settings card" | ||
| /> | ||
|
|
||
| When comments are on, Hacktron posts findings and scan summaries directly to your pull requests and merge requests. | ||
|
|
||
| When comments are off: | ||
|
|
||
| - Scans still run as normal. | ||
| - Check statuses still update and can still block a merge. | ||
| - Findings remain available in Hacktron and connected tools such as Slack, Jira, and Linear. | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When a finding has not been approved or sent and automatic ticket creation is disabled, merely connecting Jira or Linear does not make that finding available there: Useful? React with 👍 / 👎. |
||
| - Hacktron does not post findings, summaries, or other comments to the pull request or merge request. | ||
|
|
||
| Turning comments off does not remove comments that Hacktron has already posted. | ||
|
|
||
| ## SLA thresholds | ||
|
|
||
| Set the resolution window and minimum compliance target for each severity. | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This says only organization admins can change the toggle, while the same page states that organization admins and owners can change organization settings. Owners therefore receive conflicting guidance about whether they can manage this new setting; clarify that owners are included, or document this as an explicit exception in the page introduction.
Useful? React with 👍 / 👎.