Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions code-review/config.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -170,7 +170,7 @@ release branches except `release/legacy/**`.

## Include scans

Use the include block to scan **only** pull and merge requests that match specific rules. Hacktron records a skip check comment on PRs/MRs it doesn't scan.
Use the include block to scan **only** pull and merge requests that match specific rules. Hacktron records a skipped check on PRs/MRs it doesn't scan and, if [code review comments](/platform/organization-settings#code-review-comments) are on, a skip comment.

```yaml
include:
Expand Down Expand Up @@ -204,7 +204,7 @@ include:

## Fail the check on findings

By default, the Hacktron check is green as long as the scan completes. Findings are posted as inline comments but don't block the merge. Configure a severity threshold to turn the check **red** when a finding is at or above that level.
By default, the Hacktron check is green as long as the scan completes, and findings are posted as inline comments but don't block the merge. Configure a severity threshold to turn the check **red** when a finding is at or above that level.

![Failed check example](/images/fail_on_failure_example.png)

Expand Down
2 changes: 1 addition & 1 deletion code-review/findings-feedback.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ title: "Findings and feedback"
description: "Understand where Hacktron posts Code Review findings and how feedback improves future reviews."
---

Hacktron posts Code Review findings where developers already work.
By default, Hacktron posts Code Review findings where developers already work. Admins can turn this off in [Code review comments](/platform/organization-settings#code-review-comments).

## Inline findings

Expand Down
2 changes: 1 addition & 1 deletion code-review/overview.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ title: "Code Review"
description: "Use Code Review to run continuous pull request security reviews across connected repositories."
---

Code Review reviews pull requests and merge requests in the repositories you enable. Hacktron reads each change with repository context, looks for exploitable vulnerabilities, and comments directly on affected code so engineers can fix issues before merge.
Code Review reviews pull requests and merge requests in the repositories you enable. Hacktron reads each change with repository context and looks for exploitable vulnerabilities. By default, Hacktron comments directly on affected code so engineers can fix issues before merge.

Use Code Review for continuous security coverage on day-to-day development. For broader, scoped assessments of a repository or application, use [White-box Pentest](/white-box-pentest/overview).

Expand Down
2 changes: 1 addition & 1 deletion code-review/troubleshooting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ If only some pull requests or merge requests are reviewed:
## Developer is not covered

If a developer is not covered by a Code Review seat,
Hacktron leaves a pull request comment explaining that no seat is assigned.
Hacktron marks the check as skipped. If [code review comments](/platform/organization-settings#code-review-comments) are on, Hacktron also leaves a pull request comment explaining that no seat is assigned.

Check **Billing** to confirm the organization has trial or paid review capacity available.

Expand Down
Binary file added images/code_review_comments.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
24 changes: 23 additions & 1 deletion platform/organization-settings.mdx
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: "Organization settings"
description: "Configure scan filters, the check gate, and SLA thresholds for your organization."
description: "Configure scan filters, the check gate, code review comments, and SLA thresholds for your organization."
---

Organization settings apply to every repository unless a repository's `.hacktron/config.yaml` overrides them. Only organization admins and owners can change these settings.
Expand Down Expand Up @@ -60,6 +60,28 @@ Set an org-wide severity threshold that fails a PR or MR check when a finding me

See [Fail the check on findings](/code-review/config#fail-the-check-on-findings) for the full severity table and per-repository overrides.

## Code review comments

Choose whether Hacktron posts scan results as comments on your pull requests and merge requests. This setting applies to every repository in your organization and is on by default.

To change it, go to **Settings → Code review comments**. Only organization admins can change this setting.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reconcile owner access to the comments setting

This says only organization admins can change the toggle, while the same page states that organization admins and owners can change organization settings. Owners therefore receive conflicting guidance about whether they can manage this new setting; clarify that owners are included, or document this as an explicit exception in the page introduction.

Useful? React with 👍 / 👎.


<img
src="/images/code_review_comments.png"
alt="Code review comments settings card"
/>

When comments are on, Hacktron posts findings and scan summaries directly to your pull requests and merge requests.

When comments are off:

- Scans still run as normal.
- Check statuses still update and can still block a merge.
- Findings remain available in Hacktron and connected tools such as Slack, Jira, and Linear.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Qualify the Jira and Linear availability claim

When a finding has not been approved or sent and automatic ticket creation is disabled, merely connecting Jira or Linear does not make that finding available there: platform/project-management.mdx documents that only approved findings can be sent and that automatic tickets require auto-create. This bullet currently implies that every finding remains available in those tools when comments are disabled; qualify it to say that existing configured notification and ticket workflows continue unchanged.

Useful? React with 👍 / 👎.

- Hacktron does not post findings, summaries, or other comments to the pull request or merge request.

Turning comments off does not remove comments that Hacktron has already posted.

## SLA thresholds

Set the resolution window and minimum compliance target for each severity.
Expand Down
Loading