Skip to content
Published

Last reviewed: 2026-09-16

Pull request checks

Enable CodeCleared GitHub PR checks and GitLab MR External Status Checks for vulnerabilities, secrets, licenses, dependency advisor, and SAST.

Purpose

PR / MR checks post one or more provider status results on each pull or merge request so reviewers see whether proposed changes introduce security or policy violations before merge.

Who

Organization owners or admins enable checks. Repository maintainers need the matching provider permission: GitHub App Checks, or GitLab External Status Checks (Premium/Ultimate).

Prerequisites

  • Repository connected via the GitHub App or GitLab.com OAuth (Settings → Sources)
  • Provider status permission granted (GitHub Checks, or GitLab External Status Checks on Premium/Ultimate)
  • PR checks enabled for the organization or repository in CodeCleared (Settings → Scan defaults, or per-repository Scan triggers)
  • Eligible plan limits for how many repositories can use PR checks (Free: 1; Starter and above: unlimited)
  • SAST PR checks: SAST add-on and a sast project unit on the repository
  • Secrets PR checks: a secrets project unit on the repository
  • Vulnerabilities, licenses, dependency advisor: SCA project units (recognized lockfiles)

How it works

  1. Open or update a pull request (GitHub) or merge request (GitLab) against a monitored branch (scanOnPr / scanOnPrUpdate must be enabled).
  2. CodeCleared queues a separate workflow per enabled check type.
  3. Each check publishes pass or fail on the PR / MR in the provider.
  4. Investigate failures in CodeCleared (PR check detail), then push a fix or apply a documented override where supported.

Check types

Check typeFails whenEvaluation model
VulnerabilitiesNew or present findings with severity ≥ prCheckSeverityThreshold (see mode below)Configurable severity threshold
SecretsNew or present findings with severity ≥ prCheckSeverityThresholdConfigurable severity threshold
LicensesLicense policy is non-compliant for the evaluated commitOrganization license policies
Dependency advisorCategory / dependency policy is non-compliantDependency Advisor policies
SASTNew or present findings with severity ≥ prCheckSeverityThresholdConfigurable severity threshold + SAST add-on

Policy-based checks (licenses, dependency advisor) use the same evaluators as the product tabs and Quality Gates. Severity-based checks (vulnerabilities, secrets, SAST) use prCheckSeverityThreshold only — they are not Quality Gates and are not linked to Quality Gate rules for these PR checks.

Severity threshold (prCheckSeverityThreshold)

Values: critical | high | medium | low. Default: high.

The check fails when at least one evaluated finding has severity at or above the threshold (for example high fails on critical and high; critical fails on critical only).

  • Organization: Settings → Scan defaults
  • Repository override: repository Scan triggers (optional; omit to inherit the org default)
  • Also set during Onboarding and repository Import (PR threshold only on import)

This field is separate from apiGateSeverityThreshold (Public API / CLI / MCP wait). See Scans API.

Diff vs full mode

Default mode is diff (organization or repository metadata):

  • Diff: compares base and head commits. For vulnerabilities, secrets, SAST, and dependency advisor, only new violations fail the check. Existing issues on the base branch do not block the PR by themselves.
  • Full: evaluates the head commit only (all matching findings at that commit can fail severity-based checks).

Configuration precedence

On import, all five PR check types default to enabled unless organization scan defaults say otherwise.

Per repository:

  • If the repository has at least one PR check type enabled, repository toggles apply to all types.
  • If the repository has no enabled checks (empty or all off), organization Scan defaults apply.

Configure toggles and the optional PR severity override under repository Scan triggers or organization Scan defaults.

GitLab merge-request checks

On GitLab.com import, CodeCleared registers project webhooks and attempts to create the five External Status Checks (same check types as GitHub). External Status Checks require GitLab Premium or Ultimate; without that plan, import and scans still work, but MR status checks are not created. Self-managed GitLab is not supported. See Connect GitLab.

Scenarios & edge cases

No check appears (GitHub): the App lacks Checks permission, PR checks are disabled, scanOnPr is off, or the repository is outside the App grant.

No check appears (GitLab): External Status Checks were not registered (often Free/Standard plan), PR checks are disabled, scanOnPr is off, or OAuth access is insufficient.

Only some checks appear: each type is independent; confirm the toggle for that type and any add-on (SAST) or project unit (secrets, SAST) requirement.

Check fails but the dashboard looks fine: you may be comparing different commits, branches, or project units; in diff mode, only new findings fail severity-based checks.

Fork PRs: App access and secrets available to fork workflows may differ; confirm the repository the check ran against.

Policy changed after open: push a new commit or wait for a new run so the check evaluates current policy.

SAST check fails with “no SAST project unit”: enable SAST on the repository and ensure the SAST project unit exists.

Limits

A failed PR / MR check is a governance signal, not proof that production is compromised. Free organizations can enable PR checks on a single repository. PR checks consume credits according to the underlying scans (head branch in diff mode is billed; base branch scan in diff mode is skipped for billing where configured).

Changing Quality Gate package thresholds does not change PR fail severity for vulns / secrets / SAST. Use prCheckSeverityThreshold instead.

Common errors

  • Disabling all PR check toggles at repository level while expecting organization defaults—if the repository explicitly disables every type, no checks run.
  • Expecting Quality Gates to drive vuln / secret / SAST PR pass/fail — they do not; set prCheckSeverityThreshold.
  • Expecting license allowances to re-run PR checks immediately—they refresh on the next natural license scan (see Overrides).
  • Ignoring Checks permission when the GitHub App otherwise has content access.
  • Expecting GitLab MR status checks without Premium/Ultimate.
  • Enabling SAST PR checks without the SAST add-on or project unit.

Links