Enable the check
You need Security write permission to change this setting. Your repository must have PR Security review access.1
Open repository Security settings
In the CodeRabbit app, open Security > Repositories, select your repository, and open Settings.
2
Enable publication
Under Pull request check, turn on Publish CodeRabbit Security check. The setting saves automatically.
3
Choose what blocks merging
Set Block on to the lowest severity you want to block. The default is Critical. This selection also saves automatically.
4
Run a review
The check starts with the next review. To evaluate an existing pull request now, comment
@coderabbitai full review on it..coderabbit.yaml option for this check.
Severity thresholds
The threshold includes the selected severity and every higher severity.
Threshold changes apply to newly published comments. Raising the threshold does not clear existing blockers, and lowering it does not turn comments previously below the threshold into blockers. Existing comments retain the decision made when they were first evaluated.
Require the check in GitHub
Publishing the check does not change your repositoryâs merge rules. To block merging, a GitHub repository administrator must configure a ruleset for the protected branch, or a branch protection rule, that requires CodeRabbit Security.- Let CodeRabbit Security complete a review with Success or Neutral so GitHub can list it as an available required check.
- In your GitHub repository, open Settings > Rules > Rulesets. Create or edit a branch ruleset and select the branches you want to protect. If you use classic branch protection, edit the rule under Settings > Branches instead.
- Enable Require status checks to pass before merging and add CodeRabbit Security. Select the CodeRabbit App as the expected source.
- Save the rule. For a ruleset, set its enforcement status to Active.
Understand the result
During a review, the check shows In progress. When evaluation finishes, it reports one of these results:
Known blockers continue to fail the check even when other review evidence is unavailable. Incomplete analysis alone does not cause failure. A successful or neutral result does not guarantee that the code has no security issues.
What counts as a Security comment?
The check tracks visible inline comments published by CodeRabbit under Security & Privacy. Each comment counts once. When one comment contains multiple Security issues, its highest displayed Security severity applies. Replies, summary-only items, comments in other categories, and unpublished analysis do not count.Read the report
Open CodeRabbit Security in the pull requestâs Checks tab to see:- The commit that was evaluated.
- Comment counts by severity: Found, Verified fixed, Remaining, and Blocking.
- Blocking comments with their file locations and direct links.
- The Block on threshold used for that review and a link to repository settings.
â) means the history needed for that count is unavailable; it does not mean zero. The report can list blockers admitted under an earlier threshold even after you change the setting.
Clear a blocking comment
Fix the issue, push a new commit, and let CodeRabbit review it. CodeRabbit uses its code-based comment resolution results to verify that the current code addresses the issue. Unrelated pushes do not clear blockers.Resolving a GitHub conversation, marking it outdated, or replying that an issue is fixed does not establish a verified fix and does not clear a Security blocker.
Disable or troubleshoot the check
Before turning off Publish CodeRabbit Security check, remove the check requirement from GitHub. Otherwise, GitHub can block merging while waiting for a check that will no longer be published. See GitHubâs required check troubleshooting guide. Disabling applies to subsequent reviews. A check already in progress finishes normally, and previously published checks remain visible. Disabling and re-enabling does not erase tracked blockers or history. If the check does not appear, confirm that publication is enabled for the correct repository, PR Security reviews are available, and a review has run since you enabled it. If your plan no longer provides PR Security reviews, new checks stop publishing even if the saved preference remains enabled.Whatâs next
CodeRabbit Security
Explore PR Security reviews and repository-wide AI Deep Scans.
Review commands
Request a full review or check your review status.
Request Changes Workflow
Configure review approvals across all actionable review feedback.