> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coderabbit.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# CodeRabbit Security check

> Publish a GitHub check for Security review comments and require it to pass before merging.

export const DeploymentBadge = ({variant = "cloud-only", tip, title, cta = "Learn more", href = "/self-hosted/overview", disabled = false}) => {
  const isCloudOnly = variant === "cloud-only";
  const defaultTitle = isCloudOnly ? "Cloud Only" : "Self-Hosted Only";
  const defaultTip = isCloudOnly ? "This feature is available on CodeRabbit Cloud only. It is not available on self-hosted CodeRabbit deployments." : "This feature is available on self-hosted CodeRabbit deployments only. It is not available on CodeRabbit Cloud.";
  return <Tooltip tip={tip || defaultTip} cta={cta} href={href}>
        <Badge icon="rabbit" disabled={disabled || undefined}>
            {title || defaultTitle}
        </Badge>
    </Tooltip>;
};

export const GitHubBadge = ({tip = "This feature is available on GitHub and GitHub Enterprise.", title = "GitHub", cta, href, disabled = false}) => {
  return <Tooltip tip={tip} cta={cta} href={href}>
        <Badge icon="github" disabled={disabled || undefined}>
            {title}
        </Badge>
    </Tooltip>;
};

<GitHubBadge title="GitHub Cloud" tip="The CodeRabbit Security check is available on GitHub Cloud only." /> | <DeploymentBadge variant="cloud-only" />

**CodeRabbit Security** is a native GitHub check that fails while blocking Security review comments remain on a pull request. Choose a severity threshold, then require the check in GitHub to block merging.

The check is **off by default for every repository**. It appears only after you enable it for a repository with PR Security review access. It is separate from the general **CodeRabbit** review check and from AI Deep Scan results.

## Enable the check

You need Security write permission to change this setting. Your repository must have [PR Security review access](/security#access-and-billing).

<Steps>
  <Step title="Open repository Security settings">
    In the CodeRabbit app, open **Security > Repositories**, select your repository, and open **Settings**.
  </Step>

  <Step title="Enable publication">
    Under **Pull request check**, turn on **Publish CodeRabbit Security check**. The setting saves automatically.
  </Step>

  <Step title="Choose what blocks merging">
    Set **Block on** to the lowest severity you want to block. The default is **Critical**. This selection also saves automatically.
  </Step>

  <Step title="Run a review">
    The check starts with the next review. To evaluate an existing pull request now, comment `@coderabbitai full review` on it.
  </Step>
</Steps>

The first evaluation includes existing visible Security comments on the pull request. Configure publication in these repository settings; there is no `.coderabbit.yaml` option for this check.

### Severity thresholds

The threshold includes the selected severity and every higher severity.

| Block on | Comments that can block |
| - | - |
| Critical | Critical |
| Major and above | Major, Critical |
| Minor and above | Minor, Major, Critical |
| Trivial and above | Trivial, Minor, Major, Critical |
| Info and above | Info, Trivial, Minor, Major, Critical |

Threshold changes apply to newly published comments. Raising the threshold does not clear existing blockers, and lowering it does not turn comments previously below the threshold into blockers. Existing comments retain the decision made when they were first evaluated.

## Require the check in GitHub

Publishing the check does not change your repository's merge rules. To block merging, a GitHub repository administrator must configure a ruleset for the protected branch, or a branch protection rule, that requires **CodeRabbit Security**.

1. Let **CodeRabbit Security** complete a review with **Success** or **Neutral** so GitHub can list it as an available required check.
2. In your GitHub repository, open **Settings > Rules > Rulesets**. Create or edit a branch ruleset and select the branches you want to protect. If you use classic branch protection, edit the rule under **Settings > Branches** instead.
3. Enable **Require status checks to pass before merging** and add **CodeRabbit Security**. Select the **CodeRabbit App** as the expected source.
4. Save the rule. For a ruleset, set its enforcement status to **Active**.

See GitHub's guide to [creating a branch ruleset](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/creating-rulesets-for-a-repository) and its [required status check rules](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets#require-status-checks-to-pass-before-merging) for setup details. GitHub requires the check to pass on the latest commit; both **Success** and **Neutral** satisfy this requirement. A failed or unfinished required check blocks merging, subject to your GitHub bypass rules.

<Warning>
  The Security check currently runs on pull request commits, not merge queue commits. Do not require it for a GitHub merge queue: the queue can wait for a check that is not published on its temporary commit.
</Warning>

## Understand the result

During a review, the check shows **In progress**. When evaluation finishes, it reports one of these results:

| Result | Meaning |
| - | - |
| Failure | At least one blocking Security comment remains. |
| Success | Security comments are tracked, and none remain blocking. |
| Neutral | No Security comments are tracked, or comment history cannot be confirmed and there are no known blockers. |

Known blockers continue to fail the check even when other review evidence is unavailable. Incomplete analysis alone does not cause failure. A successful or neutral result does not guarantee that the code has no security issues.

### What counts as a Security comment?

The check tracks visible inline comments published by CodeRabbit under **Security & Privacy**. Each comment counts once. When one comment contains multiple Security issues, its highest displayed Security severity applies. Replies, summary-only items, comments in other categories, and unpublished analysis do not count.

### Read the report

Open **CodeRabbit Security** in the pull request's **Checks** tab to see:

* The commit that was evaluated.
* Comment counts by severity: **Found**, **Verified fixed**, **Remaining**, and **Blocking**.
* Blocking comments with their file locations and direct links.
* The **Block on** threshold used for that review and a link to repository settings.

Counts carry across reviews of the same pull request. A dash (`—`) means the history needed for that count is unavailable; it does not mean zero. The report can list blockers admitted under an earlier threshold even after you change the setting.

## Clear a blocking comment

Fix the issue, push a new commit, and let CodeRabbit review it. CodeRabbit uses its code-based comment resolution results to verify that the current code addresses the issue. Unrelated pushes do not clear blockers.

<Info>
  Resolving a GitHub conversation, marking it outdated, or replying that an issue is fixed does not establish a verified fix and does not clear a Security blocker.
</Info>

If a published comment is deleted, a later review removes it from blocking only after confirming the deletion. Deleted comments are not counted as **Verified fixed**.

## Disable or troubleshoot the check

Before turning off **Publish CodeRabbit Security check**, remove the check requirement from GitHub. Otherwise, GitHub can block merging while waiting for a check that will no longer be published. See [GitHub's required check troubleshooting guide](https://docs.github.com/en/pull-requests/how-tos/merge-and-close-pull-requests/troubleshooting-required-status-checks).

Disabling applies to subsequent reviews. A check already in progress finishes normally, and previously published checks remain visible. Disabling and re-enabling does not erase tracked blockers or history.

If the check does not appear, confirm that publication is enabled for the correct repository, PR Security reviews are available, and a review has run since you enabled it. If your plan no longer provides PR Security reviews, new checks stop publishing even if the saved preference remains enabled.

## What's next

<CardGroup cols={1}>
  <Card title="CodeRabbit Security" href="/security" icon="shield-check" horizontal>
    Explore PR Security reviews and repository-wide AI Deep Scans.
  </Card>

  <Card title="Review commands" href="/reference/review-commands" icon="terminal" horizontal>
    Request a full review or check your review status.
  </Card>

  <Card title="Request Changes Workflow" href="/pr-reviews/request-changes-workflow" icon="git-pull-request" horizontal>
    Configure review approvals across all actionable review feedback.
  </Card>
</CardGroup>
