Scandrix
Continuous delivery · Ships weekly

Platform changelog.

Every engine upgrade, new rule, and integration — dated, tagged, and explained. No marketing, just what shipped.

Releases
6 tracked
Cadence
Weekly
Latest
v2.4.0
Status
Production stable
v2.4.0LatestMar 12, 2026

Cross-file taint tracking & CLI dry-run parity

The review engine now follows data across file boundaries, and every rule change can be rehearsed against history before it goes live.

  • New · Engine

    Deep cross-file taint analysis in Go, TypeScript, and Python — tracks user input from HTTP handlers through services down to DB and system sinks.

  • New · CLI

    scandrix rules test --diff pr.diff — rehearse rule modifications against historical diffs and preview exactly what would have been flagged.

  • Improved · Engine

    Webhook ingestion via outbox relay, built to absorb burst PR traffic without losing reviews.

  • Improved · Rules

    Inline patch suggestions ship with one-click commit buttons directly inside the PR review comment.

v2.3.0Feb 24, 2026

Bring your own LLM key & the Drixy rules catalog

Use your own model keys with zero markup, and start from the production-tested rules catalog instead of a blank page.

  • New · Enterprise

    BYOK support for Anthropic, OpenAI, and Gemini keys — your spend, your rate limits, 0% token markup.

  • New · Rules

    Public Drixy rules catalog: production-tested rules mapped to OWASP Top 10, installable per org or per repo.

  • Improved · Rules

    Rule dry-run reports now show precision/recall deltas against the previous rule version.

  • Fixed · Integrations

    GitLab merge-request discussion threads now auto-resolve when the follow-up push fixes the finding.

v2.2.0Feb 05, 2026

SAML SSO, SCIM provisioning & audit log export

Enterprise identity end-to-end: single sign-on, automatic deprovisioning, and an immutable trail of who changed what.

  • New · Enterprise

    SAML 2.0 single sign-on with Okta, Microsoft Entra ID, and Google Workspace.

  • New · Enterprise

    SCIM 2.0 user lifecycle — automatic provisioning, deprovisioning, and RBAC role sync.

  • New · Enterprise

    Immutable audit log with SIEM export for every review, rule change, and approval.

  • Improved · Enterprise

    Team API keys (kodus_*) now support per-key scopes and expiry.

v2.1.0Jan 22, 2026

Bitbucket & Azure Repos GA, faster AST compile

Two more Git platforms graduate to general availability, and cold reviews get noticeably quicker.

  • New · Integrations

    Bitbucket and Azure Repos pull-request reviews generally available, including inline suggestions.

  • New · Integrations

    Forgejo webhook support in public beta for self-hosted forges.

  • Improved · Engine

    Incremental Tree-sitter parsing reuses ASTs for unchanged files, speeding up cold reviews on large monorepos.

  • Fixed · Engine

    Fixed missed findings in Rust macro expansions spanning multiple files.

v2.0.0Jan 08, 2026

Multi-model gateway & quorum workers

The engine becomes model-agnostic and the queue layer moves to quorum queues — reviews built for sub-minute turnaround.

  • New · Engine

    Model-agnostic LLM gateway: OpenAI, Anthropic, Gemini, plus self-hosted vLLM and Ollama endpoints.

  • Improved · Engine

    Workers migrated to RabbitMQ quorum queues with idempotent claim/release — no lost or double reviews.

  • Improved · Engine

    Sub-minute design goal: reviews built for turnaround under a minute on the async worker queue.

v1.8.0Dec 18, 2025

Self-hosted VPC beta & zero-retention mode

Run the full platform inside your own network with strict guarantees about where code travels.

  • New · Enterprise

    Self-hosted beta for AWS, GCP, and Azure VPCs, including air-gapped installs with internal LLM endpoints.

  • New · Enterprise

    Zero code retention mode: diffs processed in ephemeral workers with cryptographic erasure after review.

  • Fixed · Enterprise

    Fixed VPC egress allow-list to cover all model provider endpoints used by BYOK.

Never miss a release

Watch it ship, then ship with it.

Follow releases on GitHub, or start a trial and get the latest engine on your very next pull request.