ScanDrix for Monorepos
Directory-level rules, path filters, and per-service configuration for monorepo reviews.
Monorepos need different rules per package. ScanDrix resolves configuration hierarchically so one repository can carry many policies.
Strategy
Scope rules to services/payments/**, apps/web/**, etc.
Give Drixy cross-repo contract context for PRs that span services.
Per-directory rules
Extend scandrix.yml with directory-scoped rule activation:
version: 1
project: "platform-monorepo"
rules:
- rule: "no-hardcoded-secrets"
severity: "critical"
directories:
- path: "services/payments/**"
rules:
- rule: "enforce-parameterized-sql"
severity: "critical"
- rule: "tenant-isolation-guard"
severity: "critical"
- path: "apps/web/**"
rules:
- rule: "unbounded-goroutine-spawn"
severity: "info" # Go-specific rule, irrelevant here
- path: "packages/ui/**"
ignore_paths:
- "**/*.stories.tsx" # visual tests are not review targets
Resolution: organization → repository → directory (deepest match wins per rule ID).
Keep ignore paths honest
ignore_paths:
- "**/generated/**"
- "**/*.pb.go"
- "**/dist/**"
- "**/node_modules/**"
Generated code inflates review time and noise. If a directory is owned by humans, don't ignore it — use severity: info to demote noise instead.
Review fan-out
Large monorepo PRs (30+ files) get chunked analysis: the worker splits by top-level directory so review latency stays near single-service numbers. Status comments remain one summary per PR with file-grouped inline comments.
Cost & signal tuning
| Symptom | Lever |
|---|---|
| Too many comments in one package | Downgrade that package's rules to warning/info |
| Same finding re-flagged after suppression | /scandrix ignore <rule> --reason ... (audited) |
PR touches only docs/** | Global ignore_paths: ["docs/**"] or expect Skipped |
| Shared package change should warn dependents | Enable linked context on the package (Rules → Linked Repositories) |