CI/CD Pipeline Integration

Embed ScanDrix automated review quality gates into GitHub Actions, GitLab CI, and CircleCI.

You can run ScanDrix directly inside automated deployment pipelines to enforce pre-merge security gates and block pull requests containing critical vulnerabilities.

GitHub Actions

Create .github/workflows/scandrix.yml in your repository:

yaml
name: ScanDrix Code Review Gate

on:
  pull_request:
    branches: [main, master, develop]

jobs:
  review:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - name: Install ScanDrix CLI
        run: curl -fsSL https://scandrix.dev/install | sh

      - name: Run Review Gate
        env:
          SCANDRIX_API_KEY: ${{ secrets.SCANDRIX_API_KEY }}
        run: |
          scandrix review \
            --base origin/${{ github.base_ref }} \
            --fail-on critical \
            --summary-pr ${{ github.event.pull_request.number }}

GitLab CI/CD

Add the following job to .gitlab-ci.yml:

yaml
scandrix_review:
  stage: test
  image: alpine:latest
  only:
    - merge_requests
  before_script:
    - apk add --no-cache curl git bash
    - curl -fsSL https://scandrix.dev/install | sh
  script:
    - scandrix review --base origin/$CI_MERGE_REQUEST_TARGET_BRANCH_NAME --fail-on critical
  variables:
    SCANDRIX_API_KEY: $SCANDRIX_API_KEY

CircleCI

Add a review step in .circleci/config.yml:

yaml
version: 2.1
jobs:
  scandrix-gate:
    docker:
      - image: cimg/base:current
    steps:
      - checkout
      - run:
          name: Run ScanDrix Quality Check
          command: |
            curl -fsSL https://scandrix.dev/install | sh
            scandrix review --base origin/main --fail-on critical
workflows:
  build-and-test:
    jobs:
      - scandrix-gate

Set --fail-on critical to ensure only high-risk vulnerabilities (SQL injection, leaked credentials, broken authorization) block pipeline execution, while style and minor architectural recommendations are posted as non-blocking comments.