scandrix.yml Reference

Configure active rules, path filters, and severities per repository with scandrix.yml.

Place a scandrix.yml or .scandrix.yml file at the repository root to configure ScanDrix behavior for that repository. Changes take effect on the next pull request — no dashboard action needed.

Full example

yaml
version: 1
project: "my-service"
rules:
  - rule: "enforce-parameterized-sql"
    severity: "critical"
  - rule: "tenant-isolation-guard"
    severity: "critical"
  - rule: "no-hardcoded-secrets"
    severity: "critical"
ignore_paths:
  - "vendor/**"
  - "dist/**"
  - "**/*.spec.ts"

Fields

version

Schema version. Currently 1.

project

Optional label for the repository. Appears in review summaries and Cockpit-style metrics so monorepo services stay distinguishable.

rules

Explicit list of rules to activate for this repository. Each entry may override severity. Rules inherited from the organization scope are active even if not listed — add them here only to change severity.

yaml
rules:
  - rule: "unbounded-goroutine-spawn"
    severity: "warning"   # downgrade from critical
  - rule: "legacy-regex-style"
    severity: "info"      # keep, but never block

ignore_paths

Glob patterns excluded from analysis. Excluded files are never parsed, never sent to a model, and never commented on.

Ignore paths are also respected by the security engine — excluding a directory means ScanDrix cannot flag issues there. Exclude generated code, vendored dependencies, and fixtures, not source directories you own.

Precedence

Configuration resolves in this order (later wins):

  1. Organization defaults (dashboard)
  2. Repository settings (dashboard)
  3. scandrix.yml in the repository root
  4. Per-PR overrides via bot comment commands

The effective configuration is shown in the dashboard under Repositories → Settings → Effective Config, including which file each value came from.

Validation

CI validates the file on push:

bash
scandrix config validate

An invalid file fails the check with a line-anchored error; reviews continue with the last known-good configuration so a typo never blocks your pipeline.