scandrix.yml Reference
Configure active rules, path filters, and severities per repository with scandrix.yml.
Place a scandrix.yml or .scandrix.yml file at the repository root to configure ScanDrix behavior for that repository. Changes take effect on the next pull request — no dashboard action needed.
Full example
version: 1
project: "my-service"
rules:
- rule: "enforce-parameterized-sql"
severity: "critical"
- rule: "tenant-isolation-guard"
severity: "critical"
- rule: "no-hardcoded-secrets"
severity: "critical"
ignore_paths:
- "vendor/**"
- "dist/**"
- "**/*.spec.ts"
Fields
version
Schema version. Currently 1.
project
Optional label for the repository. Appears in review summaries and Cockpit-style metrics so monorepo services stay distinguishable.
rules
Explicit list of rules to activate for this repository. Each entry may override severity. Rules inherited from the organization scope are active even if not listed — add them here only to change severity.
rules:
- rule: "unbounded-goroutine-spawn"
severity: "warning" # downgrade from critical
- rule: "legacy-regex-style"
severity: "info" # keep, but never block
ignore_paths
Glob patterns excluded from analysis. Excluded files are never parsed, never sent to a model, and never commented on.
Ignore paths are also respected by the security engine — excluding a directory means ScanDrix cannot flag issues there. Exclude generated code, vendored dependencies, and fixtures, not source directories you own.
Precedence
Configuration resolves in this order (later wins):
- Organization defaults (dashboard)
- Repository settings (dashboard)
scandrix.ymlin the repository root- Per-PR overrides via bot comment commands
The effective configuration is shown in the dashboard under Repositories → Settings → Effective Config, including which file each value came from.
Validation
CI validates the file on push:
scandrix config validate
An invalid file fails the check with a line-anchored error; reviews continue with the last known-good configuration so a typo never blocks your pipeline.