Configuration File (.scandrix.yaml)

Complete schema reference for repo-level configuration, path filters, rule overrides, and review directives.

Repositories can be configured via a .scandrix.yaml or .scandrix.yml file placed at the root of the default branch. This file is version-controlled and allows engineering teams to define deterministic review rules, ignore paths, and custom prompt directives.

Minimal example

yaml
version: 1

review:
  auto_review: true
  severity_threshold: warning
  max_comments_per_pr: 15
  patch_suggestions: true

ignore:
  - "dist/**"
  - "vendor/**"
  - "**/*.generated.ts"
  - "package-lock.json"

Complete schema reference

review settings

FieldTypeDefaultDescription
auto_reviewbooleantrueAutomatically trigger review when a PR is opened or synchronized.
severity_thresholdstringinfoMinimum severity to post inline: info, warning, or critical.
max_comments_per_prnumber20Cap on inline comments to prevent PR review notification spam.
patch_suggestionsbooleantrueAttach ready-to-commit GitHub suggestion blocks to comments.
summary_commentbooleantruePost an overarching executive review table at the top of the PR.
block_on_criticalbooleanfalseRequest changes / set commit status to failure if critical bugs exist.

ignore patterns

Glob patterns matching files that should be completely skipped during AST parsing:

yaml
ignore:
  - "**/*.min.js"
  - "migrations/**"
  - "mocks/**"
  - "tests/fixtures/**"
  - "**/*.pb.go"

directives (Natural language prompt instructions)

You can provide team-specific directives that guide the AI reasoning layer alongside deterministic AST queries:

yaml
directives:
  - "Enforce modern Go 1.25 conventions: prefer 'any' over 'interface{}'."
  - "All database writes must execute within a tenant-scoped transaction."
  - "Flag any hardcoded timeouts longer than 5 seconds in HTTP client calls."

rules (Per-rule overrides)

Override default severities or disable specific built-in Drixy rules:

yaml
rules:
  # Elevate SQL injection to always block PR
  sec-001:
    severity: critical
    enabled: true

  # Downgrade strict naming lint to informational
  style-042:
    severity: info

  # Disable regex email validator rule in favor of custom schema
  val-012:
    enabled: false

Centralized organization inheritance

In enterprise workspaces, organization admins can enforce a baseline .scandrix.yaml across all microservices.

  • Organization rules inherit downward.
  • Repositories can increase severity (e.g. from warning to critical), but cannot disable organization-mandated security rules unless granted an explicit admin waiver.