GitLab CI/CD
Connect a GitLab project with a access token, webhook, and pipeline-based review job.
ScanDrix works with GitLab.com and self-managed GitLab two ways: webhook reviews (ScanDrix comments on MRs automatically) and CI job reviews (your pipeline runs the CLI). Most teams start with webhooks and add the CI job as a merge gate.
Option A — Webhook reviews (recommended)
- Create a project access token with
apiscope: Settings → Access tokens. - In ScanDrix: Settings → Integrations → GitLab and paste the token.
- Register the webhook — see Webhook Setup for the URL and secret. Subscribe to Merge request events and Push events.
Drixy now reviews merge requests automatically.
Option B — Pipeline review job
Add a review stage to .gitlab-ci.yml so every MR runs the CLI as a merge gate:
stages:
- review
scandrix_code_review:
stage: review
image: scandrix/cli:latest
script:
- scandrix review --ci --base $CI_MERGE_REQUEST_TARGET_BRANCH_NAME
only:
- merge_requests
variables:
SCANDRIX_TEAM_KEY: $SCANDRIX_TEAM_KEY
- Store
SCANDRIX_TEAM_KEYunder Settings → CI/CD → Variables with Masked enabled. --basecompares against the MR target branch, so only the MR's changes are reviewed.- Exit code is non-zero when blocking-severity findings exist → the job fails → merge request cannot merge while required checks fail.
Webhook and CI reviews de-duplicate: if both are enabled, the CI job reuses the webhook review's findings for the same commit SHA instead of posting twice.
Protected branches
On protected branches, ensure the CI job has permission to run (it only needs to read code and write the job status — the ScanDrix API key is separate from GitLab's job token).
Troubleshooting
- 401 from the integration — token expired or missing
apiscope; regenerate. - Reviews on the wrong branch — check the
only: [merge_requests]rule matches your MR pipeline settings. - Self-managed GitLab behind SSO — use the self-hosted ScanDrix deployment or allowlist ScanDrix egress IPs (shown in Settings → Integrations).