Troubleshooting

Symptom-first fixes for reviews that don't trigger, webhook failures, and CLI errors.

Reviews are not triggering

Work through this list in order — it resolves the large majority of cases:

1

Is the integration connected?

Settings → Integrations should show the provider as connected with a recent sync time. Reconnect if it shows Action required (usually an expired token after a credential rotation).

2

Is the repository granted?

Only explicitly selected repositories are reviewed. Add the repo, or switch the integration to "all repositories".

3

Did the webhook arrive?

Integrations → Last deliveries lists recent events. If the list is empty, the provider isn't reaching you — go to Webhook Setup and register manually.

4

Is the PR eligible?

Draft PRs and PRs labeled scandrix-skip are skipped by default. Check path filters in scandrix.yml — a PR touching only ignored paths produces a Skipped status, not silence.

5

Check the check run

Open the PR's checks tab. A Failed status with a log link means analysis errored after retries — the log names the failing stage.

Webhook received but no comment

SymptomLikely causeFix
Event logged, review never startsIdempotency collision (re-delivery of same commit)Push an empty commit or re-run from Reviews → Re-run
Review completes, zero commentsNothing violated active rulesExpected — Approved with no comments
Comments appear on old PR onlyProcessing backlogCheck worker health /readyz; queue depth metric should drain
Duplicate commentsTwo delivery paths (webhook + CI job)Remove one, or keep both — dedupe needs the same commit SHA

CLI errors

401 unauthorized Team key missing, malformed, or revoked. Echo it (never print it in shared terminals): echo ${#SCANDRIX_TEAM_KEY} should be > 20. Rotate/regenerate in Settings → API Keys if needed.

429 too many requests Rate limit per key — wait for the Retry-After window or use a different team key for parallel CI shards.

config validate fails Line-anchored YAML error. Common: tabs (use spaces), quoting on/off values as booleans, or a rule ID not in the catalog — scandrix rules list shows valid IDs.

No findings but CI should fail Blocking severity is configured above your findings' severity. Check Settings → Merge Policies, or pass --fail-on warning in CI.

Provider-side errors

  • GitHub 403 on comments — app missing from the repo, or branch protection blocking bot pushes to the check; reinstall the app (GitHub App Setup).
  • GitLab 401 — project access token expired or missing api scope.
  • Azure 401 — PAT expired or missing PR-threads write scope.

Still failing?

Email hello@scandrix.dev with the inquiryId/review ID shown in the dashboard — it carries enough context for us to trace the event through the queue without you sharing source code.