Security-First Review Pipeline

Configure Drixy rules for OWASP risks, secret detection, and secure coding patterns as merge gates.

A ready-to-adopt rule set that makes critical security findings block merges while keeping lower severities advisory.

1. Enable the security baseline

From Rules → Library, activate:

Rule IDSeverityBlocks
sec-001 enforce-parameterized-sqlcritical✓
sec-002 no-hardcoded-secretscritical✓
arch-001 tenant-isolation-guardcritical✓
injection/eval patternscritical✓
missing outbound timeoutswarning✗
yaml
version: 1
project: "payments-service"
rules:
  - rule: "enforce-parameterized-sql"
    severity: "critical"
  - rule: "no-hardcoded-secrets"
    severity: "critical"
  - rule: "tenant-isolation-guard"
    severity: "critical"
  - rule: "outbound-timeout"
    severity: "warning"
ignore_paths:
  - "**/*_test.go"
  - "testdata/**"

2. Set merge policies

Settings → Merge Policies: block on critical, comment on warning, advisory for info. This gives security a hard gate without parking refactors.

3. Dry Run before enforcing

Run scandrix rules dry-run --since 30d and review the would-be findings. Expect an initial spike on legacy code — narrow matches or triage with suppressions (/scandrix ignore <rule> --reason "<ticket>") rather than turning the rule off.

4. Evidence for auditors

  • Audit log — every suppression carries author, reason, timestamp.
  • Export — audit CSV for SOC 2 / ISO review periods.
  • CI proof — required status check shows the policy set version active on each merge.

5. Keep it alive

Quarterly, review the rule feedback report: rules with high rejected-suggestion rates get tuned; rules with zero hits over 90 days get questioned. The pipeline only stays trusted while the signal stays clean.