Security-First Review Pipeline
Configure Drixy rules for OWASP risks, secret detection, and secure coding patterns as merge gates.
A ready-to-adopt rule set that makes critical security findings block merges while keeping lower severities advisory.
1. Enable the security baseline
From Rules → Library, activate:
| Rule ID | Severity | Blocks |
|---|---|---|
sec-001 enforce-parameterized-sql | critical | ✓ |
sec-002 no-hardcoded-secrets | critical | ✓ |
arch-001 tenant-isolation-guard | critical | ✓ |
| injection/eval patterns | critical | ✓ |
| missing outbound timeouts | warning | ✗ |
version: 1
project: "payments-service"
rules:
- rule: "enforce-parameterized-sql"
severity: "critical"
- rule: "no-hardcoded-secrets"
severity: "critical"
- rule: "tenant-isolation-guard"
severity: "critical"
- rule: "outbound-timeout"
severity: "warning"
ignore_paths:
- "**/*_test.go"
- "testdata/**"
2. Set merge policies
Settings → Merge Policies: block on critical, comment on warning, advisory for info. This gives security a hard gate without parking refactors.
3. Dry Run before enforcing
Run scandrix rules dry-run --since 30d and review the would-be findings. Expect an initial spike on legacy code — narrow matches or triage with suppressions (/scandrix ignore <rule> --reason "<ticket>") rather than turning the rule off.
4. Evidence for auditors
- Audit log — every suppression carries author, reason, timestamp.
- Export — audit CSV for SOC 2 / ISO review periods.
- CI proof — required status check shows the policy set version active on each merge.
5. Keep it alive
Quarterly, review the rule feedback report: rules with high rejected-suggestion rates get tuned; rules with zero hits over 90 days get questioned. The pipeline only stays trusted while the signal stays clean.