Configuration File (.scandrix.yaml)
Complete schema reference for repo-level configuration, path filters, rule overrides, and review directives.
Repositories can be configured via a .scandrix.yaml or .scandrix.yml file placed at the root of the default branch. This file is version-controlled and allows engineering teams to define deterministic review rules, ignore paths, and custom prompt directives.
Minimal example
yaml
version: 1
review:
auto_review: true
severity_threshold: warning
max_comments_per_pr: 15
patch_suggestions: true
ignore:
- "dist/**"
- "vendor/**"
- "**/*.generated.ts"
- "package-lock.json"
Complete schema reference
review settings
| Field | Type | Default | Description |
|---|---|---|---|
auto_review | boolean | true | Automatically trigger review when a PR is opened or synchronized. |
severity_threshold | string | info | Minimum severity to post inline: info, warning, or critical. |
max_comments_per_pr | number | 20 | Cap on inline comments to prevent PR review notification spam. |
patch_suggestions | boolean | true | Attach ready-to-commit GitHub suggestion blocks to comments. |
summary_comment | boolean | true | Post an overarching executive review table at the top of the PR. |
block_on_critical | boolean | false | Request changes / set commit status to failure if critical bugs exist. |
ignore patterns
Glob patterns matching files that should be completely skipped during AST parsing:
yaml
ignore:
- "**/*.min.js"
- "migrations/**"
- "mocks/**"
- "tests/fixtures/**"
- "**/*.pb.go"
directives (Natural language prompt instructions)
You can provide team-specific directives that guide the AI reasoning layer alongside deterministic AST queries:
yaml
directives:
- "Enforce modern Go 1.25 conventions: prefer 'any' over 'interface{}'."
- "All database writes must execute within a tenant-scoped transaction."
- "Flag any hardcoded timeouts longer than 5 seconds in HTTP client calls."
rules (Per-rule overrides)
Override default severities or disable specific built-in Drixy rules:
yaml
rules:
# Elevate SQL injection to always block PR
sec-001:
severity: critical
enabled: true
# Downgrade strict naming lint to informational
style-042:
severity: info
# Disable regex email validator rule in favor of custom schema
val-012:
enabled: false
Centralized organization inheritance
In enterprise workspaces, organization admins can enforce a baseline .scandrix.yaml across all microservices.
- Organization rules inherit downward.
- Repositories can increase severity (e.g. from
warningtocritical), but cannot disable organization-mandated security rules unless granted an explicit admin waiver.