GitLab CI/CD

Connect a GitLab project with a access token, webhook, and pipeline-based review job.

ScanDrix works with GitLab.com and self-managed GitLab two ways: webhook reviews (ScanDrix comments on MRs automatically) and CI job reviews (your pipeline runs the CLI). Most teams start with webhooks and add the CI job as a merge gate.

  1. Create a project access token with api scope: Settings → Access tokens.
  2. In ScanDrix: Settings → Integrations → GitLab and paste the token.
  3. Register the webhook — see Webhook Setup for the URL and secret. Subscribe to Merge request events and Push events.

Drixy now reviews merge requests automatically.

Option B — Pipeline review job

Add a review stage to .gitlab-ci.yml so every MR runs the CLI as a merge gate:

yaml
stages:
  - review

scandrix_code_review:
  stage: review
  image: scandrix/cli:latest
  script:
    - scandrix review --ci --base $CI_MERGE_REQUEST_TARGET_BRANCH_NAME
  only:
    - merge_requests
  variables:
    SCANDRIX_TEAM_KEY: $SCANDRIX_TEAM_KEY
  • Store SCANDRIX_TEAM_KEY under Settings → CI/CD → Variables with Masked enabled.
  • --base compares against the MR target branch, so only the MR's changes are reviewed.
  • Exit code is non-zero when blocking-severity findings exist → the job fails → merge request cannot merge while required checks fail.

Webhook and CI reviews de-duplicate: if both are enabled, the CI job reuses the webhook review's findings for the same commit SHA instead of posting twice.

Protected branches

On protected branches, ensure the CI job has permission to run (it only needs to read code and write the job status — the ScanDrix API key is separate from GitLab's job token).

Troubleshooting

  • 401 from the integration — token expired or missing api scope; regenerate.
  • Reviews on the wrong branch — check the only: [merge_requests] rule matches your MR pipeline settings.
  • Self-managed GitLab behind SSO — use the self-hosted ScanDrix deployment or allowlist ScanDrix egress IPs (shown in Settings → Integrations).