Configuration

Last updated: Oct 7, 2026


Which pull requests the assistant reviews

The assistant reviews a pull request only when all these conditions are true. If one condition is false, the code hosting platform shows no result.

ConditionWhere you set it
The repository is inside the installation of the appOn GitHub, when you install or edit the app
The group has pull request review onIntegrations, SCM connections, Pull request review
The repository is a Git root of that groupScope section of the group
That root is ActiveScope section of the group

Exclude files from the review

Each Git root has an Exclusions field. The patterns of this field use gitignore syntax. The review obeys them: if an exclusion covers a file, the assistant does not report that file. This is true also when the pull request adds a vulnerable line to the file.

You edit the exclusions where you register the root. Refer to Exclude subpaths in Git repositories.

PatternWhat it excludes
test/fixtures/*All the files below test/fixtures
*.min.jsAll the minified JavaScript files
vendor/The vendor directory

Set the severity threshold

The review uses the same policy as CI Gate: Minimum to break the build. You set this policy in Policies, at the level of the organization. You can also set a different value for one group. Refer to Security gates.

A vulnerability breaks the check when its score is equal to the threshold or more than the threshold:

ThresholdScore of the vulnerabilityResult
8.18.1The check fails
8.18.0The check does not fail
8.28.1The check does not fail

The assistant detects and reports a vulnerability below the threshold. The summary comment shows it, and the diff shows it as a notice. This vulnerability does not make the check fail.

If you change the threshold, ask GitHub to re-run the check. The assistant examines again the vulnerabilities that it found before. Thus the result can change, and you do not push a commit.

Block the merges that disobey your policy

The check alone does not block a merge. To block a merge, you must make the check necessary in GitHub:

  1. Open a pull request and let the Peer Reviewer Assistant check report one time. GitHub shows a check in the branch protection only after the check reports.
  2. In the protection rule or the ruleset of the target branch, select Peer Reviewer Assistant as a required status check.
  3. In a ruleset, attach the check to the Fluid Attacks Platform app. Thus no other app can report the check in its place.

GitHub explains the two mechanisms in its own documentation:

On this page