GitHub Peer Reviewer Assistant
Last updated: Oct 7, 2026
Available only for cloud-hosted GitHub repositories. GitHub Enterprise Server (on-premises) is not supported.
You connect GitHub one time for each organization, in the SCM connections screen. Then you select the groups that get their pull requests reviewed.
Role required: Organization Manager. On GitHub, you must be an owner of the organization that owns the repositories. On a personal account, you must be the owner of the account. If you are a member and not an owner, GitHub sends the request to an owner.
A GitHub account connects to one Fluid Attacks organization. Connect the account from the organization that owns the groups that you want to review.
Pull request review is available to groups on the Essential and Advanced plans.
1. Open the SCM connections screen
- In your organization, go to Integrations.
- Open the SCM connections tab.
- Click Connect SCM.
2. Select the provider
The Choose your provider window opens. Click the GitHub card.
3. Examine the permissions of the app
The Prepare the connection window shows what the Fluid Attacks GitHub App can do:
| Permission | Why the app needs it |
|---|---|
| Read access to administration, code, and metadata | To read the code that the assistant examines |
| Read and write access to checks and pull requests | To publish the check and the summary comment |
Click Configure GitHub.
4. Install the Fluid Attacks GitHub App
GitHub shows its installation screen. Do these steps:
- Select the GitHub account or organization for the app.
- Select All repositories or Only select repositories.
- Click Install.
A repository outside the installation sends no event. If the assistant does not review a repository, examine the installation of the app on GitHub first.
GitHub sends you back to the platform. A Connection established message confirms the installation.
A Connection refused message means that the platform cannot verify the installation. Install the app again.
5. Select the groups that get reviewed
The connection card has a Pull request review section. This section has one toggle for each group in the organization.
- Turn on the toggle of each group that you want to review.
- For each group, click Add repositories.
- Add the repositories of the group and select the branch of each one.
The assistant reviews each pull request of those repositories. The branch that the pull request targets does not change this.
The assistant does not review a group with its toggle off, and GitHub shows no result. Refer to Configuration for all the conditions that a pull request must obey.
6. Verify that the connection operates
- Open or update a pull request in one of the repositories that you added.
- Make sure that the check Peer Reviewer Assistant reports on the commit.
- Make sure that a summary comment appears in the conversation.
Manage the connection
The connection card has these controls:
| Control | What it does |
|---|---|
| Status | Shows Connected or Suspended |
| Verify connection | Examines the installation of the app again. If the app is not there, the platform removes the connection |
| Manage on GitHub | Opens the installation settings of the app on GitHub |
| Review permissions on GitHub | Appears when an administrator must approve new permissions. The permissions of the past continue to operate |
| Disconnect | Removes the Fluid Attacks app from the account |
Disconnect removes the app. The assistant stops the review of pull requests. The toggles of the groups go off. If you connect again, you must select the groups again.
Related information
There are also guides to integrate with GitLab and Azure DevOps.
Peer Reviewer Assistant
Review the lines that a pull request adds, report the vulnerabilities that the change introduces in a check and a comment, and grant exceptions from the Fluid Attacks platform.
GitLab Peer Reviewer Assistant
Set up the Fluid Attacks Peer Reviewer Assistant for GitLab to get automated vulnerability scanning and comments on merge requests.