GitHub Peer Reviewer Assistant
Last updated: Jul 28, 2026
Available only for cloud-hosted GitHub repositories. GitHub Enterprise Server (on-premises) is not supported.
Steps to configure the GitHub Peer Reviewer Assistant integration
This guide outlines the steps for configuring the GitHub Peer Reviewer Assistant integration within the Fluid Attacks platform. This integration enables an automatic peer reviewer to analyze pull requests (PRs) in GitHub and add inline review comments regarding security findings.
This integration is only available for groups with the Advanced plan. You must also have admin permissions on the GitHub organization or repository to install the app.
1. Initiate the integration within the Fluid Attacks platform
- Navigate to the Integrations section on the Fluid Attacks platform dashboard.
- Scroll down to locate the GitHub Peer Reviewer Assistant card.
- Click the Use integration button on the card.
2. Connect the integration to an organization group
- A window titled "Use GitHub Peer Reviewer Assistant integration" will appear.
- Select the specific group within your organization that contains the repositories you wish to scan.
- Click the Connect button next to your selected group.
3. Install the Fluid Attacks GitHub App
- You will be redirected to GitHub to install the Fluid Attacks GitHub App.
- Choose the GitHub account or organization where you want to install the app.
- Select whether to grant access to all repositories or only specific repositories.
- Click Install to grant Fluid Attacks the requested permissions and complete the installation.
- GitHub redirects you back to the Integrations page in the Fluid Attacks platform, where the group now shows as connected.
Integration management and verification
Manage the connected integration
- Return to the GitHub Peer Reviewer Assistant card and click Edit for the connected group.
- The "Manage GitHub Peer Reviewer Assistant integration" window will display the connected GitHub account, the connection date, and the granted permissions.
- From this screen, you can disconnect the integration or add a new integration for other groups.
- Click Close to exit the management window.
Verify the integration is active
- Open or update a pull request in one of the repositories covered by the installation.
- Confirm that the Fluid Attacks bot appears as a reviewer and that inline comments are posted on the changed lines where security vulnerabilities are detected.
How it works
Once active, the Peer Reviewer Assistant automatically analyzes each new or updated pull request in the configured repositories. When security vulnerabilities are detected, the integration posts inline review comments directly on the affected lines in the pull request diff, providing developers with immediate, actionable feedback.
There are also guides to integrate with GitLab and Azure DevOps.
Azure DevOps Peer Reviewer Assistant
Set up the Fluid Attacks Peer Reviewer Assistant for Azure DevOps to get automated vulnerability scanning and comments on pull requests.
Functionality
Learn how the Peer Reviewer Assistant analyzes code changes in pull requests and merge requests, reports security vulnerabilities as inline comments, and validates remediations.