Review in the platform
Last updated: Oct 7, 2026
This page describes the GitHub integration. The work on the GitLab and Azure DevOps integrations continues. The goal is the same behavior as GitHub. Refer to their own pages.
You find each review of a pull request in the DevSecOps section of the group.
The DevSecOps table
Go to the DevSecOps section of the group. A row with the Type Peer Reviewer Assistant is a review of a pull request.
| Column | What it shows for a pull request |
|---|---|
| Identifier | PR #18 · ea65c74, with the source branch below |
| Type | Peer Reviewer Assistant |
| Status | In progress, Passed, Passed with exceptions, Failed, or Incomplete |
| Vulnerabilities | The total, with N unmanaged · M accepted below. A dash while the scan continues |
| Breaks build | Yes or No. A dash while the scan continues |
| Strictness | Strict. One unmanaged vulnerability makes the check fail |
| Technique | SAST · SCA · SS |
| Git repository | The nickname of the root |
| Executed date | The date when the review ended |
The platform does not count a vulnerability below the severity threshold as unmanaged, and it does not count it as accepted. Thus this column shows no quantity for a review that found only these vulnerabilities. The detail of the review shows them.
The detail of one review
Click the identifier of the row to open the review. The View details in Fluid Attacks → link in the summary comment opens the same page.
The header shows the number and the title of the pull request, its status, and six fields:
| Field | What it shows |
|---|---|
| Git repository | The nickname of the root |
| Branch | The source branch and the target branch |
| Commit | The commit of the review |
| Pull request | The number of the pull request |
| Author | The person who opened the pull request |
| Executed date | The date when the review ended |
Copy link gives you the address of the review. Send it to a person who can grant an exception. Open in SCM opens the pull request again.
Vulnerabilities
This tab shows each vulnerability of the review:
| Column | What it shows |
|---|---|
| Weakness | The criteria code and the name of the weakness |
| Vulnerability | The file |
| Specific | The line |
| Technique | SAST, SCA, or SS |
| Severity (v4.0) | The CVSS 4.0 score, or a dash |
| Gate | Unmanaged, Accepted, or a dash for a vulnerability below the threshold |
An Accepted vulnerability also shows its exception, the person who granted the exception, and the date.
Click Export CSV to get the list as a file.
You also grant the exceptions in this tab. Refer to Exceptions.
Exceptions
This tab shows one card for each exception. The card shows the quantity of vulnerabilities, the justification, the person who granted the exception, the date, and the time from that date.
Pushes
This tab shows one row for each commit of the review, the newest first. Each row shows the date of the push, the result of the review, the commit, and the quantity of unmanaged vulnerabilities.
This is the history of the pull request.
If the Peer Reviewer Assistant did not review a pull request, the platform tells you so. It does not show an empty review.
Related information
Exceptions
Grant an exception, thus a pull request can merge with a vulnerability that you accept, with a justification and a record of the person who granted it.
File exclusion
Exclude files and directories from Peer Reviewer Assistant reviews with the Exclusions field of the Git root, and move away from the obsolete exclusion files of the repository.