Troubleshooting

Last updated: Oct 7, 2026


The assistant does not review a pull request

GitHub shows no check and no comment, and the DevSecOps section of the group shows no row. Examine this list in this sequence.

What you must examineWhere
The repository is inside the installation of the appOn GitHub, in the settings of the app
The connection shows ConnectedIntegrations, SCM connections
The toggle of the group is on, below Pull request reviewIntegrations, SCM connections
The repository is a Git root of that groupScope section of the group
That root is ActiveScope section of the group
The group is on the Essential plan or the Advanced planGroup information

The result is Incomplete

The scan did not end, thus some vulnerabilities can be absent. The result does not tell you which part of the scan failed, because your action is the same in each case.

Push a new commit, or ask GitHub for a re-run of the check.

The check does not show a change

What you changedWhat changes the check
You granted an exceptionNothing. The platform publishes a new check run on the same commit
The severity thresholdAsk for a re-run of the check. The assistant examines the result again, but it does not scan again
The exclusions of the rootPush a commit. A re-run does not scan again, thus it does not obey a new exclusion
The codePush a commit

The check is necessary, but GitHub permits the merge

The check reports the same result for a clean pull request and for a pull request that passes with exceptions. A branch protection rule cannot see the difference. Refer to Configuration.

Make sure also that you attached the check to the Fluid Attacks Platform app in your ruleset. Thus no other app can report the check in its place.

GitLab: integration not working after setup

If, after completing the integration setup, you do not see a comment in the merge request (MR) comments indicating that the analysis has started, you may need to reconnect the integration. Follow these steps:

  1. Navigate to the Integrations section on the Fluid Attacks platform dashboard.
  2. Locate the GitLab Peer Reviewer Assistant card.
  3. Click the Edit button (or the corresponding management button) for the connected group.
  4. In the Manage GitLab Peer Reviewer Assistant Integrations window, disconnect the current integration.
  5. Repeat the integration setup process from the beginning.
    • Click the Use integration button.
    • Select the group and click Connect.
    • Authorize the GitLab connection.
    • Configure the integration details (GitLab project).
    • Click Update to finalize.

This reconnection process will refresh the integration tokens and webhook configuration, ensuring that the Peer Reviewer Assistant can properly analyze MRs.

GitLab: token expiration and renewal

The integration tokens used by the GitLab Peer Reviewer Assistant have a 6-month validity period. After this period, the integration will stop functioning and will need to be renewed.

To renew the integration, follow the same steps described in GitLab: integration not working after setup to disconnect the current integration and redo the setup.

It is recommended to set a calendar reminder 6 months after the initial integration setup to ensure continuous operation of the security analysis.

On this page