Troubleshooting
Last updated: Oct 7, 2026
The assistant does not review a pull request
GitHub shows no check and no comment, and the DevSecOps section of the group shows no row. Examine this list in this sequence.
| What you must examine | Where |
|---|---|
| The repository is inside the installation of the app | On GitHub, in the settings of the app |
| The connection shows Connected | Integrations, SCM connections |
| The toggle of the group is on, below Pull request review | Integrations, SCM connections |
| The repository is a Git root of that group | Scope section of the group |
| That root is Active | Scope section of the group |
| The group is on the Essential plan or the Advanced plan | Group information |
If you change the target branch of an open pull request, the assistant does not start a review. Push a commit, or close the pull request and open it again. Then the assistant reviews it against the new branch.
The result is Incomplete
The scan did not end, thus some vulnerabilities can be absent. The result does not tell you which part of the scan failed, because your action is the same in each case.
Push a new commit, or ask GitHub for a re-run of the check.
The check does not show a change
| What you changed | What changes the check |
|---|---|
| You granted an exception | Nothing. The platform publishes a new check run on the same commit |
| The severity threshold | Ask for a re-run of the check. The assistant examines the result again, but it does not scan again |
| The exclusions of the root | Push a commit. A re-run does not scan again, thus it does not obey a new exclusion |
| The code | Push a commit |
The check is necessary, but GitHub permits the merge
The check reports the same result for a clean pull request and for a pull request that passes with exceptions. A branch protection rule cannot see the difference. Refer to Configuration.
Make sure also that you attached the check to the Fluid Attacks Platform app in your ruleset. Thus no other app can report the check in its place.
GitLab: integration not working after setup
If, after completing the integration setup, you do not see a comment in the merge request (MR) comments indicating that the analysis has started, you may need to reconnect the integration. Follow these steps:
- Navigate to the Integrations section on the Fluid Attacks platform dashboard.
- Locate the GitLab Peer Reviewer Assistant card.
- Click the Edit button (or the corresponding management button) for the connected group.
- In the Manage GitLab Peer Reviewer Assistant Integrations window, disconnect the current integration.
- Repeat the integration setup process from the beginning.
- Click the Use integration button.
- Select the group and click Connect.
- Authorize the GitLab connection.
- Configure the integration details (GitLab project).
- Click Update to finalize.
This reconnection process will refresh the integration tokens and webhook configuration, ensuring that the Peer Reviewer Assistant can properly analyze MRs.
GitLab: token expiration and renewal
The integration tokens used by the GitLab Peer Reviewer Assistant have a 6-month validity period. After this period, the integration will stop functioning and will need to be renewed.
To renew the integration, follow the same steps described in GitLab: integration not working after setup to disconnect the current integration and redo the setup.
It is recommended to set a calendar reminder 6 months after the initial integration setup to ensure continuous operation of the security analysis.
File exclusion
Exclude files and directories from Peer Reviewer Assistant reviews with the Exclusions field of the Git root, and move away from the obsolete exclusion files of the repository.
Use a configuration file
Learn to use configuration files for vulnerability scans with the Fluid Attacks scanners. Fluid Attacks offers SAST, SCA, DAST, CSPM and MAST security analysis.