Code Configuration
Overview
Code findings (SAST) are configured from the Nullify dashboard — there is no checked-in config file. Query findings with GET /sast/findings (and /detailed, /preview); fetch a single finding with GET /sast/findings/{findingId}, and update one with PATCH /sast/findings/{findingId}.
Autofix
Nullify drafts pull requests automatically for supported languages. Autofix is enabled per tenant; its pull request volume is fixed platform behaviour and not configurable:
3 open Nullify pull requests per repository at a time.
5 new pull requests per remediation plan.
Pull request gate
Whether Nullify reviews pull requests and whether a code finding can fail CI is controlled from Configure → Pull Requests (PUT /admin/pr-gate-settings): enabled, min_priority (URGENT or IMPORTANT), allow_approving_reviews, and allow_request_changes_reviews. See Pull Request Configuration for details.
Ignore findings
Accept a risk by allowlisting the specific finding — either per-finding from the dashboard or via the API:
POST /sast/findings/{findingId}/allowlistRequest body:
{
"allowlistReason": "HTTP requests with variables in tests are acceptable",
"allowlistType": "UserAssumeRisk"
}allowlistType is one of AI, UserFixed, UserAssumeRisk, UserFalsePositive, or UserOther. To allowlist several findings at once, use POST /sast/findings/allowlist and add a findingIds array to the same body. Remove an allowlist entry with POST /sast/findings/{findingId}/unallowlist.
Allowlist events also flow through the Nullify API so you can export them for compliance, metrics, or SIEM correlation.
Last updated