Skip to content

Troubleshooting

Drag the .app directly from Finder onto the iOS drop area. If you have an .ipa, extract it and use the .app inside Payload.

Confirm that it is a regular .apk file. AABs, extracted directories, and ZIP files are not supported. In CI, verify that the build command produces the artifact at the configured path.

  • Wait and retry.
  • Check whether a VPN, proxy, or security product blocks PUT requests to object storage.
  • Remove the selection and add the binary again.
  • Verify the organization and target application.

A scan can take up to about an hour. If the status remains unchanged for an extended period after reloading, record the scan ID, start time, and platform, then contact your representative. Starting the same binary repeatedly creates separate scans and consumes additional credits.

Check that the workflow or job has id-token: write under permissions. Abyss Action does not require an API key or Application ID.

After granting the GitHub App access to the repository, confirm that you linked the repository to an Abyss application under Organization → Integrations. Reconfigure the integration after transferring a repository to another organization.

This is expected. Open the review page from the Abyss pull request comment and approve the credit charge. A balance below one credit cannot start a scan. If an old link is SUPERSEDED, open the submission for the latest commit.

Pull request comment or check is not updated

Section titled “Pull request comment or check is not updated”

Ask an administrator to verify the GitHub App installation ID, target repository, and permissions for pull request comments and checks. If analysis is progressing in Abyss, you can still review the result from the scan details.

Wait while the status is Preparing AI. Reports remain available if AI preparation failed. If you reached the question limit, review existing threads or contact an organization administrator.

Open the decision reason and review Critical and High counts, new and recurring issues, severity increases, and expired exceptions. Incomplete analysis, including a failure on one platform, can also fail the gate.

Review the evidence and impact before relaxing a policy. Use a risk exception for a justified decision not to fix an issue.

  • Confirm that you entered a reason and a future expiration date.
  • Confirm that you have write access.
  • Check whether the vulnerability already has a pending or approved exception.

Only organization administrators can approve, reject, or revoke exceptions.