Troubleshooting
I cannot select an .app
Section titled “I cannot select an .app”Drag the .app directly from Finder onto the iOS drop area. If you have an .ipa, extract it and use the .app inside Payload.
My APK is rejected
Section titled “My APK is rejected”Confirm that it is a regular .apk file. AABs, extracted directories, and ZIP files are not supported. In CI, verify that the build command produces the artifact at the configured path.
Upload fails
Section titled “Upload fails”- Wait and retry.
- Check whether a VPN, proxy, or security product blocks PUT requests to object storage.
- Remove the selection and add the binary again.
- Verify the organization and target application.
Scan does not progress
Section titled “Scan does not progress”A scan can take up to about an hour. If the status remains unchanged for an extended period after reloading, record the scan ID, start time, and platform, then contact your representative. Starting the same binary repeatedly creates separate scans and consumes additional credits.
Actions cannot obtain an OIDC token
Section titled “Actions cannot obtain an OIDC token”Check that the workflow or job has id-token: write under permissions. Abyss Action does not require an API key or Application ID.
Repository is shown as not connected
Section titled “Repository is shown as not connected”After granting the GitHub App access to the repository, confirm that you linked the repository to an Abyss application under Organization → Integrations. Reconfigure the integration after transferring a repository to another organization.
CI upload does not start a scan
Section titled “CI upload does not start a scan”This is expected. Open the review page from the Abyss pull request comment and approve the credit charge. A balance below one credit cannot start a scan. If an old link is SUPERSEDED, open the submission for the latest commit.
Pull request comment or check is not updated
Section titled “Pull request comment or check is not updated”Ask an administrator to verify the GitHub App installation ID, target repository, and permissions for pull request comments and checks. If analysis is progressing in Abyss, you can still review the result from the scan details.
AI questions are unavailable
Section titled “AI questions are unavailable”Wait while the status is Preparing AI. Reports remain available if AI preparation failed. If you reached the question limit, review existing threads or contact an organization administrator.
Security gate fails
Section titled “Security gate fails”Open the decision reason and review Critical and High counts, new and recurring issues, severity increases, and expired exceptions. Incomplete analysis, including a failure on one platform, can also fail the gate.
Review the evidence and impact before relaxing a policy. Use a risk exception for a justified decision not to fix an issue.
I cannot request a risk exception
Section titled “I cannot request a risk exception”- Confirm that you entered a reason and a future expiration date.
- Confirm that you have write access.
- Check whether the vulnerability already has a pending or approved exception.
Only organization administrators can approve, reject, or revoke exceptions.