Skip to content

About

Reviews git diffs with 15 rule-based checks plus optional LLM notes; outputs a Markdown review. CLI + GitHub Action.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

🤖 code-reviewer-bot

Reviews git diffs with fast rule-based checks plus optional LLM comments, and writes a Markdown review. Ships as a CLI and a GitHub Action.

CI TypeScript Node.js GitHub Actions Runtime deps License: MIT

LLM-only reviewers are slow, cost money on every push, and sometimes miss the obvious. Pure linters can't explain why something matters. code-reviewer-bot does both: a deterministic rule engine catches the things that should never merge (leaked keys, debugger, .only, SQL built from strings), and an optional LLM adds higher-level reviewer notes on top.

It works offline out of the box with a deterministic mock reviewer, and switches to any OpenAI-compatible API (OpenAI, Groq, Together, Ollama, LM Studio…) when you set an API key.

📸 Demo

code-reviewer-bot posting a Markdown review on a pull request

The review above was generated from examples/sample.diff; raw output in examples/sample-review.md.

✨ Features

  • Unified diff parser: git diff, diff -u, new/deleted/renamed/binary files, accurate new-file line numbers, hunk-aware so a removed -- comment line is never mistaken for a header

  • 15 built-in rules across security, correctness and hygiene:

    Severity Rules
    🔴 error hardcoded-secret (AWS, GitHub, Slack, Stripe, OpenAI keys, private keys, passwords), merge-conflict-marker, focused-test, debugger-statement
    🟠 warning sql-injection, dangerous-eval, empty-catch, console-log, ts-any, ts-ignore, large-change
    🔵 info loose-equality, todo-comment, long-line, missing-tests
  • String-aware matching: patterns inside string literals and comments don't trigger false positives

  • Secrets are masked in the review itself, so the bot never re-leaks what it found

  • Health score and verdict (approve / comment / request-changes) with a configurable --fail-on gate

  • Pluggable notes provider: MockProvider (offline, deterministic) or OpenAICompatibleProvider (native fetch); if the LLM call fails the review still completes with mock notes

  • Markdown or JSON output, ready for PR comments, job summaries or dashboards

  • GitHub Action (action.yml) that posts or updates a PR comment and exposes verdict / score outputs

  • Zero runtime dependencies, tested with the built-in node:test runner

🚀 Quick start

git clone https://github.com/hbtabi/code-reviewer-bot.git
cd code-reviewer-bot
npm install
npm run demo                       # review the bundled sample diff

Review your own work:

node dist/src/cli.js                         # git diff HEAD in the current repo
node dist/src/cli.js --base main             # compare with a branch
git diff main...feature | node dist/src/cli.js --stdin --out review.md
node dist/src/cli.js --format json --fail-on warning
node dist/src/cli.js --list-rules

Use a real LLM (optional)

export OPENAI_API_KEY=sk-...
export OPENAI_MODEL=gpt-4o-mini                      # optional
export OPENAI_BASE_URL=https://api.openai.com/v1     # or Groq / Ollama (http://localhost:11434/v1) / LM Studio
node dist/src/cli.js --base main

LLM_API_KEY, LLM_BASE_URL and LLM_MODEL work too. Use --provider mock to force offline mode, or --provider none for rules only.

As a GitHub Action

# .github/workflows/pr-review.yml
on: pull_request
permissions:
  contents: read
  pull-requests: write
jobs:
  review:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }
      - uses: hbtabi/code-reviewer-bot@main
        with:
          comment: "true"
          fail-on: error
        env:
          OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}   # optional
Input Default Description
base PR base SHA Ref to diff against
diff-file Review a diff file instead of running git
fail-on error error / warning / info / never
provider auto auto / mock / none
comment false Post or update a PR comment

The review is always written to the job summary. Outputs: verdict, score.

Configuration

Drop a .reviewbotrc.json in your repo root (see examples/.reviewbotrc.json):

{
  "disabledRules": ["loose-equality"],
  "severityOverrides": { "console-log": "error" },
  "maxLineLength": 120,
  "largeChangeThreshold": 400,
  "ignorePaths": ["package-lock.json", "dist/", "vendor/"]
}

Library use

import { review, toMarkdown } from "code-reviewer-bot";
const result = await review(diffText, { llm: null });
console.log(result.summary.verdict, toMarkdown(result));

🗂️ Project structure

code-reviewer-bot/
├── action.yml              # composite GitHub Action
├── src/
│   ├── diff.ts             # unified diff parser
│   ├── rules/
│   │   ├── helpers.ts      # lineRule() factory, string stripping, path filters
│   │   └── index.ts        # the 15 built-in rules
│   ├── review.ts           # runs rules, scores, calls the notes provider
│   ├── llm.ts              # MockProvider + OpenAI-compatible provider
│   ├── markdown.ts         # GitHub-flavoured Markdown renderer
│   ├── config.ts           # .reviewbotrc.json loader
│   └── cli.ts              # command-line entry point
├── test/                   # node:test suites (parser, rules, review, CLI)
├── examples/               # sample diff, sample review, workflow + config templates
└── docs/demo.png

🧪 Tests

npm test        # builds, then runs 27 tests with node:test

CI runs the suite on Node 20 and 22, and runs the action itself against the sample diff.

🛣️ Roadmap

  • Inline PR review comments on exact lines (GitHub review API)
  • Language packs: Go, Rust and Java specific rules
  • Custom rules loaded from a local rules/ folder
  • SARIF output for GitHub code scanning
  • Cache LLM notes per diff hash to save tokens

📄 Licence

MIT © 2026 Mohammed Hassan bin Tayyeb · Built in London at Hasenix.

About

Reviews git diffs with 15 rule-based checks plus optional LLM notes; outputs a Markdown review. CLI + GitHub Action.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages