Reviews git diffs with fast rule-based checks plus optional LLM comments, and writes a Markdown review. Ships as a CLI and a GitHub Action.
LLM-only reviewers are slow, cost money on every push, and sometimes miss the obvious. Pure linters can't explain
why something matters. code-reviewer-bot does both: a deterministic rule engine catches the things that
should never merge (leaked keys, debugger, .only, SQL built from strings), and an optional LLM adds
higher-level reviewer notes on top.
It works offline out of the box with a deterministic mock reviewer, and switches to any OpenAI-compatible API (OpenAI, Groq, Together, Ollama, LM Studio…) when you set an API key.
The review above was generated from examples/sample.diff; raw output in
examples/sample-review.md.
-
Unified diff parser:
git diff,diff -u, new/deleted/renamed/binary files, accurate new-file line numbers, hunk-aware so a removed-- commentline is never mistaken for a header -
15 built-in rules across security, correctness and hygiene:
Severity Rules 🔴 error hardcoded-secret(AWS, GitHub, Slack, Stripe, OpenAI keys, private keys, passwords),merge-conflict-marker,focused-test,debugger-statement🟠 warning sql-injection,dangerous-eval,empty-catch,console-log,ts-any,ts-ignore,large-change🔵 info loose-equality,todo-comment,long-line,missing-tests -
String-aware matching: patterns inside string literals and comments don't trigger false positives
-
Secrets are masked in the review itself, so the bot never re-leaks what it found
-
Health score and verdict (
approve/comment/request-changes) with a configurable--fail-ongate -
Pluggable notes provider:
MockProvider(offline, deterministic) orOpenAICompatibleProvider(nativefetch); if the LLM call fails the review still completes with mock notes -
Markdown or JSON output, ready for PR comments, job summaries or dashboards
-
GitHub Action (
action.yml) that posts or updates a PR comment and exposesverdict/scoreoutputs -
Zero runtime dependencies, tested with the built-in
node:testrunner
git clone https://github.com/hbtabi/code-reviewer-bot.git
cd code-reviewer-bot
npm install
npm run demo # review the bundled sample diffReview your own work:
node dist/src/cli.js # git diff HEAD in the current repo
node dist/src/cli.js --base main # compare with a branch
git diff main...feature | node dist/src/cli.js --stdin --out review.md
node dist/src/cli.js --format json --fail-on warning
node dist/src/cli.js --list-rulesexport OPENAI_API_KEY=sk-...
export OPENAI_MODEL=gpt-4o-mini # optional
export OPENAI_BASE_URL=https://api.openai.com/v1 # or Groq / Ollama (http://localhost:11434/v1) / LM Studio
node dist/src/cli.js --base mainLLM_API_KEY, LLM_BASE_URL and LLM_MODEL work too. Use --provider mock to force offline mode, or
--provider none for rules only.
# .github/workflows/pr-review.yml
on: pull_request
permissions:
contents: read
pull-requests: write
jobs:
review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with: { fetch-depth: 0 }
- uses: hbtabi/code-reviewer-bot@main
with:
comment: "true"
fail-on: error
env:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }} # optional| Input | Default | Description |
|---|---|---|
base |
PR base SHA | Ref to diff against |
diff-file |
Review a diff file instead of running git | |
fail-on |
error |
error / warning / info / never |
provider |
auto |
auto / mock / none |
comment |
false |
Post or update a PR comment |
The review is always written to the job summary. Outputs: verdict, score.
Drop a .reviewbotrc.json in your repo root (see examples/.reviewbotrc.json):
{
"disabledRules": ["loose-equality"],
"severityOverrides": { "console-log": "error" },
"maxLineLength": 120,
"largeChangeThreshold": 400,
"ignorePaths": ["package-lock.json", "dist/", "vendor/"]
}import { review, toMarkdown } from "code-reviewer-bot";
const result = await review(diffText, { llm: null });
console.log(result.summary.verdict, toMarkdown(result));code-reviewer-bot/
├── action.yml # composite GitHub Action
├── src/
│ ├── diff.ts # unified diff parser
│ ├── rules/
│ │ ├── helpers.ts # lineRule() factory, string stripping, path filters
│ │ └── index.ts # the 15 built-in rules
│ ├── review.ts # runs rules, scores, calls the notes provider
│ ├── llm.ts # MockProvider + OpenAI-compatible provider
│ ├── markdown.ts # GitHub-flavoured Markdown renderer
│ ├── config.ts # .reviewbotrc.json loader
│ └── cli.ts # command-line entry point
├── test/ # node:test suites (parser, rules, review, CLI)
├── examples/ # sample diff, sample review, workflow + config templates
└── docs/demo.png
npm test # builds, then runs 27 tests with node:testCI runs the suite on Node 20 and 22, and runs the action itself against the sample diff.
- Inline PR review comments on exact lines (GitHub review API)
- Language packs: Go, Rust and Java specific rules
- Custom rules loaded from a local
rules/folder - SARIF output for GitHub code scanning
- Cache LLM notes per diff hash to save tokens
MIT © 2026 Mohammed Hassan bin Tayyeb · Built in London at Hasenix.
