Skip to content

AI code review GitHub App

Revex

Code review that catches what linters miss. Three layers (a syntax tree, static rules and an LLM) run on every pull request, and the findings come back as line-level comments with a severity.

The review pipeline, as documented in the Revex README.
Type
AI code review GitHub App
Timeline
Mar 2026
License
MIT, open source

What it is

Revex reviews pull requests with a three-layer pipeline: AST analysis (tree-sitter), static analysis (Semgrep) and an LLM review (Gemini). Install it as a GitHub App, point it at a repo, and every pull request is reviewed automatically, with no manual trigger.

There is also a CLI (revex review app.py) for reviewing a single file, and a webhook server you can deploy with Docker or any platform such as Railway, Render or Fly.io.

The pipeline

  1. Webhook

    Receives pull_request events: opened, updated or reopened.

  2. Diff parser

    Extracts the file changes and detects each file’s language.

  3. Prioritizer

    Ranks files by risk, skips tests and configs, and batches large pull requests.

  4. AST analyzer

    tree-sitter finds unused variables, high cyclomatic complexity and functions with too many parameters.

  5. Semgrep

    Runs 23 custom rules for security, quality and performance.

  6. LLM reviewer

    Gemini analyzes the diff together with the static findings and produces line-level comments.

  7. Post the review

    Comments, severity badges and a check run are posted to the pull request.

Design decisions

Spend the model’s attention where it matters

The prioritizer reviews security-sensitive files first and skips tests and lockfiles. Large diffs are trimmed to the changed functions, using the AST, so they fit in the model’s token limit. Pull requests with 50 or more files are split into reviewable batches.

Static findings feed the LLM

The model doesn’t review blind. Gemini receives the diff together with what the AST analyzer and Semgrep already found.

Structured, bounded output

Every comment has a severity (CRITICAL, WARNING or INFO) and a category, and the pull request gets a GitHub check: a green checkmark or a red X. Reviews are rate-limited to 10 per repository per hour, configurable.

Verified webhooks

The integration is secured with JWT authentication and HMAC-SHA256 verification.

Built-in rules

23 Semgrep rules, plus three detections from the AST analyzer.

Security (10)
SQL injection, XSS, hardcoded secrets, eval and exec, path traversal, SSRF, weak crypto, insecure random, open redirect, debug mode
Best practices (8)
Empty except, mutable default arguments, bare assert, print statements, wildcard imports, broad exceptions, magic numbers
Performance (5)
N+1 queries, string concatenation in loops, sync I/O in async code, unnecessary copies, missing DB indexes
AST (3)
Unused variables, too many parameters (more than 5), high cyclomatic complexity

Python, JavaScript, TypeScript and TSX get AST analysis. Python gets all 23 Semgrep rules; JavaScript and TypeScript get 3 each. Any other language is still reviewed by the LLM.

Evaluation

A 30-case eval suite with 45 planted bugs measures detection accuracy on every change. It lives in tests/eval, next to the unit tests, alongside linting with ruff and type checking with mypy.

Stack

Server
FastAPI and uvicorn
AST
tree-sitter for Python, JavaScript, TypeScript and TSX
Static analysis
Semgrep, with 23 custom YAML rules
LLM
Google Gemini (gemini-2.0-flash by default)
GitHub
PyGithub and PyJWT
CLI and config
Click, and Pydantic v2 settings
Deployment
Docker, and Railway
Next case studyComplyDeskCompliance software for small companies