What it is
Revex reviews pull requests with a three-layer pipeline: AST analysis (tree-sitter), static analysis (Semgrep) and an LLM review (Gemini). Install it as a GitHub App, point it at a repo, and every pull request is reviewed automatically, with no manual trigger.
There is also a CLI (revex review app.py) for reviewing a single file, and a webhook server you can deploy with Docker or any platform such as Railway, Render or Fly.io.
The pipeline
Webhook
Receives
pull_requestevents: opened, updated or reopened.Diff parser
Extracts the file changes and detects each file’s language.
Prioritizer
Ranks files by risk, skips tests and configs, and batches large pull requests.
AST analyzer
tree-sitter finds unused variables, high cyclomatic complexity and functions with too many parameters.
Semgrep
Runs 23 custom rules for security, quality and performance.
LLM reviewer
Gemini analyzes the diff together with the static findings and produces line-level comments.
Post the review
Comments, severity badges and a check run are posted to the pull request.
Design decisions
Spend the model’s attention where it matters
The prioritizer reviews security-sensitive files first and skips tests and lockfiles. Large diffs are trimmed to the changed functions, using the AST, so they fit in the model’s token limit. Pull requests with 50 or more files are split into reviewable batches.
Static findings feed the LLM
The model doesn’t review blind. Gemini receives the diff together with what the AST analyzer and Semgrep already found.
Structured, bounded output
Every comment has a severity (CRITICAL, WARNING or INFO) and a category, and the pull request gets a GitHub check: a green checkmark or a red X. Reviews are rate-limited to 10 per repository per hour, configurable.
Verified webhooks
The integration is secured with JWT authentication and HMAC-SHA256 verification.
Built-in rules
23 Semgrep rules, plus three detections from the AST analyzer.
- Security (10)
- SQL injection, XSS, hardcoded secrets, eval and exec, path traversal, SSRF, weak crypto, insecure random, open redirect, debug mode
- Best practices (8)
- Empty except, mutable default arguments, bare assert, print statements, wildcard imports, broad exceptions, magic numbers
- Performance (5)
- N+1 queries, string concatenation in loops, sync I/O in async code, unnecessary copies, missing DB indexes
- AST (3)
- Unused variables, too many parameters (more than 5), high cyclomatic complexity
Python, JavaScript, TypeScript and TSX get AST analysis. Python gets all 23 Semgrep rules; JavaScript and TypeScript get 3 each. Any other language is still reviewed by the LLM.
Evaluation
A 30-case eval suite with 45 planted bugs measures detection accuracy on every change. It lives in tests/eval, next to the unit tests, alongside linting with ruff and type checking with mypy.
Stack
- Server
- FastAPI and uvicorn
- AST
- tree-sitter for Python, JavaScript, TypeScript and TSX
- Static analysis
- Semgrep, with 23 custom YAML rules
- LLM
- Google Gemini (
gemini-2.0-flashby default) - GitHub
- PyGithub and PyJWT
- CLI and config
- Click, and Pydantic v2 settings
- Deployment
- Docker, and Railway
- Python
- FastAPI
- tree-sitter
- Semgrep
- Gemini