Skip to content
CAI
Software that uses CAICheck a score

DGouron/review-flow

68.8

Adequate · 21 September 2026

39.8k

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a self-hosted, daemonized code review automation service that integrates with GitHub and GitLab to execute AI-driven code reviews using Anthropic's Claude models. It manages the full lifecycle of review jobs—including webhook ingestion, model routing, background execution, and result posting—while enforcing strict security, budget caps, and quality gates. The platform provides a web dashboard and an MCP interface for monitoring stats, managing pending reviews, and interacting with a read-only AI assistant for project insights.

Features

Add formatted initialization summary output

The CLI now provides a structured, human-readable summary after running the initialization wizard. This new output details the configuration paths, port, repository count, and the status of the MCP server setup, followed by clear next steps for configuring webhooks and starting the server.

src/cli/formatters · high confidence

Added project setup templates and configuration scaffolding

Introduced new template files to guide users through the initial setup of the reviewflow tool. This includes SETUP.md with instructions for configuring the \.claude\ directory structure, \config.json.template\ for defining review agents and platform settings (GitLab/GitHub), \SKILL.md.template\ providing a code review skill definition with progress markers and inline comment logic, and \claude-mcp-config.example.json\ for MCP server integration.

templates · high confidence

Background mode for Claude invocation with health and billing timers

The \claudeInvocationTimers\ module now manages background operations for Claude invocations, specifically supporting the new \--bg\ mode. It introduces two periodic tasks: a supervisor health check and a billing audit, both running on configurable intervals. This allows the system to monitor session health and track billing state asynchronously without blocking the main execution flow.

src/frameworks/claude/timers · high confidence

CLI gateways for GitHub and GitLab review actions

New CLI gateway implementations for the review-execution module now translate internal review actions into platform-specific CLI commands. The GitHub gateway uses the \gh\ CLI to resolve threads, post comments, reply to threads, add labels, and create inline comments via GraphQL and REST APIs. The GitLab gateway uses the \glab\ CLI to perform equivalent operations, including enriching comment bodies with links and constructing inline comments with precise file/line positioning via the API. These gateways enable the CLI interface to execute review actions on both GitHub and GitLab repositories.

src/modules/review-execution/interface-adapters/gateways/cli · high confidence

CLI gateways for approval revocation, comment posting, and review labeling

New CLI gateway implementations have been added for GitHub and GitLab to handle approval revocation, posting comments (including threaded replies), and managing review labels. These gateways execute platform-specific CLI commands (gh and glab) via a command executor, ensuring that comment bodies and label values are shell-quoted to prevent injection issues when running through /bin/sh. The approval revocation gateways dismiss reviews on GitHub and unapprove merge requests on GitLab. The comment posting gateways create new comments and reply to existing threads using REST or GraphQL APIs as appropriate. The review label gateways ensure labels exist and add/remove them from pull requests or merge requests.

src/modules/platform-integration/interface-adapters/gateways/cli · high confidence

Initial module structure for model routing, backfill progress, and token usage tracking

This change introduces the foundational entity definitions and use-case skeletons for three new bounded contexts. In review execution, it defines the \RoutingPolicy\ schema (validating Claude model names and line limits) and its gateway interface. In statistics insights, it establishes the \BackfillProgress\ type to track job status and counts. In token accounting, it creates the \TrackTokenUsage\ use case, which delegates recording to a token usage gateway. These files provide the structural contracts and initial logic for these features.

src/modules/review-execution/entities/modelRouting, src/modules/statistics-insights/entities/backfill, src/modules/token-accounting/usecases/trackTokenUsage · high confidence

Introduce AI-powered code review insights with persistent developer metrics

The statistics-insights module now generates AI-driven insights for code reviews. This change introduces a new background session workflow (generateAiInsightsViaSession) that builds prompts from review data and dispatches them to an AI provider, while persisting the results. It also adds a persistence layer (computeInsightsWithPersistence) that tracks processed review IDs and reconciles diff stats from a rolling window to ensure metrics remain accurate as new reviews arrive. Additionally, the system now computes detailed developer and team insights (computeDeveloperInsights, computeTeamInsights) based on quality, responsiveness, code volume, and iteration trends, exposing these via a unified status endpoint (getInsightsWithAiStatus) that indicates whether AI insights are stale due to new reviews.

src/modules/statistics-insights/usecases/insights · high confidence

Introduce Ember, a read-only conversational AI assistant for project review insights

This change adds the Ember module, enabling users to ask natural-language questions about their project's review data (scores, insights, job history, worktrees) via a live, streaming chat interface. Ember operates in a strict read-only mode, grounding its answers in recent project statistics and a private per-project memory notebook that persists conversation history and recurring insights. Users can clear this memory via the dashboard, and Ember can autonomously record recurring findings to its private notebook to improve future context without modifying any project state.

src/modules/ember-chat · high confidence

Introduce Model Context Protocol (MCP) server for programmatic code review control

The \src/mcp\ directory now contains the core infrastructure for a new Model Context Protocol (MCP) server, enabling external tools to programmatically interact with the code review workflow. This includes a file-based logging system (\mcpLogger.ts\) for debugging, a server implementation (\server.ts\, \mcpServerStdio.ts\) that exposes tools for managing review jobs (such as \get\_workflow\, \start\_agent\, \complete\_agent\, \set\_phase\, \get\_threads\, \add\_action\, and \record\_insight\), and support for per-job context files to facilitate lazy-loading of review state. The \add\_action\ tool specifically supports platform-agnostic inline comments, allowing external agents to post comments directly to files and lines.

src/mcp · high confidence

Introduce automated schedulers for cleanup, supervisor management, and worktree sweeps

The scheduler framework now includes three new background schedulers that automate routine maintenance tasks. The Cleanup Scheduler runs daily to remove expired review files based on project-specific retention policies. The Supervisor Scheduler periodically checks and respawns supervisor agents to ensure they remain active. The Worktree Sweep Scheduler performs daily sweeps to remove stale worktrees and provides APIs to query the last sweep status, next scheduled time, and trigger manual sweeps.

src/frameworks/scheduler · high confidence

Introduce background session dispatch with reliable prompt handling and cross-process completion bridging

The interface-adapters layer now supports dispatching Claude CLI sessions in background mode (--bg) and reliably receiving their results. The CLI gateway ensures the user prompt is not swallowed by variadic tool flags by appending a '--' terminator, and it correctly extracts the session ID from stdout even when ANSI escape codes are present. To handle the asynchronous nature of background agents, a file-system-based MCP completion bridge has been added, allowing the Fastify host to poll for completion signals written by the MCP sub-process, alongside an in-memory bridge for single-process scenarios. Supporting gateways for billing state, supervisor health, environment checks, and review report storage have also been implemented to complete the background invocation workflow.

src/modules/claude-invocation/interface-adapters · high confidence

Introduce configurable runtime settings with persistent storage

The application now supports a new runtime settings system that persists user preferences across restarts. Users can configure the AI model (haiku, sonnet, or opus), interface language, worktree stale threshold, trigger mode, and review timeout (5–480 minutes). These settings are stored in a JSON file at \~/.claude-review/settings.json and are validated against strict schemas to ensure data integrity.

src/frameworks/settings · high confidence

Introduce domain entities and gateways for the Claude invocation module

This change establishes the foundational data models and interface contracts for the \claude-invocation\ module, defining core entities such as \ClaudeSession\, \BillingState\, \SupervisorHealth\, and \SessionCompletion\ via Zod schemas. It introduces gateway interfaces (e.g., \ClaudeSessionGateway\, \BillingStateGateway\) to abstract external dependencies like session dispatching, billing tracking, and health monitoring, while also adding value objects for retry scheduling and guards for data validation. These components provide the structural basis for managing background Claude sessions, tracking usage, and handling session lifecycle events.

src/modules/claude-invocation/entities · high confidence

Introduce egress content scanning for public outputs

Added a new egress scanning module that inspects public-facing content (such as comments and posts) before publication. The scanner detects secrets (e.g., API keys, tokens), out-of-scope project references, and excessive body length, applying configurable policies to either allow, redact, or block the content. It provides a gateway interface for integration and a trace gateway to record scan outcomes, with sensible defaults for redaction markers and size limits.

src/modules/platform-integration/entities/egressScan · high confidence

Introduce monthly token budget tracking and usage reporting

Users can now set a monthly spending cap for Claude API usage (defaulting to $200, with a maximum of $600) and monitor their consumption against this limit via new HTTP endpoints. The \src/modules/token-accounting\ module implements the core logic for calculating costs based on Anthropic's model-specific pricing (including Opus 4, Sonnet 4, and Haiku 4-5 rates), persisting usage records and budget configurations to the local filesystem, and exposing status summaries that show remaining balance, percentage used, and cost breakdowns by model.

src/modules/token-accounting · high confidence

Introduce new dashboard UI with setup wizard and stats page

The dashboard now includes a dedicated setup wizard interface (setup.html) with interactive forms, avatar visualization, and step-by-step configuration flow, alongside a new /stats page (stats.html) featuring a volume hero section with key metrics (reviews, commits, additions/deletions) and a back navigation. These pages are styled with a new design system (styles.css) using warm near-black backgrounds, amber-gold accents, and Geist/JetBrains Mono typography, and are powered by the Anime.js v4.4.1 animation library for smooth transitions and visual feedback.

src/dashboard · high confidence

Introduce pending review request entity with schema, validation, and gateway interface

This change adds the foundational data structures and access patterns for pending review requests within the review-execution module. It defines a Zod schema for \PendingReviewRequest\ and \ReviewJobSnapshot\, capturing details such as platform (GitLab/GitHub), project paths, merge request metadata, and trigger sources (webhook-initial, webhook-followup, dashboard-manual). A corresponding guard is provided for runtime validation, and a gateway interface is established to handle saving, loading, listing, and deleting these pending requests.

src/modules/review-execution/entities/pendingReviewRequest · high confidence

Introduce review request entity and state machine

This change introduces the core data model and lifecycle logic for review requests within the new \review-execution\ module. It defines the \ReviewRequest\ entity schema (using Zod) to capture details like platform, branch info, and metadata, along with validation guards. Crucially, it implements a \ReviewRequestState\ value object that enforces a strict state machine with defined transitions (e.g., from \pending-fix\ to \merged\ or \closed\), ensuring that review requests only move through valid statuses.

src/modules/review-execution/entities/reviewRequest · high confidence

Introduce review state labels for automated review tracking

The system now uses specific platform labels to signal the state of automated reviews on merge requests. A new 'review-in-progress' label marks MRs currently being reviewed, while a 'review-done' label indicates that the automated review has completed. These labels are managed via a new gateway interface that handles ensuring the labels exist on the project and adding or removing them from specific merge requests.

src/modules/platform-integration/entities/reviewLabel · high confidence

Introduce shared domain entities and value objects for the shared kernel

This change establishes a set of foundational domain models and validation schemas within the shared kernel module, providing reusable types for the rest of the application. It introduces a \Duration\ value object to handle time-based calculations and formatting, a \TriggerMode\ schema to enforce 'full-auto' or 'semi-auto' states, and a \Language\ schema for 'en' and 'fr'. Additionally, it defines core entity types for repository configuration, diff statistics, and a new \DiffSizeGate\ mechanism that evaluates merge request sizes against a budget while excluding lock files. These components serve as the structural basis for features like oversized merge request guarding and self-service stats backfilling.

src/modules/shared-kernel · high confidence

Introduce shared service utilities for CLI, daemon, and security

This change adds a suite of new shared services in src/shared/services to support the CLI and daemon infrastructure. It introduces ANSI color helpers that respect the NO\_COLOR environment variable, a browser opener that uses execFileSync to prevent command injection, and a Claude CLI path resolver that automatically locates the executable via which, nvm, or common paths. Daemon support is enabled through configuration directory detection (respecting XDG\_CONFIG\_HOME), PID file management with schema validation, log file reading and watching, and a daemon spawner. Additional utilities include dependency checking for GitLab/GitHub CLIs, process existence checks, and secure webhook secret generation and validation.

src/shared/services · high confidence

Introduce worktree lifecycle management with health monitoring and force cleanup

This change adds the core backend logic for managing Git worktrees, including creating, listing, and removing them based on their association with pull requests. It introduces a health-probing system that detects degraded worktrees caused by stale inactivity, orphaned Git locks, or unresolved merge conflicts, and exposes these via a new HTTP overview API. Users can now trigger manual sweeps to remove stale or closed worktrees and perform force cleanup on specific worktrees, with concurrency protection to prevent race conditions during removal.

src/modules/worktree-management · high confidence

Introduces a daemon-capable CLI with startup banner and management commands

The application now includes a full command-line interface entry point (\src/main/cli.ts\) that supports \start\, \stop\, \status\, \logs\, \init\, \discover\, \validate\, and \followup-importants\ commands. The \start\ command can run as a background daemon (controlled via \--daemon\), manages a PID file for lifecycle tracking, and displays a startup banner with dashboard and webhook URLs (implemented in \src/cli/startupBanner.ts\). This provides users with a structured way to manage the review service from the terminal, including daemon control and configuration validation.

src/main · high confidence

Introduces core job execution entities and persistence interfaces

This change establishes the foundational data models and interfaces for the review job execution module. It defines the \ReviewJob\ and \JobStatus\ structures to capture detailed metadata about code review tasks (including platform, branch, and audit scope), and introduces a \JobRecord\ schema with Zod validation to persist job history to disk. Additionally, it provides gateway interfaces (\JobContextGateway\ and \JobHistoryGateway\) to manage job context registration and handle the append, load, and pruning of historical job records.

src/modules/review-execution/entities/job · high confidence

Introduces file-system and memory gateways for review execution state persistence

The review execution module now includes concrete gateway implementations to persist and retrieve review state. A file-system gateway stores review contexts, pending review requests, and progress data as JSON files in local directories (such as the user's home directory or project-specific \.claude/reviews/logs\ paths), ensuring state survives application restarts. Additionally, in-memory gateways are provided for job context and review progress tracking, while a GitLab-specific gateway handles authenticated thread inventory retrieval via the \glab\ CLI. These adapters enable the review system to maintain state across sessions and integrate with GitLab discussion threads.

src/modules/review-execution/interface-adapters/gateways · high confidence

Introduces real implementations for statistics and AI insights gateways

This change adds concrete interface-adapter implementations for the statistics-insights module, replacing stubs or missing logic with production-ready gateways. It introduces \GitHubDiffStatsFetchGateway\ and \GitLabDiffStatsFetchGateway\ to fetch accurate diff statistics (additions, deletions, commits) from GitHub and GitLab respectively, ensuring real data is used for insights. It also adds \AiInsightsSessionClaudeGateway\ to execute AI insights via a background Claude session, polling the transcript for results. Additionally, \FileSystemInsightsGateway\ and \FileSystemStatsGateway\ are added to persist and load insights and project statistics to/from local JSON files, with \FileSystemStatsGateway\ including a lenient fallback to prevent crashes on legacy or partial data formats.

src/modules/statistics-insights/interface-adapters/gateways · high confidence

Introduces review execution entities and agent definitions

This change adds the core entity definitions for the review execution module, including agent configurations for various review focuses (front, back, fullstack, doc) and specific agents like Clean Code, Threads, and Report. It defines the progress tracking model with phases and agent statuses, a principle catalog for detecting project-specific principles, and a review score value object for tracking blocking issues, warnings, and suggestions. These entities form the foundation for the review execution workflow.

src/modules/review-execution/entities/progress · high confidence

Introduces strict validation schemas for developer, team, and AI insights

The statistics-insights module now enforces strict data contracts for insight entities using Zod schemas. This change adds validation definitions and type definitions for developer insights (including metrics, category levels, and titles), team insights (including average levels and tips), and AI-generated insights. It also defines schemas for persisted insights data to ensure consistency when saving review statistics and AI results, along with corresponding guard utilities for parsing and validating incoming data.

src/modules/statistics-insights/entities/insight · high confidence

Introduction of WebhookEvent type definitions for platform integration

The platform integration module now includes a new TypeScript file defining the \WebhookEvent\ union type. This type standardizes the structure of incoming webhook payloads by establishing a common base (\WebhookEventBase\) containing platform, project, and merge request metadata, and then extending it with specific fields for distinct event types such as \review-requested\, \followup-push\, \close\, \merge\, \approve\, and \ignored\. This change provides a strict contract for handling these events within the integration layer.

src/modules/platform-integration/entities/webhookEvent · high confidence

New CLI configuration and repository management capabilities

This change introduces a suite of new use cases within the CLI configuration module that enable users to initialize project settings, manage repository lists, and control the background daemon. Users can now run an init command to generate configuration files, discover and add local Git repositories to the system, and toggle repositories on or off. The module also adds commands to start, stop, and query the status of the review daemon, validate configuration integrity, and configure MCP server settings. Additionally, dashboard-specific wrappers are provided to expose these repository management actions through the web interface.

src/modules/cli-configuration/usecases/cli · high confidence

New HTTP API endpoints for CLI configuration, status, and management

This change introduces a new set of HTTP routes in the CLI configuration module, exposing several new capabilities to users via the Fastify server. Users can now check the operational status and version of the Claude CLI, GitLab CLI (glab), and GitHub CLI (gh) via dedicated status endpoints. A new health and status API provides system health, queue statistics, job status, and version update availability. Runtime settings such as the AI model, language, trigger mode, and review timeout are now editable via API, with the review timeout change applied live without requiring a daemon restart. Project configuration (including review focus, skills, and thresholds) can be read and patched. Additionally, users can manage project repositories (add, remove, enable/disable) and check for or trigger self-updates for the CLI tool itself.

src/modules/cli-configuration/interface-adapters/controllers · high confidence

New HTTP API endpoints for project statistics, insights, and multi-project overview

This change introduces three new Fastify route modules that expose the statistics and insights capabilities via HTTP. The \/api/overview\ endpoint aggregates data across all enabled repositories, providing a multi-project summary including active jobs, capacity, and recent reviews. The \/api/stats\ endpoint serves detailed project metrics, including an analytics header, key insights, and bugs categorized by type, and now supports a \POST /api/stats/recalculate\ action that allows users to trigger a self-service backfill of historical data. Additionally, the \/api/insights\ and \/api/insights/generate\ endpoints provide access to developer and team insights, including the ability to generate new AI-driven insights for a specific project path.

src/modules/statistics-insights/interface-adapters/controllers · high confidence

New HTTP API for MR tracking, quality gates, and oversized-MR management

This change introduces a new set of HTTP routes in the tracking module to manage merge request reviews and dashboard interactions. Users can now retrieve MR tracking data (pending, approved, merged, closed) enriched with diff statistics via the \/api/mr-tracking\ endpoint. The \/api/mr-tracking/approve\ endpoint enforces a configurable quality threshold, blocking approval if the review score or open threads fall below the project's defined limit. Additionally, a new \/api/mr-tracking/mark-as-merged\ endpoint allows manual marking of reviews as merged, while the \/api/size-blocks\ and \/api/mr-tracking/force-start\ endpoints provide a dashboard interface to identify and manually launch reviews for oversized merge requests that were previously blocked. These routes are backed by a new file-system-based tracking gateway and dedicated presenters for state and size-block data.

src/modules/tracking/interface-adapters · high confidence

New HTTP and MCP interfaces for review execution and pending review management

This change introduces the HTTP route definitions and MCP (Model Context Protocol) tool handlers for the review-execution module. On the HTTP side, new endpoints allow users to list, confirm, and dismiss pending reviews, as well as list, read, delete, and cancel active review jobs. On the MCP side, new handlers expose tools to start agents, complete agents, set review phases, retrieve workflow and thread information, and add actions (such as replies or comments) to a review job. Supporting presenters format job statuses, pending review requests, and review context progress for these interfaces.

src/modules/review-execution/interface-adapters/controllers · high confidence

New MCP integration use cases for review execution

Added a new set of use cases in the review-execution module to support Model Context Protocol (MCP) interactions. These include addAction for submitting review actions (thread resolves, replies, and comments), getThreads for retrieving discussion threads, getWorkflow for exposing the current review state and agent instructions, and lifecycle handlers (startAgent, completeAgent, setPhase) to manage agent execution and progress. The setPhase use case also integrates with a completion bridge to publish completion events when a review phase is marked as completed.

src/modules/review-execution/usecases/mcp · high confidence

New bug category breakdown and key insights for code reviews

The statistics module now categorizes review findings into six specific types—Security, Logic, Performance, Type Safety, Style, and Dependencies—and aggregates them into a category breakdown. This data powers new Key Insights that highlight the dominant bug category, track review volume trends over the last 30 days, monitor changes in average review duration, and assess code volume. The system also introduces a 12-month trailing window for monthly review volume tracking and adds support for parsing category data from structured review output lines.

src/modules/statistics-insights/entities/stats · high confidence

New centralized configuration loader with validation and repository enrichment

The application now uses a new \configLoader.ts\ module to load, validate, and enrich configuration data. This module handles environment variable loading, validates server ports, and processes repository configurations by automatically detecting Git remote URLs and determining the platform (GitHub or GitLab) based on project-specific settings. It also supports a new 'semi-auto' trigger mode and allows empty usernames for single-platform users, providing a more robust and flexible configuration experience.

src/frameworks/config · high confidence

New dashboard modules for animations, budget tracking, and Ember chat

The dashboard now includes a suite of new modules: animations.js provides anime.js helpers for UI transitions and respects reduced-motion preferences; budgetSettings.js introduces a monthly Claude budget cap with a live gauge and WebSocket status updates; desktopNotifications.js adds rich, interactive desktop notifications for review events; emberAvatar.js and emberAvatarRenderer.js render an animated flame wireframe avatar; emberChat.js implements a read-only chat client for the Ember AI assistant; and cardCounters.js, collapsibleList.js, cleanup.js, and assignee.js add new UI components for review tracking, list management, and data cleanup.

src/dashboard/modules · high confidence

New gateway interfaces for posting comments and thread replies

The platform integration layer now exposes specific gateway interfaces for note comments, defining the input structures and methods required to post a new comment or reply within an existing thread. This introduces the \NoteCommentPostGateway\ contract along with its associated input types (\NoteCommentPostInput\ and \NoteCommentThreadReplyInput\), establishing the API surface for these interactions without yet implementing the underlying logic.

src/modules/platform-integration/entities/noteComment · high confidence

New platform integration gateways for GitLab and GitHub

This change introduces a new set of interface-adapters in the \src/modules/platform-integration/interface-adapters/gateways\ directory to support platform-specific operations. It adds dedicated gateways for fetching changed files and diff metadata for both GitHub and GitLab, as well as thread fetching capabilities for both platforms. Additionally, it includes a scoped GitLab executor that enforces least-privilege access by isolating credentials and environment variables, a member access resolver for GitLab with caching, an in-memory idempotency store, and an egress scanning gateway that scans and potentially redacts or blocks outgoing comments based on security policies.

src/modules/platform-integration/interface-adapters/gateways · high confidence

New project identifier resolution utility

Added a new \resolveProjectIdentifier\ function in the statistics-insights module that extracts a normalized project path from Git remote URLs. The utility supports both SSH and HTTP(S) formats, strips the \.git\ suffix, and returns a slash-separated path (e.g., \owner/repo\) only when at least two segments are present; otherwise, it returns null.

src/modules/statistics-insights/entities/projectIdentifier · high confidence

New review orchestration and webhook processing use cases

This change introduces a suite of new use cases in the platform-integration layer to manage the review lifecycle and webhook handling. It adds logic to gate auto-runs based on trusted reviewer membership (IsTrustedActor), guard against oversized merge requests with a split message (GuardDiffSize), and signal review states using platform labels (MarkReviewInProgress, MarkReviewDone, ClearReviewInProgress). Additionally, it centralizes webhook processing (ProcessWebhook) to handle close, merge, follow-up, and approval events, and orchestrates review requests (ProcessReviewRequest) by enforcing budget limits and actor trust before queuing.

src/modules/platform-integration/usecases · high confidence

New shared foundation interfaces and base classes for domain-driven architecture

The shared foundation layer now includes a set of new base classes and interfaces to support a structured, domain-driven approach. This includes \ApplicationRuleViolation\ and \BusinessRuleViolation\ for distinct error handling, a \Guard\ utility built on Zod for input validation, and base classes like \ExecutionGatewayBase\ and \Gateway\ to standardize command execution and data access. Additionally, \Presenter\ and \UseCase\ interfaces are introduced to enforce separation of concerns between domain logic and output formatting.

src/shared/foundation · high confidence

New statistics and insights dashboard components

The statistics and insights module now includes a comprehensive set of new presenter classes that transform raw project data into structured views for the user interface. These presenters power the multi-project overview, displaying active review jobs, project cards with sparkline history, and recent review feeds. Additionally, dedicated presenters now render the analytics header with key performance indicators (PRs reviewed, bugs caught, average review time), key insight cards summarizing project health, and a breakdown of bugs by category. The system also presents detailed developer and team insights, including individual strengths, weaknesses, and overall levels, alongside a comprehensive stats summary that tracks trends in code quality and review volume over time.

src/modules/statistics-insights/interface-adapters/presenters · high confidence

New tracking use cases for MR lifecycle, quality gates, and state transitions

The tracking module now includes a comprehensive set of new use cases that manage the full lifecycle of tracked merge requests. Users can now track assignments, record pushes and review completions (including quality scores and blocking issues), and handle platform approvals with automatic quality gate enforcement. The system supports comment-based bypasses for quality gates, allows manual marking of reviews as merged (which cleans up jobs and worktrees), and enables force-launching of blocked reviews for oversized MRs. State transitions are now gated by quality checks and can be explicitly controlled, ensuring that approvals and merges respect defined quality thresholds unless explicitly bypassed.

src/modules/tracking/usecases/tracking · high confidence

Persist and manage job execution history

The review execution module now records job outcomes to disk, allowing users to view recent job history and ensuring old records are automatically pruned based on a configurable retention period. This change introduces three new use cases: \LoadRecentJobHistoryUseCase\ retrieves the most recent job records sorted by completion time; \PersistJobRecordUseCase\ saves job details (including status mapping for success, killed, timeout, or failed) to the history gateway; and \PruneJobHistoryUseCase\ removes records older than the specified retention window. These components rely on the \JobHistoryGateway\ to handle the underlying storage operations.

src/modules/review-execution/usecases/jobHistory · high confidence

Review statistics now include diff metrics and support manual recalculation with backfill

The statistics insights module now tracks code change metrics (additions, deletions, and commit counts) alongside traditional review data like scores and warnings. To ensure data completeness, a new backfill mechanism can populate missing diff statistics for existing reviews, and a self-service recalculation feature allows users to manually trigger this backfill and aggregate update via a dedicated use case.

src/modules/statistics-insights/usecases/stats · high confidence

Setup wizard introduces structured entity models and HTTP streaming interface

The setup wizard now defines a comprehensive set of Zod schemas and gateway interfaces for its internal entities (such as project context, step outcomes, and agent presets) to enforce data integrity. It also introduces a new HTTP API with endpoints to start, cancel, and submit input to a setup run, and to stream real-time wizard events to clients via Server-Sent Events (SSE).

src/modules/setup-wizard · high confidence

Supervisor lifecycle management for Claude agents

The supervisor-management module now implements the lifecycle management for the Claude agents supervisor, including health probing, detached spawning, and automatic respawning when the process becomes unreachable. This change introduces a file-system-based lock mechanism to prevent concurrent supervisor instances and an in-memory status store to track the supervisor's state (up, down, or unknown) over time.

src/modules/supervisor-management · high confidence

Removals

Removal of legacy webhook processing logic

The \src/webhooks\ directory has been cleared of its previous implementation, specifically deleting \eventFilter.ts\, \github.handler.ts\, and \gitlab.handler.ts\. This removes the code responsible for verifying webhook signatures, filtering GitLab Merge Request and GitHub Pull Request events based on reviewer assignments and state, and enqueuing review jobs for these platforms. Users will no longer receive automated code reviews triggered by these specific webhook handlers in this location.

src/webhooks · high confidence

Removal of local deployment and setup scripts

The local installation and configuration assets for the Claude Review Automation Server have been removed. This includes the systemd service units for the Node.js application and the Cloudflare Tunnel, the example Cloudflare configuration file, the shell script used to install these services, and the webhook testing utility. Users can no longer use these provided scripts to deploy or test the server locally via systemd and Cloudflare tunnels.

setup · high confidence

Removal of the legacy review job queue implementation

The \src/queue/reviewQueue.ts\ file has been deleted, removing the previous implementation of the review job queue. This change eliminates the specific job deduplication logic, the \PQueue\-based concurrency management, and the in-memory tracking of active and completed review jobs that were previously handled in this module.

src/queue · high confidence

Architecture

Modularized architecture introduces bounded contexts for review execution, platform integration, and data lifecycle

The codebase has been restructured into eight bounded contexts under src/modules/, establishing a cleaner separation of concerns. This change introduces specific capabilities within these new modules: the platform-integration module now includes adapters to translate GitHub and GitLab webhook events into a unified ReviewRequest format; the review-execution module adds a SelectModelForReview use case that routes diff analysis to specific AI models (Haiku, Sonnet, or Opus) based on line-count thresholds defined in a routing policy; the data-lifecycle module provides a cleanup mechanism to automatically delete expired review files and logs based on retention policies; and the token-accounting module adds a summarization use case to aggregate token usage and costs by model. These changes represent a structural shift to a modular architecture while introducing the foundational logic for model selection, platform interoperability, and automated data retention.

(repo-wide) · high confidence

Refactor Claude invocation logic into frameworks layer

The implementation of Claude CLI invocation and progress parsing has been moved from the src/claude directory to the frameworks layer (src/frameworks/claude). The files in this location now act as re-export shims to maintain backward compatibility during the migration, ensuring that existing imports continue to work while the core logic is consolidated in the new architecture.

src/claude · high confidence

Behavioural changes

Add strict schema validation for GitHub and GitLab platform events

This change introduces Zod-based validation guards for incoming webhook payloads from GitHub (Pull Request, Pull Request Review, and Issue Comment events) and GitLab (Merge Request and Note events). By enforcing strict schemas on these platform integration entities, the system now ensures that event data conforms to expected structures before processing, improving reliability and error handling for platform-specific workflows.

src/modules/platform-integration/entities/github · high confidence

CLI commands restructured into modular, dependency-injected files

The monolithic CLI entry point has been split into individual command modules (discover, followupImportants, init, logs, setup, start, status, stop, validate) located in src/main/commands. Each command now uses a dependency-injection pattern, accepting a dependencies object that abstracts system interactions (file I/O, process management, network calls, prompts). This change improves testability and maintainability by decoupling command logic from infrastructure concerns, while preserving the existing command-line interface and behavior for users.

src/main/commands · high confidence

Claude review execution engine and observability overhaul

The framework layer for Claude code review has been rebuilt to support background execution (--bg mode) with real-time progress tracking, token usage accounting, and cross-platform desktop notifications. The new \claudeInvoker.ts\ orchestrates the review lifecycle, delegating to use cases for model routing, diff stats, and token tracking, while \progressParser.ts\ parses stdout markers to emit live progress events. A new \auditScopeDirective.ts\ enforces project-specific review scopes, and \broadcastBudgetAfterUsage.ts\ integrates with the token accounting module to report budget status. Observability is enhanced via \logBuffer.ts\ for dashboard visibility and \desktopNotification.ts\ for macOS/Linux alerts. Legacy stream-json parsing is stubbed out in \streamJsonParser.ts\ as it is no longer used in the --bg path.

src/frameworks/claude · high confidence

Configurable per-project concurrency limits for review jobs

The queue framework now supports capping the number of parallel reviews allowed per project. A new \ProjectSemaphore\ component gates job entry into the main processing queue, enforcing a configurable concurrency limit (defaulting to 2) for each project path. This change allows administrators to control resource usage on a per-project basis, preventing any single project from monopolizing review capacity, while maintaining existing serialization logic for merge requests.

src/frameworks/queue · high confidence

Configuration loading migrated to new modular architecture

The configuration loading logic in src/config has been refactored to support the new Strangler Fig migration. The previous monolithic loader, which handled server, user, queue, and repository settings via a single config.json file, is now replaced by re-exports from the new modular location (@/frameworks/config/configLoader.js). Additionally, a new project-specific configuration system has been introduced via src/config/projectConfig.ts, allowing per-project settings (such as review focus, model routing, and concurrency caps) to be loaded from .claude/reviews/config.json with strict Zod-based validation. This change simplifies the global configuration structure while enabling more granular, project-level control over review behavior.

src/config · high confidence

Define least-privilege executor capabilities and role requirements

The platform integration now enforces a least-privilege model for CLI executors by introducing a capability system. A new \ExecutorCapability\ type defines four specific actions: reading merge requests, posting comments, resolving threads, and revoking tokens. These capabilities are mapped to minimum GitLab roles (\reporter\ or \developer\) and an \autoPath\ flag, allowing the system to automatically determine which permissions are granted by default versus those requiring explicit configuration.

src/modules/platform-integration/entities/executorToken · high confidence

Defined member access levels and gateway interface for trusted reviewer checks

Added the core domain types and interface for the member access module, establishing the access level hierarchy (from noAccess to owner) and a \MemberAccessGateway\ contract. The gateway is designed to resolve a GitLab actor's access level by username, with a fail-closed behavior where any lookup error, timeout, or unknown username resolves to \null\ (non-trusted). The \isDeveloperOrAbove\ helper implements the trust rule from SPEC-197, considering Developer level and above as trusted.

src/modules/platform-integration/entities/memberAccess · high confidence

Enforce monthly budget caps and validate limit updates

The token-accounting module now enforces monthly usage limits for Claude. A new EnforceBudget use case checks the current budget status against the monthly cap and determines whether requests are accepted or rejected based on whether the limit has been exceeded. Additionally, an UpdateBudget use case allows users to modify their monthly spending limit, but strictly validates that the new value falls within the defined floor and ceiling ranges before saving.

src/modules/token-accounting/usecases/enforceBudget, src/modules/token-accounting/usecases/updateBudget · high confidence

Enforce strict provenance validation and authenticated thread inventory access

The review execution module now enforces stricter security boundaries for LLM actions. A new provenance resolver ensures that only the exact canonical token 'trusted' is accepted, treating all other inputs (including casing variations or null values) as 'untrusted' to prevent privilege escalation. Additionally, an authenticated gateway has been introduced to provide page-by-page access to the merge request's thread inventory, requiring explicit project and merge request context for each fetch operation.

src/modules/review-execution/entities/actionProvenance, src/modules/review-execution/entities/threadInventory · high confidence

Idempotency store interface for deduplicating webhook events

A new IdempotencyStore interface has been introduced in the platform-integration module, defining a recordIfAbsent method to support deduplication of redelivered GitLab webhook events based on event UUIDs.

src/modules/platform-integration/entities/idempotency · medium confidence

Introduce quality gate enforcement and comment-based bypass logic

The tracking module now enforces a quality gate that blocks approval when the latest score falls below a defined threshold or when blocking issues are present, while also supporting a comment-based bypass mechanism (using the \/bypass-quality\ marker) to override this check under specific conditions. This change introduces the core entity definitions and evaluation logic for these quality controls within the tracking subsystem.

src/modules/tracking/entities · high confidence

Introduce self-update mechanism for source-checkout installations

The CLI now detects when it is installed from a source checkout (by looking for a .git directory) and, in that case, performs self-updates by running git pull and rebuilding via yarn, rather than attempting an npm global update. This prevents the previous false dashboard-update flow for source-checkout users. The change also includes gateways for fetching the latest npm version, caching version checks, reading/writing project config, listing repositories, and restarting the daemon after an update.

src/modules/cli-configuration/interface-adapters/gateways · high confidence

Introduce semi-automatic review execution with human confirmation

The review execution module now supports a semi-automatic trigger mode. Instead of always running immediately, review jobs can be parked in a pending state requiring human confirmation before execution. This is implemented through new use cases: \GateClaudeInvocation\ decides whether to auto-enqueue or park based on trigger mode and trusted reviewer status; \ConfirmPendingReview\ and \DismissPendingReview\ allow users to approve or reject parked requests; \ListPendingReviews\ exposes the queue for management. Additionally, \cancelReview\ allows cancelling in-flight jobs, \handleClose\ cleans up resources on request closure, and \handleReviewRequestPush\ manages follow-up reviews. The \executeReview\ use case orchestrates the actual AI review process, including context creation, progress tracking, and post-review actions.

src/modules/review-execution/usecases · high confidence

Introduce structured review context and action models with recovery support

The review execution module now defines explicit schemas and types for review contexts, actions, and results, replacing ad-hoc data handling with strict validation via Zod. Review contexts now support GitHub and GitLab platforms, track detailed progress phases (from initializing to completed), and include thread comments with author information. Review actions are discriminated unions supporting thread resolution, comment posting, replies, label addition, inline comments, and thread fetching. Results distinguish between measured reviews (with scores and verdicts like 'ready\_to\_merge' or 'needs\_fixes') and backfilled results for recovery scenarios, enabling the system to recover unposted reviews on restart.

src/modules/review-execution/entities/reviewContext · high confidence

Introduces self-update logic for source-checkout installations

The CLI now detects when it is installed via source checkout and applies a dedicated update flow, preventing the previous false dashboard update notifications. This change adds the entity definitions, validation schemas, and gateway interfaces required to check for updates, handle local-origin constraints, and manage the self-update sequence (including refusal motives like dirty checkouts or reviews in progress) specifically for non-NPM installations.

src/modules/cli-configuration/entities · high confidence

Introduces strict transport validation logic for webhook endpoints

A new use case, evaluateTransport, has been added to enforce security constraints on incoming transport requests. This logic rejects connections that do not originate from a trusted hop address, are not using HTTPS, or originate from an IP address not included in the allowed CIDR ranges, returning a 403 status for any violations.

src/modules/platform-integration/usecases/transport · high confidence

MCP server entry point replaces legacy HTTP server

The application's entry point has shifted from the previous HTTP-based server (src/server.ts) to a new Model Context Protocol (MCP) server (src/mcpServer.ts). The legacy server, which exposed endpoints for health checks, status, webhooks, and a dashboard, has been removed. The new entry point initializes the MCP server via stdio, logging environment variables and handling startup errors, indicating a move away from the web-based interface towards an MCP-driven interaction model.

src · high confidence

Migrate lint and formatting tooling to oxlint and oxfmt

The project has replaced its previous linting and formatting tools with oxlint and oxfmt. New configuration files (.oxlintrc.json and .oxfmtrc.json) define the rules, categories, and formatting preferences (such as import sorting and quote styles) for the new toolchain, and the .gitignore has been updated to exclude their respective output and cache directories.

(repo-wide) · high confidence

New pre-commit and pre-use hooks enforce architecture, safety, and workflow rules

The repository now includes a suite of shell scripts in scripts/hooks that act as automated gatekeepers for development workflows. These hooks enforce Clean Architecture dependency rules (preventing inner layers from importing outer ones), ensure gateway ports remain pure interfaces, require presenters to be classes, and forbid barrel exports. They also protect the main branch by blocking direct commits and pushes, require a valid spec file before feature implementation agents can run, and prevent commits if source code changes are staged without corresponding spec updates or tracker adjustments. A test runner and specific test suites are included to verify these hook behaviors.

scripts/hooks · high confidence

New transport security validation and client IP resolution

The platform integration module now enforces stricter transport security by validating client IP addresses against allowed CIDR ranges and rejecting requests that originate from untrusted sockets, use non-HTTPS protocols, or fall outside the configured allowlist. This change introduces a new transport context and decision model that returns specific rejection reasons (untrusted-socket, non-https, off-allowlist) with a 403 status. It also adds a gateway for resolving client IPs from the Forwarded-For header, ensuring that only trusted hops are used to determine the actual client address.

src/modules/platform-integration/entities/transport, src/modules/platform-integration/interface-adapters/gateways/transport · high confidence

Persistent file-based storage for job history, project principles, and review files

The review execution module now persists operational data to the local file system instead of relying on in-memory or external storage. Job history is stored as date-partitioned JSONL files in the user's home directory (\~/.claude-review/jobs), with automatic retention pruning based on a configurable number of days. Project principles are read directly from the local project structure, specifically the CLAUDE.md file and the .claude/skills directory. Review artifacts are managed as Markdown files within the project's .claude/reviews directory, supporting listing, reading, and deletion of past reviews.

src/modules/review-execution/interface-adapters/gateways/fileSystem · high confidence

Project configuration now supports concurrency caps and quality thresholds

Users can now configure per-project concurrency limits and quality thresholds via the CLI. The system introduces a new use case to recompute global concurrency based on individual project caps, ensuring the total parallel review capacity is calculated correctly. Additionally, project settings can be updated to include a quality threshold (0-10) and a maximum concurrent reviews cap, with validation enforcing these constraints and whitelisting only specific editable fields like language, model, and skills.

src/modules/cli-configuration/usecases/projectConfig · high confidence

Refactored Claude invocation into modular use cases with improved billing and review handling

The \src/modules/claude-invocation/usecases\ directory has been restructured into distinct, single-responsibility use cases (\auditBilling\, \awaitSessionCompletion\, \checkSupervisorHealth\, \cleanupClaudeSession\, \dispatchClaudeSession\, \retrieveReviewReport\, \runClaudeReviewJob\). This refactoring introduces a more robust billing safeguard that prevents dispatch when an explicit \ANTHROPIC\_API\_KEY\ is detected, replacing a previous heuristic-based check that caused false positives. It also adds a fallback mechanism for retrieving review reports, allowing the system to look in the worktree root if the primary path is missing, which prevents failures on follow-up jobs. Additionally, the session dispatch and completion logic now supports background modes with proper token usage tracking and retry scheduling for rate limits.

src/modules/claude-invocation/usecases · high confidence

Reloadable GitLab webhook token verification and transport guard configuration

The security module now supports runtime rotation of the GitLab webhook secret without requiring a process restart, as the token is read fresh from the environment on every verification call. To prevent timing-based side-channel attacks during this comparison, the verification logic now hashes both the candidate and expected tokens with a random per-process key before performing a constant-time comparison. Additionally, a new transport guard configuration has been introduced to strictly define the trusted reverse-proxy hop (defaulting to loopback) and allowed CIDR ranges, ensuring that request attributes are not inflated by client-supplied headers. The verifier also now extracts the GitLab event UUID from request headers to support event deduplication.

src/security · high confidence

Review execution services: action dispatch, recovery, and reporting

The review-execution module now includes a suite of services that govern how LLM-generated review actions are processed and applied. A new constrained dispatch pipeline (dispatchConstrainedActions, constrainActionSurface, resolveThreadInventory) ensures that write actions like THREAD\_RESOLVE and THREAD\_REPLY are only executed against an authenticated thread inventory and are bounded by provenance, while public-output actions (POST\_COMMENT, THREAD\_REPLY) are routed through a scanned post sink. Context-based execution (contextActionsExecutor) re-admits dropped THREAD\_RESOLVE actions when they match the authenticated inventory, and execution failures are now explicitly logged via actionExecutionReport. Additionally, a recovery service (reviewRecovery.service) replays unposted review actions after application restarts within a grace window, and a context watcher (reviewContextWatcher.service) polls for progress updates. Agent instructions are now built and formatted via agentInstructionsBuilder, and comment links are enriched with platform-specific blob URLs via commentLinkEnricher.

src/modules/review-execution/services · high confidence

Safe diff stats fetching with error handling

The statistics insights module now includes a new service function that safely fetches diff statistics by wrapping the underlying gateway call in a try-catch block. If the fetch operation fails, the system logs a warning with relevant context (project path, merge request number, and error details) and returns null instead of crashing, ensuring more robust behavior when retrieving repository statistics.

src/modules/statistics-insights/services · high confidence

Scoped GitLab executor with isolated environment and provenance-validated thread fetching

The platform integration now runs GitLab CLI operations in an isolated, least-privilege environment. A new scoped executor environment creates dedicated HOME and GLAB\_CONFIG\_DIR directories, writes a config file containing only the specific executor token, and restricts inherited environment variables to a strict allowlist (PATH, HOME, GLAB\_CONFIG\_DIR, LANG), preventing credential leakage. To ensure thread-fetching actions are driven by server-validated sources rather than forgeable webhook payloads, a new pinned thread fetch target mechanism validates that the requested merge request number matches the trusted upstream gate before allowing thread retrieval. Additionally, an auto-executor action filter restricts automated operations to a specific set of safe capabilities (readMr, postComment), dropping any actions that require higher privileges.

src/modules/platform-integration/services · high confidence

Self-update logic now distinguishes source-checkout installs to prevent false update prompts

The version-checking and self-update workflows have been refactored to detect whether the CLI is installed via a source checkout. The new \checkVersion\ usecase includes the installation type in its result, and \triggerSelfUpdate\ routes source-checkout users to a dedicated self-update flow (fetching and rebuilding from the repository) instead of attempting a global npm update. This prevents the dashboard from incorrectly suggesting updates for users running directly from source.

src/modules/cli-configuration/usecases/version · high confidence

Simplified launcher and replaced custom scripts with asset copying

The project's operational scripts have been restructured: the previous launcher.sh has been simplified to start the server using Yarn and open the dashboard, removing the automatic Cloudflare tunnel setup and system notifications. The status.sh and stop.sh scripts have been removed entirely. A new copyAssets.mjs script has been added to handle copying dashboard assets and the animejs library from node\_modules to the distribution directory.

scripts · high confidence

Webhook controller refactoring with diff-size guards and transport security

The webhook controllers for GitHub and GitLab have been restructured to introduce stricter safety and security controls. A new diff-size guard helper now blocks reviews on oversized merge requests by revoking approvals or posting comments, preventing resource exhaustion. Additionally, a transport guard middleware validates incoming webhook traffic against trusted IP ranges and CIDR blocks, rejecting unauthorized requests. The controllers also implement event filtering to deduplicate GitLab webhook events by UUID and gate auto-run triggers on trusted reviewer membership, ensuring that only verified actors can initiate automated review processes.

src/modules/platform-integration/interface-adapters/controllers · high confidence

Test coverage

Added acceptance tests for core review and worktree features; Added architecture tests to enforce \claude -p\ deprecation and legacy parser isolation; Added integration tests for server endpoints and Claude invocation workflow; Added test factories for domain entities and platform events; Added test stubs for setup-wizard gateway interfaces; Added unit and integration tests for CLI argument parsing, startup banner, and init summary formatting; Added unit tests for BackfillProgress entity; Added unit tests for Claude framework integration components; Added unit tests for Claude invocation interface adapters and entities; Added unit tests for Claude invocation timers; Added unit tests for Claude invocation use cases; Added unit tests for DiffStats entity; Added unit tests for Duration, ReviewRequestState, and ReviewScore value objects; Added unit tests for GitHub and GitLab CLI review gateways; Added unit tests for GitHub and GitLab pull/merge request event guards; Added unit tests for GitHub and GitLab review processor provenance validation; Added unit tests for GitLab executor and member access gateways; Added unit tests for HTTP controller routes; Added unit tests for MCP controller handlers; Added unit tests for MCP server infrastructure and context loading; Added unit tests for MCP settings validation and parsing; Added unit tests for PlatformAdapter event translation; Added unit tests for ReviewAction guard logic; Added unit tests for config validation and Git URL normalization; Added unit tests for dashboard layout, loading race conditions, and inline handler exports; Added unit tests for diff size gate and trigger mode schema; Added unit tests for gateway interface adapters; Added unit tests for insight entity schemas and guards; Added unit tests for job history use cases; Added unit tests for main CLI commands and core services; Added unit tests for model routing, token usage tracking, and summarization; Added unit tests for package version validation and update result types; Added unit tests for platform integration entity guards and utilities; Added unit tests for platform-integration executor services; Added unit tests for project configuration loading and validation; Added unit tests for project stats schema validation and review duration formatting; Added unit tests for queue concurrency and project semaphore logic; Added unit tests for review context schemas and result handling; Added unit tests for review execution HTTP controllers and presenters; Added unit tests for review file retention policy and cleanup use case; Added unit tests for review job and package version factories; Added unit tests for review stats accumulation logic; Added unit tests for review-execution entity guards and type definitions; Added unit tests for review-execution file-system and GitLab gateways; Added unit tests for review-execution service constraints and dispatch logic; Added unit tests for review-execution services; Added unit tests for runtime settings persistence and configuration; Added unit tests for scheduler components; Added unit tests for self-update sequence validation logic; Added unit tests for setup wizard entities, gateways, and HTTP routes; Added unit tests for shared foundation types; Added unit tests for statistics use cases; Added unit tests for supervisor management lifecycle and gateways; Added unit tests for the AI insights engine and persistence layer; Added unit tests for the Claude progress parser; Added unit tests for the Ember Chat module; Added unit tests for the Language schema validation; Added unit tests for the egress scanner entity; Added unit tests for token accounting budget and pricing logic; Added unit tests for token accounting budget use cases; Added unit tests for tracking entity logic; Added unit tests for transcript stream JSON parsing logic; Added unit tests for transport security validation; Added unit tests for version and self-update stubs; Added unit tests for version check and self-update use cases; Added unit tests for webhook controller helpers and reply logic; Added unit tests for webhook controller logic and event filtering; Added unit tests for webhook security verification and transport guards; Added unit tests for worktree management entities and schemas; Added unit tests for worktree management services; Unit tests added for CLI configuration and daemon management use cases; Unit tests added for review execution use cases; Unit tests added for the setup wizard CLI and its steps.

Dependencies

Package manager migration to Yarn and dependency overhaul

The project has switched from npm to Yarn as its package manager, replacing the deleted package-lock.json with a new yarn.lock file and pinning the Yarn version via corepack. This change accompanies a significant dependency update, including an upgrade to Fastify v5, the addition of the Hono server adapter, and the introduction of new tooling for linting (oxlint), formatting (oxfmt), testing (Vitest), and documentation (VitePress).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 63 → 69 (+5.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 86 (-7.6)
  • Architecture 99 → 79 (-20.0)
  • Maturity 74 → 83 (+9.7)
  • Readiness 54 → 63 (+8.6)
  • Security 65 → 77 (+11.9)
  • Accessibility 65 → 69 (+4.1)

Resolved (31)

  • Boundary-crossing change coupling: github.controller.ts ↔ mrTrackingAdvanced.routes.ts (src/modules/platform-integration/interface-adapters/controllers/webhook/github.controller.ts)
  • Boundary-crossing change coupling: github.controller.ts ↔ reviewContext.fileSystem.gateway.ts (src/modules/platform-integration/interface-adapters/controllers/webhook/github.controller.ts)
  • Boundary-crossing change coupling: gitlab.controller.ts ↔ mrTrackingAdvanced.routes.ts (src/modules/platform-integration/interface-adapters/controllers/webhook/gitlab.controller.ts)
  • Boundary-crossing change coupling: projectConfig.ts ↔ gitlab.controller.ts (src/config/projectConfig.ts)
  • Change coupling: contextActionsExecutor.ts ↔ threadActionsExecutor.ts (src/modules/review-execution/services/contextActionsExecutor.ts)
  • Change coupling: eventFilter.ts ↔ github.controller.ts (src/modules/platform-integration/interface-adapters/controllers/webhook/eventFilter.ts)
  • Change coupling: eventFilter.ts ↔ gitlab.controller.ts (src/modules/platform-integration/interface-adapters/controllers/webhook/eventFilter.ts)
  • Change coupling: github.controller.ts ↔ gitlab.controller.ts (src/modules/platform-integration/interface-adapters/controllers/webhook/github.controller.ts)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 11 more

New (123)

  • AddProjectStep.execute (cognitive 16) (src/modules/setup-wizard/usecases/steps/addProject.step.ts)
  • AiInsightsSessionClaudeGateway.readAnswer (cognitive 22) (src/modules/statistics-insights/interface-adapters/gateways/aiInsightsSession.claude.gateway.ts)
  • Change coupling clique: eventFilter.ts, github.controller.ts, gitlab.controller.ts (src/modules/platform-integration/interface-adapters/controllers/webhook/eventFilter.ts)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Documentation: written for insiders (docs/index.md)
  • FileTooLong: main/routes.ts (src/main/routes.ts)
  • FunctionTooLong: claudeInvoker.invokeViaBackgroundSession (src/frameworks/claude/claudeInvoker.ts)
  • FunctionTooLong: cliStatus.routes.cliStatusRoutes (src/modules/cli-configuration/interface-adapters/controllers/http/cliStatus.routes.ts)
  • FunctionTooLong: github.controller.handleGitHubPullRequestReviewHook (src/modules/platform-integration/interface-adapters/controllers/webhook/github.controller.ts)
  • FunctionTooLong: github.controller.handleGitHubWebhook (src/modules/platform-integration/interface-adapters/controllers/webhook/github.controller.ts)
  • FunctionTooLong: gitlab.controller.handleGitLabWebhook (src/modules/platform-integration/interface-adapters/controllers/webhook/gitlab.controller.ts)
  • FunctionTooLong: insightsReport.getReportStyles (src/dashboard/modules/insightsReport.js)
  • FunctionTooLong: mrSheet.drawScoreTimeline (src/dashboard/modules/mrSheet.js)
  • FunctionTooLong: mrSheet.renderMrSheetContent (src/dashboard/modules/mrSheet.js)
  • FunctionTooLong: mrTrackingAdvanced.routes.mrTrackingAdvancedRoutes (src/modules/tracking/interface-adapters/controllers/http/mrTrackingAdvanced.routes.ts)
  • FunctionTooLong: projectConfig.routes.projectConfigRoutes (src/modules/cli-configuration/interface-adapters/controllers/http/projectConfig.routes.ts)
  • FunctionTooLong: routes.registerRoutes (src/main/routes.ts)
  • FunctionTooLong: server.startServer (src/main/server.ts)
  • FunctionTooLong: statsCharts.drawScoreTrendChart (src/dashboard/modules/statsCharts.js)
  • …and 103 more

Changes since last survey

  • 12 commits — 11 feature/other, 1 fixes

By area

  • (root) — 7 commits
  • src/tests — 5 commits

Notable commits

  • fix: fix: keep the daemon alive and stop requiring unused platform CLIs (#385)
  • change: chore(deps): bump fast-uri from 3.1.4 to 3.1.5 (#377)
  • change: chore(master): release reviewflow 3.49.0 (#374)
  • change: chore(master): release reviewflow 3.50.0 (#379)
  • change: chore(master): release reviewflow 3.51.0 (#381)
  • change: chore(master): release reviewflow 3.51.1 (#387)
  • change: chore(master): release reviewflow 3.52.0 (#388)
  • change: chore(master): release reviewflow 3.53.0 (#390)
  • change: feat(review): implement spec-224 follow-up review labels (#380)
  • change: feat(review): signal review state with platform labels (spec-221, spec-222) (#373)
  • change: feat(threads): carry author replies in the context (#382)
  • change: feat(version): implement spec-223 source-checkout self-update (#378)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

DGouron/review-flow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a89a6e661dc953be961ab909f2c392be5dae4851 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.