{"_id":"@detiq/ai-pr-reviewer","_rev":"2-836c6f567fed344169811077dfa73c3e","name":"@detiq/ai-pr-reviewer","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.2":{"name":"@detiq/ai-pr-reviewer","version":"1.0.2","keywords":["ai","code-review","pr-review","llm","github-actions","prompts","templates","guidelines"],"author":{"name":"Detiq"},"license":"MIT","_id":"@detiq/ai-pr-reviewer@1.0.2","maintainers":[{"name":"tucnow","email":"tucnowsolutions@gmail.com"}],"homepage":"https://github.com/deepanimators/ai-pr-reviewer-workflows#readme","bugs":{"url":"https://github.com/deepanimators/ai-pr-reviewer-workflows/issues"},"dist":{"shasum":"522d8f611f85aceef5d46117b21163b51e1e9441","tarball":"https://registry.npmjs.org/@detiq/ai-pr-reviewer/-/ai-pr-reviewer-1.0.2.tgz","fileCount":22,"integrity":"sha512-qvmCLfxqEGafee4jlrogZwic59eKE9/Jo+n0je2L1iSkRfELjolmfV0MX0NJAzeqyn+a5rOgRlL3d0R62eYvMg==","signatures":[{"sig":"MEUCIDRCoQk1qJBs82OzQV7+MgC7GdSjNWbb2ZcJ0gexcSF3AiEAq3nC4NCAXMERwCxkgs4FWX1re0mNYx/+bljUxOMKS/8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":183899},"main":"index.ts","type":"module","engines":{"bun":">=1.0.0"},"exports":{".":{"types":"./index.ts","import":"./index.ts"},"./lib/*":"./lib/*","./prompts/*":"./prompts/*","./scripts/*":"./scripts/*"},"gitHead":"52b10067e1b075bd0320266489edc376369e58c7","scripts":{"dev":"bun run type-check:watch","lint":"tsc --noEmit && echo 'TypeScript check passed'","clean":"rm -rf node_modules/.cache/","lint:fix":"echo 'No auto-fix available, check TypeScript errors manually'","validate":"bun lib/validate.ts","type-check":"tsc --noEmit","prepublishOnly":"bun run clean && bun run type-check","validate:strict":"bun lib/validate.ts --strict","type-check:watch":"tsc --noEmit --watch"},"_npmUser":{"name":"tucnow","email":"tucnowsolutions@gmail.com"},"repository":{"url":"git+https://github.com/deepanimators/ai-pr-reviewer-workflows.git","type":"git"},"_npmVersion":"10.9.2","description":"Prompt templates and guidelines for AI-powered PR reviews using Auggie CLI","directories":{},"_nodeVersion":"23.10.0","dependencies":{"zod":"^4.1.12","@octokit/rest":"^22.0.0","@aws-sdk/client-s3":"^3.937.0"},"publishConfig":{"access":"restricted"},"_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.1","typescript":"^5.9.3","@types/node":"^24.9.1"},"_npmOperationalInternal":{"tmp":"tmp/ai-pr-reviewer_1.0.2_1786424575115_0.961636690279841","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@detiq/ai-pr-reviewer","version":"1.0.3","description":"Prompt templates and guidelines for AI-powered PR reviews using Auggie CLI","main":"index.ts","type":"module","exports":{".":{"import":"./index.ts","types":"./index.ts"},"./prompts/*":"./prompts/*","./lib/*":"./lib/*","./scripts/*":"./scripts/*"},"scripts":{"type-check":"tsc --noEmit","type-check:watch":"tsc --noEmit --watch","lint":"tsc --noEmit && echo 'TypeScript check passed'","lint:fix":"echo 'No auto-fix available, check TypeScript errors manually'","clean":"rm -rf node_modules/.cache/","dev":"bun run type-check:watch","prepublishOnly":"bun run clean && bun run type-check","validate":"bun lib/validate.ts","validate:strict":"bun lib/validate.ts --strict"},"publishConfig":{"access":"restricted"},"keywords":["ai","code-review","pr-review","llm","github-actions","prompts","templates","guidelines"],"author":{"name":"Detiq"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/deepanimators/ai-pr-reviewer-workflows.git"},"homepage":"https://github.com/deepanimators/ai-pr-reviewer-workflows#readme","engines":{"bun":">=1.0.0"},"devDependencies":{"@types/node":"^24.9.1","bun-types":"^1.3.1","typescript":"^5.9.3"},"dependencies":{"@aws-sdk/client-s3":"^3.937.0","@octokit/rest":"^22.0.0","zod":"^4.1.12"},"_id":"@detiq/ai-pr-reviewer@1.0.3","gitHead":"2761446ab8b9e494663f2cc374209981fbe1fd19","bugs":{"url":"https://github.com/deepanimators/ai-pr-reviewer-workflows/issues"},"_nodeVersion":"23.10.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-0hfW0G+UTsJsXdQo8C2yGgsFwTlp50z22y1Mzji1WsKC6ZsIeGKp6cxBPV74iykSdrYb9Xwwhm+fyBj6Oi7jKA==","shasum":"87ba76b40bc22d13df96f5c08841e3a632bc8ddd","tarball":"https://registry.npmjs.org/@detiq/ai-pr-reviewer/-/ai-pr-reviewer-1.0.3.tgz","fileCount":22,"unpackedSize":183899,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHZ4060ahXG02DqYgDOifiePNyGvRkgihCQAgJBK+nGfAiAm4NWqJFvbDt8odLFczwi+12vxqn45UXw+CzPQhLxrZA=="}]},"_npmUser":{"name":"tucnow","email":"tucnowsolutions@gmail.com"},"directories":{},"maintainers":[{"name":"tucnow","email":"tucnowsolutions@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ai-pr-reviewer_1.0.3_1786598239352_0.1767237865517297"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-11T05:02:54.913Z","modified":"2026-08-13T05:17:19.663Z","1.0.2":"2026-08-11T05:02:55.263Z","1.0.3":"2026-08-13T05:17:19.494Z"},"bugs":{"url":"https://github.com/deepanimators/ai-pr-reviewer-workflows/issues"},"author":{"name":"Detiq"},"license":"MIT","homepage":"https://github.com/deepanimators/ai-pr-reviewer-workflows#readme","keywords":["ai","code-review","pr-review","llm","github-actions","prompts","templates","guidelines"],"repository":{"type":"git","url":"git+https://github.com/deepanimators/ai-pr-reviewer-workflows.git"},"description":"Prompt templates and guidelines for AI-powered PR reviews using Auggie CLI","maintainers":[{"name":"tucnow","email":"tucnowsolutions@gmail.com"}],"readme":"# AI PR Reviewer\n\nA reusable GitHub Action that provides automated code reviews using the Codex CLI tool. This action can be easily integrated into any repository to get AI-powered code reviews when a specific label is added to pull requests.\n\n## Quick Start\n\n### 1. Create a Workflow in Your Repository\n\nCreate `.github/workflows/ai-pr-review.yml` in your repository:\n\n```yaml\nname: AI PR Review\n\non:\n  pull_request:\n    types: [labeled]\n\njobs:\n  ai-review:\n    if: contains(github.event.label.name, 'AI Reviewer')\n    uses: detiq/ai-pr-reviewer-workflows/.github/workflows/pr-reviewer.yml@main\n    secrets:\n      GITHUB_TOKEN_REMOTE: ${{ secrets.GITHUB_TOKEN }}\n      CLI_TOOL_API_TOKEN: ${{ secrets.CODEX_API_KEY }}\n      NPM_TOKEN: ${{ secrets.NPM_TOKEN }}\n```\n\nThe `CODEX_API_KEY` secret is alreaady available as an organization secret, so no need to add it to individual repositories.\n\n### 2. Add the Label\n\nCreate a label called \"AI Reviewer\" in your repository, or use the default label name.\n\n### 3. Trigger a Review\n\nAdd the \"AI Reviewer\" label to any pull request to trigger an automated review!\n\n## Configuration Options\n\nThe action supports several input parameters for customization:\n\n```yaml\njobs:\n  ai-review:\n    uses: detiq/ai-pr-reviewer-workflows/.github/workflows/pr-reviewer.yml@main\n    with:\n      trigger_label: \"AI Reviewer\" # Label that triggers review\n      guidelines_path: \".github/pr-review-guidelines.md\" # Deprecated; ignored for security\n      package_version: \"latest\" # reviewer package version, not the Codex CLI version\n      cli_version: \"0.144.1\" # Codex CLI pin for MCP compatibility\n      post_as_review: true # Post as PR review vs comment\n      max_files: 50 # Max files to review (0 = no limit)\n    secrets:\n      GITHUB_TOKEN_REMOTE: ${{ secrets.GITHUB_TOKEN }}\n      CLI_TOOL_API_TOKEN: ${{ secrets.CODEX_API_KEY }}\n      NPM_TOKEN: ${{ secrets.NPM_TOKEN }}\n```\n\n### Input Parameters\n\n| Parameter             | Description                                         | Default                             | Required |\n| --------------------- | --------------------------------------------------- | ----------------------------------- | -------- |\n| `trigger_label`       | Label that triggers the AI review                   | `'AI Reviewer'`                     | No       |\n| `guidelines_path`     | Deprecated; accepted but ignored                    | `''`                                | No       |\n| `guidelines_paths`    | Deprecated; accepted but ignored                    | `''`                                | No       |\n| `guidelines_template` | Built-in guidelines template to use                 | `'default'`                         | No       |\n| `package_version`     | Version of the reviewer package to use              | `'latest'`                          | No       |\n| `cli_version`         | Codex CLI version to install; `@openai/codex@latest` is forced to the MCP-compatible pin | `'0.144.1'` | No |\n| `post_as_review`      | Post results as PR review (true) or comment (false) | `true`                              | No       |\n| `max_files`           | Maximum number of files to review (0 for no limit)  | `50`                                | No       |\n| `min_severity`        | Minimum severity level for comments to be posted    | `'medium'`                          | No       |\n| `model`               | AI model to use for the review                      |         | No       |\n| `enable_ai_labels`    | Enable AI Approved/Rejected labels on PRs           | `true`                              | No       |\n\n### Code Review Graph Integration (Codex)\n\nWhen `cli_command` is set to `codex`, the reusable workflow automatically sets up [`code-review-graph`](https://github.com/tirth8205/code-review-graph):\n\n- Installs Python 3.11 and `code-review-graph` from `https://github.com/tirth8205/code-review-graph`\n- Registers a `code-review-graph` MCP server with Codex (`code-review-graph serve`)\n- Builds the initial graph for the checked-out repository (`code-review-graph build`)\n\nThis makes graph-based impact analysis tools available during the PR review run.\n\nThe reviewer uses the checked-out repository, `pr_review_context.md`, `pr_diff.patch`, `changed_files.txt`, and the `BASE_SHA`/`HEAD_SHA` diff range as the primary source for changed code. GitHub MCP is configured when Codex is used, but it is supplemental metadata; the review prompt tells Codex to continue from local git context if MCP or network access is unavailable.\n\n### Required Secrets\n\n| Secret                | Description                           | Required |\n| --------------------- | ------------------------------------- | -------- |\n| `GITHUB_TOKEN_REMOTE` | GitHub token for API access           | Yes      |\n| `CLI_TOOL_API_TOKEN`  | Codex API key for CLI authentication | Yes      |\n\n## Custom Review Guidelines\n\n`guidelines_path` and `guidelines_paths` are still accepted so existing caller workflows do not need to change, but they are ignored. Review instructions are loaded only from the centrally maintained prompt and guideline templates in this package.\n\n## Built-in Guidelines Templates\n\nThe AI PR Reviewer now includes specialized prompt templates for different types of reviews. You can use these templates by setting the `guidelines_template` parameter:\n\n### Available Templates\n\n- **`default`** - General-purpose review guidelines covering code quality, security, and maintainability\n- **`security-focused`** - Emphasizes security vulnerabilities, authentication, and data protection\n- **`performance-focused`** - Focuses on performance optimization, scalability, and efficiency\n- **`frontend-focused`** - Specialized for frontend development (React, Vue, Angular, accessibility)\n- **`backend-focused`** - Specialized for backend development (APIs, databases, architecture)\n\n### Template Priority\n\nThe action uses guidelines in this priority order:\n\n1. Built-in package template selected by `guidelines_template`\n2. Built-in fallback guidelines\n\n### Comment Types and Severity Filtering\n\nThe AI will post different types of comments with severity levels:\n\n- **🚨 Critical Issues**: Security vulnerabilities, bugs, breaking changes (posted on specific lines)\n- **⚠️ High Priority**: Performance issues, major code quality concerns (posted on specific lines)\n- **💡 Medium Priority**: Code improvements, maintainability suggestions (posted on specific lines)\n- **📝 Low Priority**: Style suggestions, minor optimizations (posted on specific lines)\n- **💬 General Comments**: Architecture feedback, overall patterns (posted in summary review)\n\n#### Filtering Comments by Severity\n\nYou can control which comments are posted by setting the `min_severity` parameter. Only comments at or above the specified severity level will be posted:\n\n```yaml\njobs:\n  ai-review:\n    uses: detiq/ai-pr-reviewer-workflows/.github/workflows/pr-reviewer.yml@main\n    with:\n      min_severity: \"high\" # Only post critical and high severity comments\n    secrets:\n      GITHUB_TOKEN_REMOTE: ${{ secrets.GITHUB_TOKEN }}\n      CLI_TOOL_API_TOKEN: ${{ secrets.CODEX_API_KEY }}\n      NPM_TOKEN: ${{ secrets.NPM_TOKEN }}\n```\n\n**Available severity levels** (from highest to lowest):\n\n- `critical` - Only critical issues\n- `high` - Critical and high priority issues\n- `medium` - Critical, high, and medium priority issues (default)\n- `low` - All comments including low priority suggestions\n\n### AI Approval/Rejection Labels\n\nThe AI reviewer can automatically add labels to PRs based on its decision:\n\n- **✅ AI Approved** - The AI has reviewed the PR and found no significant issues\n- **❌ AI Rejected** - The AI has identified issues that should be addressed\n\nThis feature is **enabled by default**. To disable it, set `enable_ai_labels: false`:\n\n```yaml\njobs:\n  ai-review:\n    uses: detiq/ai-pr-reviewer-workflows/.github/workflows/pr-reviewer.yml@main\n    with:\n      enable_ai_labels: false # Disable AI approval/rejection labels\n    secrets:\n      GITHUB_TOKEN_REMOTE: ${{ secrets.GITHUB_TOKEN }}\n      CLI_TOOL_API_TOKEN: ${{ secrets.CODEX_API_KEY }}\n      NPM_TOKEN: ${{ secrets.NPM_TOKEN }}\n```\n\n**Note**: The AI decision is based on the overall review and the severity of issues found. The labels are mutually exclusive - only one will be applied at a time.\n\n## Deploying Changes\n\nThis package is published to npm as `@detiq/ai-pr-reviewer`. Publishing is done manually after merging to `main`.\n\n### Deployment Steps\n\n1. Make your changes in a feature branch\n2. **Update the version** in `package.json` — this is the only file that needs a version bump:\n   - `1.0.x` — bug fixes, minor prompt tweaks\n   - `1.x.0` — new features, non-breaking changes\n   - `x.0.0` — breaking changes\n3. Run `bun run type-check` to catch any TypeScript errors\n4. Open a PR, get it reviewed, and merge to `main`\n5. Publish the package: `npm publish`\n\n### Testing Changes Before Merging\n\nTo test or debug changes before merging to `main`:\n\n1. Set a pre-release version in `package.json`, e.g. `\"version\": \"1.0.5-beta.1\"`\n2. Publish the package manually: `npm publish --tag beta`\n3. In the consuming repo's workflow file, point to your branch and the beta version:\n   ```yaml\n   uses: detiq/ai-pr-reviewer-workflows/.github/workflows/pr-reviewer.yml@your-branch-name\n   with:\n     package_version: \"1.0.5-beta.1\"\n   ```\n4. Trigger a review on a PR in the consuming repo to debug your changes\n\nOnce done, revert the workflow reference back to `@main` before merging.\n\n## Contributing\n\nContributions are welcome! Please feel free to submit issues, feature requests, or pull requests.\n\n## Examples\n\n### Basic Setup\n\nThe simplest way to get started:\n\n```yaml\n# .github/workflows/ai-pr-review.yml\nname: AI PR Review\n\non:\n  pull_request:\n    types: [labeled]\n\njobs:\n  ai-review:\n    if: contains(github.event.label.name, 'AI Reviewer')\n    uses: detiq/ai-pr-reviewer-workflows/.github/workflows/pr-reviewer.yml@main\n    secrets:\n      GITHUB_TOKEN_REMOTE: ${{ secrets.GITHUB_TOKEN }}\n      CLI_TOOL_API_TOKEN: ${{ secrets.CODEX_API_KEY}}\n      NPM_TOKEN: ${{ secrets.NPM_TOKEN }}\n```\n\n## How It Works\n\n1. **Label Detection**: When a PR is labeled with the trigger label, the workflow activates\n2. **Repository Checkout**: The action checks out your repository\n3. **Package Installation**: Installs the `@detiq/ai-pr-reviewer` NPM package containing prompt templates\n4. **Guidelines Resolution**: Loads centrally maintained package templates, then falls back to defaults\n5. **LLM CLI Setup**: Installs and configures the selected models' CLI tool\n6. **PR Analysis**: Analyzes the PR changes using the specified guidelines\n7. **Results Posting**: Posts the review as either a PR review or comment\n\n## NPM Package\n\nThe prompt templates are distributed as an NPM package: `@detiq/ai-pr-reviewer`\n\n### Package Versioning\n\nThe package is automatically published when:\n\n- Changes are made to the `prompts/` directory\n- A new release is created\n- Manual workflow dispatch is triggered\n\nThis ensures that all consuming repositories get the latest prompt improvements automatically.\n\n### Testing Different Package Versions\n\nYou can test different versions of the package using the `package_version` parameter:\n\n```yaml\n# Test with latest published version (default)\nwith:\n  package_version: \"latest\"\n\n# Test with specific stable version\nwith:\n  package_version: \"1.0.2\"\n\n# Test with beta/pre-release version\nwith:\n  package_version: \"beta\"\n```\n","readmeFilename":"README.md"}