Agent-PR Reviewer — deterministic + AI-pattern review for pull requests.
Project description
Agent-PR Reviewer (apr)
Deterministic + AI-pattern review for pull requests. Wave 2 lead bet of the DevTrust connected platform.
Status
v0.2.0 beta — deterministic Python + JS/TS rules, deterministic AI-pattern checker (ai-review:hallucinated-symbol) now multi-language via Repo X-ray v0.4 call edges, plus optional LLM-backed ai-review:diff-comprehension (Anthropic).
Why
Three of your existing GitHub Apps — ai-quality-gate, pr-coach, commit-craft — each solve part of "make PR review better" but ship as separate apps with separate auth, separate webhooks, separate UIs. apr consolidates them into one engine so:
- One install. One webhook. One sticky comment per PR.
- Deterministic rules first (testable, gradeable, cheap), LLM layer second.
- Reuses Repo X-ray's architecture model for file context.
Rules shipped through v0.0.2
Python (.py)
| Rule ID | Severity | Category | What it catches |
|---|---|---|---|
bare-except |
warning | quality | except: without an exception class |
print-debug |
info | quality | leftover print(...) calls (skipped in __main__ guard files) |
todo-no-ticket |
info | todo | TODO/FIXME/XXX/HACK without #123 / PROJ-123 reference |
empty-function-body |
info | ai-pattern | function body is only pass |
syntax-error |
error | quality | file does not parse |
mutable-default-arg |
warning | quality | def f(x=[]) shares state across calls |
broad-except |
info | quality | except Exception: is broader than most code needs |
assert-in-prod |
warning | security | assert is stripped under python -O. Test files exempt. |
hardcoded-secret |
critical | security | AWS / GitHub / OpenAI / Anthropic / Slack tokens, inline credential literals |
JavaScript / TypeScript (.js .jsx .mjs .cjs .ts .tsx) — v0.0.2+
| Rule ID | Severity | Category | What it catches |
|---|---|---|---|
console-log |
info | quality | leftover console.log/debug/info. Skipped in entry files (process.argv, .listen(, import.meta.main). |
debugger-statement |
warning | quality | debugger; left in code |
var-declaration |
info | style | var instead of let/const |
todo-no-ticket |
info | todo | mirror of the Python rule |
PR-level
| Rule ID | Severity | Category | What it catches |
|---|---|---|---|
pr-title-uninformative |
warning | commit | PR title too short or one of wip/draft/tmp/test |
pr-description-too-short |
info | commit | PR description under 30 characters |
AI-pattern (opt-in via --enable-ai) — v0.1.0+ / v0.2.0 multi-language
| Rule ID | Severity | Category | What it catches |
|---|---|---|---|
ai-review:hallucinated-symbol |
warning | ai-pattern | A function call whose name doesn't resolve to an in-repo symbol, an imported alias, or a known stdlib / global / popular package root. Now spans Python + JS/TS as of v0.2.0. Requires .repox/architecture.json (run repox first). |
ai-review:diff-comprehension |
warning/info | ai-pattern | LLM-backed check for "does the PR description accurately describe the diff?". Pass --ai-provider anthropic and set ANTHROPIC_API_KEY. |
CLI
apr version
apr review --repo .
apr review --repo . --changed src/foo.py --changed src/bar.py
apr review --repo . --title "Fix nullable fields" --description "..."
Output: .apr/review.json (schema-versioned, machine-readable) + .apr/review.md (human companion).
Roadmap
- ✅ v0.0.2 — JS/TS rule pack (
console-log,debugger-statement,var-declaration,todo-no-ticket). - ✅ v0.1.0 — AI rule pack: deterministic
ai-review:hallucinated-symbol+ LLM-pluggableai-review:diff-comprehension. - ✅ v0.1.1 — real Anthropic backend for
ai-review:diff-comprehension. - ✅ v0.2.0 —
ai-review:hallucinated-symbolextended to JS/TS via repox v0.4 call edges. APR now covers all three Wave-1 languages. - v0.3.0 (next) — auto-suggest fixes via the GitHub Suggested Changes API; per-import
local_namesfor renamed JS imports.
Status
Apache-2.0. See CHANGELOG.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file devtrust_apr-0.2.0.tar.gz.
File metadata
- Download URL: devtrust_apr-0.2.0.tar.gz
- Upload date:
- Size: 37.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8f3de3584b7ec6999067988658062cc1269e0a22b2954714df4a4ae2216a4c39
|
|
| MD5 |
0a79ed44ab91fb5f505253a98cc01891
|
|
| BLAKE2b-256 |
608496c3e03f5e50a2be6b728c5351ad6aab86458ba83bda361dc052ae6323b7
|
Provenance
The following attestation bundles were made for devtrust_apr-0.2.0.tar.gz:
Publisher:
release.yml on AbdullahBakir97/DevTrust
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
devtrust_apr-0.2.0.tar.gz -
Subject digest:
8f3de3584b7ec6999067988658062cc1269e0a22b2954714df4a4ae2216a4c39 - Sigstore transparency entry: 1484862585
- Sigstore integration time:
-
Permalink:
AbdullahBakir97/DevTrust@c6fc601fa074dc0135f1b9a7b5e46360ec1d9d4e -
Branch / Tag:
refs/tags/devtrust-apr-v0.2.0 - Owner: https://github.com/AbdullahBakir97
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@c6fc601fa074dc0135f1b9a7b5e46360ec1d9d4e -
Trigger Event:
push
-
Statement type:
File details
Details for the file devtrust_apr-0.2.0-py3-none-any.whl.
File metadata
- Download URL: devtrust_apr-0.2.0-py3-none-any.whl
- Upload date:
- Size: 30.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0bf0be5e92f91f6c2e9edacd24b9125ee82ef2cd59a72097ecdf977f35d0844d
|
|
| MD5 |
5b8b8e011af945da1478c99755aa32fe
|
|
| BLAKE2b-256 |
0dd9ad755b004333b9e1ec041cf1f2e1a0b670551c98809da21da6901aaf09d3
|
Provenance
The following attestation bundles were made for devtrust_apr-0.2.0-py3-none-any.whl:
Publisher:
release.yml on AbdullahBakir97/DevTrust
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
devtrust_apr-0.2.0-py3-none-any.whl -
Subject digest:
0bf0be5e92f91f6c2e9edacd24b9125ee82ef2cd59a72097ecdf977f35d0844d - Sigstore transparency entry: 1484862597
- Sigstore integration time:
-
Permalink:
AbdullahBakir97/DevTrust@c6fc601fa074dc0135f1b9a7b5e46360ec1d9d4e -
Branch / Tag:
refs/tags/devtrust-apr-v0.2.0 - Owner: https://github.com/AbdullahBakir97
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@c6fc601fa074dc0135f1b9a7b5e46360ec1d9d4e -
Trigger Event:
push
-
Statement type: