ReviewForge is not just a passive linter. ReviewForge is a Code Review tool that integrates directly with your GitHub workflows.
Whenever a developer pushes code or opens a Pull Request, ReviewForge analyzes the changes. If it spots a typo, it leaves a polite PR comment. If it detects a critical security vulnerability or architectural flaw, it autonomously creates a labeled GitHub Issue, links it to your PR, and alerts your team.
- Multi-Provider AI: Out-of-the-box support for Google Gemini, OpenAI, Nvidia NIM, Groq, or any OpenAI-compatible endpoint.
- Smart Routing: Smart routing ensures small UI tweaks get a fast, cheap review (e.g.,
gemini-3.7-flash), while complex core changes get deep security analysis (e.g.,gemini-3.7-proorgpt-oss-120b). - Issue Creation: When the AI detects a critical bug or security flaw, it automatically opens a GitHub Issue with the correct labels (
bug,security,architecture) and cross-references the offending PR. - Auto-Fix Code Blocks: The AI doesn't just complain; it provides the exact corrected code block so developers can easily copy-paste and solve the issue instantly.
- Company-Specific Rules (
.reviewforge.md): Drop a.reviewforge.mdfile in your repository root to teach the AI your specific coding standards (e.g., "Always use strict typing", "Never use raw SQL"). - Serverless: Runs entirely on GitHub Actions. Zero servers to maintain. Zero webhook configs. Zero hosting costs.
Add ReviewForge to any repository in under 30 seconds.
Create a workflow file in your repo at .github/workflows/reviewforge.yml:
name: ReviewForge SecOps
on: [pull_request, push]
jobs:
ai_review:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
issues: write
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Run ReviewForge AI
uses: cadakerem/ReviewForge@v1
with:
github_token: ${{ secrets.GITHUB_TOKEN }}
ai_provider: "gemini"
ai_api_key: ${{ secrets.GEMINI_API_KEY }}
# Optional Configuration (Defaults shown below)
# light_model: "gemini-3.7-flash"
# deep_model: "gemini-3.7-pro"
# auto_create_issues: "true"Note: Don't forget to add your
GEMINI_API_KEY(or OpenAI/Groq key) to your repository's GitHub Secrets.
| Input | Description | Default | Required |
|---|---|---|---|
github_token |
GitHub token for posting comments/issues. | ${{ github.token }} |
Yes |
ai_provider |
gemini, openai, nvidia, groq |
gemini |
Yes |
ai_api_key |
Your AI provider's API Key. | - | Yes |
light_model |
Faster model used for standard changes. | gemini-3.7-flash |
No |
deep_model |
Advanced model used for complex/security PRs. | gemini-3.7-pro |
No |
auto_create_issues |
Automatically create GitHub issues for critical vulnerabilities. | true |
No |
ReviewForge's AI engine is instructed to output a specific JSON payload if a change is highly destructive (e.g., SQL Injection, unauthenticated endpoint).
When the underlying Python engine detects this JSON output from the AI, it intercepts it, creates a formal GitHub Issue tagged with bug or security, and then leaves a warning comment on the developer's PR linking to the newly created issue ticket.
Developed by Kerem Barbaros Karnabat (@cadakerem).
Note on Repository Structure: As a serverless GitHub Action, the entry point and configuration schema are defined in
action.ymlat the root, while the core AI routing and review logic resides in thesrc/directory.
Contributions, issues, and feature requests are welcome! Feel free to check the Issues page.
This project is licensed under the MIT License.