An intelligent, webhook-based AI agent that provides comprehensive code reviews for GitHub pull requests, focusing on logic, security, critical bugs, and code quality.
-
Clone and setup:
git clone <repository-url> cd junior uv sync --all-extras
-
Configure environment:
cp .env.example .env # Edit .env with your API keys -
Test the setup:
uv run python scripts/quick_test.py
-
Start the webhook server:
./scripts/start.sh # OR uv run junior webhook-server --port 8000
Required environment variables:
GITHUB_TOKEN- GitHub Personal Access Token with repo permissions- Either
OPENAI_API_KEYorANTHROPIC_API_KEY- AI provider API key
Optional:
GITHUB_WEBHOOK_SECRET- GitHub webhook secret for securitySECRET_KEY- Application secret key
-
GitHub PR Event β Webhook receives PR opened/updated/ready-for-review
-
Data Extraction β Comprehensive PR information extraction including:
- PR metadata (title, description, author, branches)
- Commit history and linked issues
- File changes and diff content
- Repository context and dependencies
-
MCP Repository Analysis β Smart analysis with:
- Temporary repository cloning
- Project structure detection (Python, Node.js, etc.)
- Priority-based file content extraction
- Framework and dependency analysis
-
AI Review Pipeline β Specialized review focusing on:
- Logic Analysis - Business logic, conditional flows, edge cases
- Security Review - Authentication logic, business logic vulnerabilities
- Critical Bug Detection - Memory safety, race conditions, zero-day potential
- Naming Review - Semantic clarity, domain appropriateness
- Optimization - Algorithmic improvements, performance bottlenecks
- Design Principles - DRY, KISS, SOLID adherence
-
GitHub Integration β Structured review submission:
- Review summary with severity breakdown
- Inline comments (limited to 20 most critical)
- Approve/Request Changes/Comment status
- Logic-Focused: Unlike linters, Junior analyzes business logic and architectural decisions
- Security-Aware: Identifies logical security vulnerabilities, not just code patterns
- Context-Rich: Uses repository structure and project dependencies for informed reviews
- Structured Output: Consistent, actionable feedback with severity levels and suggestions
- Go to your repository β Settings β Webhooks β Add webhook
- Set Payload URL to:
https://your-server.com/webhook/github - Content type:
application/json - Select: "Pull requests" events
- Add webhook secret (optional but recommended)
repo- Repository accesspull_requests:write- Create reviews and comments
Run the comprehensive test suite:
uv run python scripts/quick_test.pyCheck configuration:
uv run junior config-checkStart webhook server:
uv run junior webhook-serverjunior/
βββ src/junior/
β βββ api.py # FastAPI webhook service
β βββ webhook.py # GitHub webhook processing
β βββ review_agent.py # Specialized AI review pipeline
β βββ mcp_tools.py # Repository analysis tools
β βββ github_client.py # GitHub API integration
β βββ models.py # Data models and schemas
β βββ config.py # Configuration management
β βββ cli.py # CLI (config-check, webhook-server)
βββ tests/ # Test suite
βββ scripts/ # Utility scripts
βββ helm/ # Kubernetes deployment
βββ docs/ # Documentation
Junior focuses on high-impact issues:
- Logic Issues - Incorrect business logic, missing edge cases
- Security - Authentication flaws, business logic vulnerabilities
- Critical Bugs - Memory safety, race conditions, data corruption
- Naming - Semantic clarity, domain appropriateness
- Optimization - Performance bottlenecks, algorithmic improvements
- Principles - DRY, KISS, SOLID violations
uv run pytest
uv run pytest --cov=src/junior --cov-report=xmluv run ruff check .
uv run ruff format .
uv run mypy src/uv run junior webhook-server --reload --debug# Build image
docker build -t junior .
# Run with docker-compose
docker-compose up -dDeploy to Kubernetes using Helm:
# Install dependencies
helm dependency update helm/junior
# Deploy
helm install junior helm/junior \
--set secrets.openaiApiKey="your-key" \
--set secrets.githubToken="your-token" \
--set secrets.secretKey="your-secret"# Review toggles
ENABLE_SECURITY_CHECKS=true
ENABLE_PERFORMANCE_CHECKS=true
ENABLE_STYLE_CHECKS=true
ENABLE_COMPLEXITY_CHECKS=true
# Review limits
MAX_FILE_SIZE=100000
MAX_FILES_PER_PR=50
REVIEW_TIMEOUT=300# Model configuration
DEFAULT_MODEL=gpt-4o
TEMPERATURE=0.1
MAX_TOKENS=4000Junior uses a modern, webhook-driven architecture:
- FastAPI - Webhook endpoints and API services
- LangChain + LangGraph - Structured AI workflows
- MCP Tools - Repository analysis and understanding
- Pydantic - Data validation and settings
- GitPython - Git operations and repository analysis
GitHub PR Event β Webhook Validation β Repository Cloning β
File Analysis β AI Review Pipeline β GitHub API Response
Each step is optimized for accuracy and performance, with comprehensive error handling and logging.
- Fork the repository
- Create a feature branch
- Make your changes
- Add tests for new functionality
- Run the test suite
- Submit a pull request
This project is licensed under the MIT License - see the LICENSE file for details.
- π Issue Tracker
- π¬ Discussions
- π Documentation