makeProjectGreatAgain/junior

Code reviewer

β˜… 0Forks 0PythonGitHub β†—Compare

README

Junior - AI Code Review Agent

An intelligent, webhook-based AI agent that provides comprehensive code reviews for GitHub pull requests, focusing on logic, security, critical bugs, and code quality.

πŸš€ Quick Start

  1. Clone and setup:

    git clone <repository-url>
    cd junior
    uv sync --all-extras
  2. Configure environment:

    cp .env.example .env
    # Edit .env with your API keys
  3. Test the setup:

    uv run python scripts/quick_test.py
  4. Start the webhook server:

    ./scripts/start.sh
    # OR
    uv run junior webhook-server --port 8000

πŸ”§ Configuration

Required environment variables:

  • GITHUB_TOKEN - GitHub Personal Access Token with repo permissions
  • Either OPENAI_API_KEY or ANTHROPIC_API_KEY - AI provider API key

Optional:

  • GITHUB_WEBHOOK_SECRET - GitHub webhook secret for security
  • SECRET_KEY - Application secret key

πŸ“‹ How It Works

The Review Flow

  1. GitHub PR Event β†’ Webhook receives PR opened/updated/ready-for-review

  2. Data Extraction β†’ Comprehensive PR information extraction including:

    • PR metadata (title, description, author, branches)
    • Commit history and linked issues
    • File changes and diff content
    • Repository context and dependencies
  3. MCP Repository Analysis β†’ Smart analysis with:

    • Temporary repository cloning
    • Project structure detection (Python, Node.js, etc.)
    • Priority-based file content extraction
    • Framework and dependency analysis
  4. AI Review Pipeline β†’ Specialized review focusing on:

    • Logic Analysis - Business logic, conditional flows, edge cases
    • Security Review - Authentication logic, business logic vulnerabilities
    • Critical Bug Detection - Memory safety, race conditions, zero-day potential
    • Naming Review - Semantic clarity, domain appropriateness
    • Optimization - Algorithmic improvements, performance bottlenecks
    • Design Principles - DRY, KISS, SOLID adherence
  5. GitHub Integration β†’ Structured review submission:

    • Review summary with severity breakdown
    • Inline comments (limited to 20 most critical)
    • Approve/Request Changes/Comment status

What Makes Junior Different

  • Logic-Focused: Unlike linters, Junior analyzes business logic and architectural decisions
  • Security-Aware: Identifies logical security vulnerabilities, not just code patterns
  • Context-Rich: Uses repository structure and project dependencies for informed reviews
  • Structured Output: Consistent, actionable feedback with severity levels and suggestions

πŸ”Œ GitHub Integration

Webhook Setup

  1. Go to your repository β†’ Settings β†’ Webhooks β†’ Add webhook
  2. Set Payload URL to: https://your-server.com/webhook/github
  3. Content type: application/json
  4. Select: "Pull requests" events
  5. Add webhook secret (optional but recommended)

Required GitHub Token Permissions

  • repo - Repository access
  • pull_requests:write - Create reviews and comments

πŸ§ͺ Testing

Run the comprehensive test suite:

uv run python scripts/quick_test.py

Check configuration:

uv run junior config-check

Start webhook server:

uv run junior webhook-server

πŸ“ Project Structure

junior/
β”œβ”€β”€ src/junior/
β”‚   β”œβ”€β”€ api.py              # FastAPI webhook service  
β”‚   β”œβ”€β”€ webhook.py          # GitHub webhook processing
β”‚   β”œβ”€β”€ review_agent.py     # Specialized AI review pipeline
β”‚   β”œβ”€β”€ mcp_tools.py        # Repository analysis tools
β”‚   β”œβ”€β”€ github_client.py    # GitHub API integration
β”‚   β”œβ”€β”€ models.py           # Data models and schemas
β”‚   β”œβ”€β”€ config.py          # Configuration management
β”‚   └── cli.py             # CLI (config-check, webhook-server)
β”œβ”€β”€ tests/                 # Test suite
β”œβ”€β”€ scripts/              # Utility scripts  
β”œβ”€β”€ helm/                # Kubernetes deployment
└── docs/                # Documentation

🚨 Review Categories

Junior focuses on high-impact issues:

  • Logic Issues - Incorrect business logic, missing edge cases
  • Security - Authentication flaws, business logic vulnerabilities
  • Critical Bugs - Memory safety, race conditions, data corruption
  • Naming - Semantic clarity, domain appropriateness
  • Optimization - Performance bottlenecks, algorithmic improvements
  • Principles - DRY, KISS, SOLID violations

πŸ› οΈ Development

Running Tests

uv run pytest
uv run pytest --cov=src/junior --cov-report=xml

Code Quality

uv run ruff check .
uv run ruff format .
uv run mypy src/

Development Server

uv run junior webhook-server --reload --debug

🐳 Docker

Build and Run

# Build image
docker build -t junior .

# Run with docker-compose
docker-compose up -d

☸️ Kubernetes Deployment

Deploy to Kubernetes using Helm:

# Install dependencies
helm dependency update helm/junior

# Deploy
helm install junior helm/junior \
  --set secrets.openaiApiKey="your-key" \
  --set secrets.githubToken="your-token" \
  --set secrets.secretKey="your-secret"

βš™οΈ Advanced Configuration

Review Settings

# Review toggles
ENABLE_SECURITY_CHECKS=true
ENABLE_PERFORMANCE_CHECKS=true
ENABLE_STYLE_CHECKS=true
ENABLE_COMPLEXITY_CHECKS=true

# Review limits
MAX_FILE_SIZE=100000
MAX_FILES_PER_PR=50
REVIEW_TIMEOUT=300

AI Model Settings

# Model configuration
DEFAULT_MODEL=gpt-4o
TEMPERATURE=0.1
MAX_TOKENS=4000

πŸ—οΈ Architecture

Junior uses a modern, webhook-driven architecture:

  • FastAPI - Webhook endpoints and API services
  • LangChain + LangGraph - Structured AI workflows
  • MCP Tools - Repository analysis and understanding
  • Pydantic - Data validation and settings
  • GitPython - Git operations and repository analysis

Review Pipeline Architecture

GitHub PR Event β†’ Webhook Validation β†’ Repository Cloning β†’ 
File Analysis β†’ AI Review Pipeline β†’ GitHub API Response

Each step is optimized for accuracy and performance, with comprehensive error handling and logging.

🀝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Make your changes
  4. Add tests for new functionality
  5. Run the test suite
  6. Submit a pull request

πŸ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

πŸ“ž Support

Contributors

mishachepimakeProjectGreatAgain

Issues