Skip to main content

How does Qodex decide to review a PR?

Qodex reviews a PR only after it decides the GitHub event is actionable and the repository is linked to a Qodex project. Then it reads repo config, reviews the diff, filters findings, optionally verifies them, and posts the result back to GitHub.

Review decision flow

  1. GitHub sends a pull_request event to Qodex.
  2. Qodex verifies the webhook signature.
  3. Qodex checks whether the action should trigger review.
  4. Qodex finds projects linked to the repository.
  5. Draft PRs are skipped until ready for review.
  6. Qodex reads .qodex.yaml from the PR head SHA. If automatic reviews are off for the repo, only a review someone asked for continues.
  7. Qodex checks the project’s plan limits for the month and for this PR.
  8. Qodex reviews the diff and creates candidate findings.
  9. Findings are filtered by confidence, severity threshold, and excluded paths.
  10. Findings inside the diff become inline comments.
  11. Findings outside the diff appear in the walkthrough.
  12. Verification probes may run against an allowed preview host.
  13. Qodex posts the walkthrough, inline comments, and Check Run conclusion.

Events that trigger review

Qodex reviews automatically on:
  • opened
  • synchronize
  • reopened
  • ready_for_review
  • edited, when the PR’s base branch changed
It also reviews when someone asks:
  • @qodex-ai review slash commands
  • The Run review button on the PR review page in Qodex
Requested reviews run even when automatic reviews are off for the repo. Other GitHub PR actions are acknowledged and skipped.

Settings that matter most

Check Run behavior

By default, Qodex is advisory. If merge blocking is enabled and branch protection requires the Qodex Check Run, verified findings at or above the configured severity can block a merge.

Next steps

How a review fires

See the full PR review lifecycle.

Inline findings

Learn how comments are placed.

Check Run and merge gating

Configure merge protection.

.qodex.yaml reference

Control review behavior per repo.