How does Qodex decide to review a PR?
Qodex reviews a PR only after it decides the GitHub event is actionable and the repository is linked to a Qodex project. Then it reads repo config, reviews the diff, filters findings, optionally verifies them, and posts the result back to GitHub.Review decision flow
- GitHub sends a
pull_requestevent to Qodex. - Qodex verifies the webhook signature.
- Qodex checks whether the action should trigger review.
- Qodex finds projects linked to the repository.
- Draft PRs are skipped until ready for review.
- Qodex reads
.qodex.yamlfrom the PR head SHA. If automatic reviews are off for the repo, only a review someone asked for continues. - Qodex checks the project’s plan limits for the month and for this PR.
- Qodex reviews the diff and creates candidate findings.
- Findings are filtered by confidence, severity threshold, and excluded paths.
- Findings inside the diff become inline comments.
- Findings outside the diff appear in the walkthrough.
- Verification probes may run against an allowed preview host.
- Qodex posts the walkthrough, inline comments, and Check Run conclusion.
Events that trigger review
Qodex reviews automatically on:openedsynchronizereopenedready_for_reviewedited, when the PR’s base branch changed
@qodex-ai reviewslash commands- The Run review button on the PR review page in Qodex
Settings that matter most
Check Run behavior
By default, Qodex is advisory. If merge blocking is enabled and branch protection requires the Qodex Check Run, verified findings at or above the configured severity can block a merge.Next steps
How a review fires
See the full PR review lifecycle.
Inline findings
Learn how comments are placed.
Check Run and merge gating
Configure merge protection.
.qodex.yaml reference
Control review behavior per repo.