Provider-neutral AI pull request review bot for 6529 repositories.
6529reviewbot runs focused PR reviews, posts concise GitHub comments as
6529bot, and records token and cost telemetry to an isolated AWS usage
ledger. The bot is designed to be used across multiple repositories while
keeping provider keys, AWS access, and bot code out of target repo pull
requests.
- Reviews pull requests with Anthropic, OpenAI, or OpenRouter models.
- Supports sixteen review modes:
- general PR review
- follow-up commit review
- WCAG 2.2 AA accessibility analysis
- i18n analysis
- crypto/security analysis
- backend deploy/actions analysis
- backend auth/API contract analysis
- DB/Lambda dataflow analysis
- media/external input analysis
- 6529Stream contract analysis
- 6529 Safe App write-path analysis
- release and deployment analysis
- privacy and evidence handling analysis
- Safe App signer UX analysis
- advisory GLM 5.2 swarm synthesis through OpenRouter
- deterministic responsiveness review
- Posts one top-level PR comment per review run.
- Uses hidden metadata so follow-up reviews can find prior bot reviews without depending on visible comment text.
- Tracks provider/model/token/cost usage in a separate AWS Aurora PostgreSQL Serverless v2 database.
- Expands each admitted trigger into explicit review jobs so the same review kind can run through multiple provider/model lanes when configured.
- Supports base-ref repository configuration for per-repo review kinds, lane selection, admission tightening, and budget caps.
- Dispatches admitted jobs through explicit worker adapters for local workers or central GitHub Actions workflows.
- Fails closed instead of posting a generic review when a live provider returns empty visible output.
- Redacts common token, sensitive-header, alert-webhook, AWS access-key id, AWS ARN, AWS account-id, and private-key shapes from worker, dispatch, ledger, alert, preflight, and repository-config diagnostics before they enter public or operator summaries.
- Normalizes usage, job, and run-control ledger metadata before persistence so prompts, diffs, provider payloads, webhook payloads, worker output, and credential-shaped fields do not become durable audit data.
- Records review-job budget and dispatch lifecycle events in a separate operator job ledger when enabled.
- Adds run-control claims for duplicate-job and concurrency protection before worker dispatch.
- Records GitHub webhook deliveries in a durable inbox with retry/backpressure handling before hydration and dispatch.
- Exposes a read-side usage API contract for public transparency and 6529.io-authenticated admin dashboards.
- Caches successful read-side API responses briefly after admin authorization and exposes admin views for failed inbox rows, job events, run claims, spend, alerts, and runtime status.
- Verifies private admin API calls through a server-side
6529.ioauth bridge instead of a separate login system. - Runs scheduled operator alerts for budget utilization, unusual spend spikes, failed jobs, and stale run-control claims.
- Uses GitHub Actions OIDC for AWS access, not long-lived AWS credentials.
This repository is public and MIT licensed. It is still pre-v1, but the core
production path is live for selected 6529 repositories: the 6529bot GitHub
App receives PR/comment events, applies trusted-actor admission, expands review
jobs, enforces run-control and budget policy, dispatches the central
review-job.yml worker, posts PR comments as the App, and writes usage/job
telemetry to the AWS ledger.
The repository includes its own .github/6529bot.yml dogfood config and the
central worker workflow used by production. Broader community release,
semver-stable configuration guarantees, and public release tags are still
tracked through the release-readiness and v0 plans.
For the current release gates, see docs/release-readiness.md. For the first pre-v1 tag boundary, see docs/v0-release-plan.md.
bin/ Thin runtime and review-mode entrypoints
src/ Review engine, App, policy, ledger, and alert code
docs/ Architecture, configuration, operations docs
templates/ Caller workflow and config examples
.github/ Community files, issue templates, CI/security
Dockerfile Central App server runtime image
AGENTS.md Instructions for coding agents working here
The full canonical documentation index is docs/README.md.
- Architecture: system boundaries and trust model.
- Installation: central App setup and target repo onboarding.
- Configuration: central runtime settings.
- Compatibility Policy: pre-v1 compatibility surfaces, breaking-change handling, and pinning guidance.
- External Evidence Boundaries: what local checks can prove and what remains operator-owned private evidence.
- GitHub App: permissions, events, and webhook setup.
- GitHub App Registration: operator packet for App creation, credential custody, verification, and rotation.
- Model Catalog: provider defaults and update path.
- Model Pricing: operator-maintained price rows.
- Budget Policies: operator-maintained central caps.
- Provider Setup: Anthropic, OpenAI, and OpenRouter operator setup.
- AWS IAM Templates: OIDC and Data API policy examples.
- Repository Config: target repo policy file.
- Comment Commands: PR comment trigger contract.
- Review Jobs: fanout and provider/model lanes.
- Review Comment Format: visible comment, hidden metadata, and budget-skip format.
- Reusable Workflow: compatibility path and caller-secret boundary.
- Run Control: dedupe and concurrency claims.
- Support: support bundle and issue triage.
- Repository Rulesets: GitHub-side
main, pull request check, and release tag protection guidance. - Job Ledger: durable job lifecycle audit events.
- Usage API: public and admin reporting contracts.
- Deployment: production App, worker, and 6529.io wiring.
- Container Deployment: runtime image, secret injection, and container verification.
- Container Publish Plan: dry-run build/push/scan/evidence steps for operator-owned registries.
- Production Deployment Plan: dry-run operator handoff across App registration, image publish, workspace, preflight, cutover, and dogfood gates.
- Dashboard Deployment Plan: dry-run 6529.io public/private dashboard configuration and verification handoff.
- Alert Delivery Plan: dry-run production alert routing handoff for webhook, SNS, or SES delivery.
- Production Cutover: go/no-go checklist and private status overlay for moving to live dogfood traffic.
- Worker Capacity: scaling, backpressure, and worker evidence.
- Dogfood Runbook: safe phased rollout.
- Dogfood Target Packet: target-repo config PR checklist and conservative posture validation.
- Dogfood Readiness: public-safe dogfood input validation before first traffic.
- Dogfood Promotion Packet: final public-safe go/no-go packet before live dogfood traffic.
- Dogfood Go-Live Packet: final public-safe release, promotion, cutover, and operator-workspace cross-check.
- Dogfood Status: private status overlay for command-only and limited initial-review dogfood evidence.
- Incident Response: containment and recovery runbooks.
- Security Review Status: private status overlay for manual security review evidence.
- Release Readiness: current gates and gaps.
- v0 Release Plan: first tag criteria.
- Release Notes Publication: completed release notes guard before tags or GitHub Releases.
- Release Tag Plan: dry-run clean-main, tag-availability, and completed-notes check before operator tagging.
- Release Candidate Bundle: public-safe release-readiness summary command.
- Release Operations Map: command and evidence-boundary index for release operators.
npm run community:gates: render the broad community-release gate checklist.- Release Notes Draft: public-safe pre-v1 release notes draft from release-candidate evidence.
- Operator Workspace: private release evidence skeleton bootstrap.
- Operator Evidence Template: redacted release/deployment proof format.
Install dependencies:
npm installRun local checks:
npm run check
npm run check:docs
npm run check:manager-memory
npm run check:codeowners
npm run check:community-release-gates
npm run check:repository-rulesets
npm run check:install-guide
npm run check:deployment-runbook
npm run check:configuration-reference
npm run check:aws-iam-templates
npm run check:security-model
npm run check:external-evidence-boundaries
npm run check:operations-runbook
npm run check:comment-commands
npm run check:review-workflows
npm run check:review-context-boundary
npm run check:review-bins
npm run check:review-comment-format
npm run check:admission-policy
npm run check:repository-config-boundary
npm run check:worker-adapter-contract
npm run check:worker-capacity
npm run check:admin-auth
npm run check:usage-api-routes
npm run check:admin-snapshot
npm run check:support-bundle
npm run check:support-runbooks
npm run check:diagnostics-redaction
npm run check:budget-policies-runbook
npm run check:model-defaults
npm run check:model-pricing-runbook
npm run check:providers
npm run check:provider-adapters
npm run check:ledger-privacy
npm run check:webhook-replay
npm run check:dogfood-target
npm run check:dogfood-status
npm run check:dogfood-readiness
npm run check:dogfood-promotion
npm run check:dogfood-go-live
npm run check:operator-workspace
npm run check:operator-drill
npm run check:operator-evidence
npm run check:production-cutover
npm run check:security-review-status
npm run check:budget-scopes
npm run check:run-control-scopes
npm run check:alert-dimensions
npm run check:alert-notifier-modes
npm run check:alerting-runbook
npm run check:alert-delivery-plan
npm run check:container-image
npm run check:container-publish-plan
npm run check:production-deployment-plan
npm run check:dashboard-deployment-plan
npm run check:public-artifacts
npm run check:github-app-manifest
npm run check:github-app-auth
npm run check:github-app-routes
npm run check:preflight
npm run check:preflight-contract
npm run check:release-gates
npm run check:v0-gates
npm run check:release-candidate
npm run check:release-notes
npm run check:release-notes-draft
npm run check:release-notes-publication
npm run check:release-tag-plan
npm run check:self-dogfood-replay
npm test
npm run check:workflow-actionsRun the full release gate:
npm run release:checkCheck completed release notes before publishing a tag or GitHub Release:
npm run community:gates -- -- --status-file <operator-community-status-file> --require-ready
npm run release:notes:check -- -- --file <release-notes.md>
npm run check:release-notes-publicationPublication-ready notes must include community-release status evidence and the matching community gate validation result, or explicitly document a dogfood-only or community-release deferral.
Build a dry-run release tag plan after completed notes pass:
npm run release:tag-plan -- -- --release v0.1.0 --release-notes <release-notes.md> --require-ready
npm run check:release-tag-planBuild a dry-run container publish plan before operator-owned registry work:
npm run container:publish-plan -- -- --image <operator-registry>/6529reviewbot --release v0.1.0 --require-ready
npm run check:container-publish-planBuild a dry-run production deployment plan before App registration, registry, worker dispatch credential, runtime, cutover, or dogfood handoff work:
npm run production:deployment-plan -- -- --host <production-bot-origin> --image <operator-registry>/6529reviewbot --operator-workspace <private-workspace-dir> --worker-dispatch-installation-id <central-repo-installation-id> --release v0.1.0 --require-ready
npm run check:production-deployment-planBuild a dry-run 6529.io dashboard deployment plan before wiring the public Open Data and private admin routes to production:
npm run dashboard:deployment-plan -- -- --frontend-origin <6529-io-origin> --bot-origin <production-bot-origin> --operator-workspace <private-workspace-dir> --auth-check-url <6529-auth-check-url> --release v0.1.0 --require-ready
npm run check:dashboard-deployment-planBuild a dry-run production alert delivery plan before enabling webhook, SNS, or SES routing from the operator environment:
npm run alerts:delivery-plan -- -- --bot-origin <production-bot-origin> --operator-workspace <private-workspace-dir> --notify-mode <webhook|sns|ses> --alert-channel <operator-alert-channel> --release v0.1.0 --require-ready
npm run check:alert-delivery-planRun a public-safe release and dogfood rehearsal:
npm run operator:drillDraft pre-v1 release notes from public-safe evidence:
npm run release:notes
npm --silent run release:notes -- -- --candidate-file <release-candidate.json> --out <release-notes.md> --quietValidate central runtime configuration without network calls:
npm run preflight
npm run check:preflight
npm run check:preflight-contractReview the pre-v1 release boundary before tagging:
cat docs/v0-release-plan.mdRender the v0 release gate checklist:
npm run v0:gates
npm run v0:gates -- -- --init-status <operator-status-file>
npm run v0:gates -- -- --status-file config/v0-release-status.example.json
npm run v0:gates -- -- --status-file <operator-status-file> --summary
npm run v0:gates -- -- --status-file <operator-status-file> --require-ready
npm run check:v0-gatesThe final --require-ready check also verifies that the status file lists
every current gate, so stale private evidence files fail loudly after the
canonical gate list changes.
Render the broad community-release gate checklist:
npm run community:gates
npm run community:gates -- -- --status-file <operator-community-status-file> --summary
npm run community:gates -- -- --status-file <operator-community-status-file> --require-ready
npm run check:community-release-gatesValidate a structured operator evidence file and render a redacted public summary:
npm run operator:evidence -- -- --file config/production-evidence.example.json
npm run operator:evidence -- -- --file <private-evidence-file> --summary
npm run operator:evidence -- -- --file <private-evidence-file> --require-ready
npm run check:operator-evidenceBuild a public-safe release candidate bundle from release gates, operator evidence, git metadata, and no-network preflight:
npm run release:candidate
npm run release:candidate -- -- --status-file <operator-status-file> --operator-evidence-file <private-evidence-file>
npm run release:candidate -- -- --status-file <operator-status-file> --community-status-file <operator-community-status-file> --operator-evidence-file <private-evidence-file>
npm run release:candidate -- -- --operator-workspace <private-workspace-dir>
npm --silent run release:candidate -- -- --operator-workspace <private-workspace-dir> --out <public-bundle-file.md> --quiet
npm run release:candidate -- -- --status-file <operator-status-file> --operator-evidence-file <private-evidence-file> --dogfood-status-file <operator-dogfood-status-file>
npm run release:candidate -- -- --status-file <operator-status-file> --operator-evidence-file <private-evidence-file> --security-review-status-file <operator-security-status-file>
npm run release:candidate -- -- --status-file <operator-status-file> --operator-evidence-file <private-evidence-file> --cutover-status-file <operator-cutover-status-file>
npm run release:candidate -- -- --status-file <operator-status-file> --operator-evidence-file <private-evidence-file> --strict-preflight --require-readyRender the release operations map when deciding what to run next:
npm run release:operations
npm run release:operations -- -- --phase release-candidate
npm run check:release-operationsThe release-operations check also parses mapped CLI argument examples through their real CLIs, including production handoff, status/release gates, dogfood ready-mode commands, private operator workspace setup, status skeleton creation, budget/model-price dry runs, webhook replay dry runs, admin snapshots, and release-note commands. That keeps the map from drifting away from required private workspace, model price, worker-dispatch, status, release-notes, strict preflight, ready-mode, and dry-run safety flags.
Create a private operator workspace with community-release, v0, dogfood, security-review, production-cutover, and operator-evidence skeletons:
npm run operator:workspace -- -- --dir <private-workspace-dir>
npm run operator:workspace -- -- --dir <private-workspace-dir> --checkTrack production cutover readiness from the public checklist plus private operator status:
npm run production:cutover
npm run production:cutover -- -- --init-status <operator-cutover-status-file>
npm run production:cutover -- -- --status-file <operator-cutover-status-file> --summary
npm run production:cutover -- -- --status-file <operator-cutover-status-file> --require-readyPrint a prompt for a target PR without calling a model:
GH_REPO=6529-Collections/6529seize-frontend \
PR_NUMBER=123 \
REVIEW_PROVIDER=anthropic \
REVIEW_PRINT_PROMPT=true \
node bin/general-pr-review.cjsDry-run a generated comment without calling a model:
GH_REPO=6529-Collections/6529seize-frontend \
PR_NUMBER=123 \
REVIEW_DRY_RUN=true \
node bin/security-analysis.cjsThe bot expects gh and git to be available when gathering PR context.
Validate a target repository config before opening its PR:
npm run validate:repo-config -- templates/dogfood-repository-config.ymlValidate dogfood inputs before first traffic:
npm run dogfood:target
npm run dogfood:target -- -- --mode limited-initial --require-ready
npm run check:self-dogfood-replay
npm run dogfood:promotion
npm run dogfood:readiness
npm run dogfood:readiness -- -- --preflight
npm run dogfood:readiness -- -- --strict-preflight --require-ready
npm --silent run dogfood:promotion -- -- --operator-workspace <private-workspace-dir> --model-price-file <reviewed-model-price-file.json> --strict-preflight --require-ready
npm --silent run dogfood:go-live -- -- --operator-workspace <private-workspace-dir> --model-price-file <reviewed-model-price-file.json> --strict-preflight --require-ready
npm --silent run dogfood:readiness -- -- --operator-workspace <private-workspace-dir> --model-price-file <reviewed-model-price-file.json> --strict-preflight --require-readycheck:self-dogfood-replay uses synthetic payloads and dry-run queueing to
prove command-only PR-open skip, trusted command admission, deliberate
multi-lane fanout, max-fanout rejection, and untrusted command denial before
live dogfood traffic.
Use dogfood:promotion as the final pre-traffic go/no-go packet. Use
dogfood:go-live as the final composed view when release-candidate,
promotion, production-cutover, and operator-workspace evidence should agree in
one place. Use npm --silent run when copying promotion, go-live, or readiness
output from commands that include private workspace or reviewed model price
file paths; normal npm run can echo the command line before the redacted
report. Final promotion and go-live ready mode require --operator-workspace
and --model-price-file so private operator evidence and reviewed price
coverage are present before live dogfood traffic.
Before the first live dogfood model call, the private dogfood status overlay
must include provider-console-readiness-reviewed and
iam-secret-custody-reviewed, backed by provider-console-readiness and
iam-and-secrets operator evidence. Keep provider account/project ids, API
keys, billing account identifiers, AWS identifiers, ARNs, secret names, wallet
addresses, and private principals out of public summaries.
Track private dogfood execution evidence:
npm run dogfood:status -- -- --init-status <operator-dogfood-status-file>
npm run dogfood:status -- -- --status-file <operator-dogfood-status-file> --summary
npm run dogfood:status -- -- --status-file <operator-dogfood-status-file> --require-readyTrack private security review evidence:
npm run security:review -- -- --init-status <operator-security-status-file>
npm run security:review -- -- --status-file <operator-security-status-file> --summary
npm run security:review -- -- --status-file <operator-security-status-file> --require-readyValidate the GitHub App manifest template:
npm run github-app:manifest -- -- --host <production-bot-origin> --quiet
npm run check:github-app-manifestRender a production-hosted manifest without generating any secrets:
npm run github-app:manifest -- -- --host <production-bot-origin>Convert GitHub's one-hour manifest code from a private operator environment:
npm run github-app:convert -- -- --code <code> --output <private-json-path>Mint a short-lived installation token from a configured private operator environment:
npm run github-app:token -- -- --profile main --installation-id <installation-id>
npm run github-app:token -- -- --profile worker-dispatch --installation-id <dispatch-installation-id>
npm run check:github-app-authGitHub App JWTs default to a 540-second TTL and configurable TTLs are capped at GitHub's documented 600-second maximum.
Print the Aurora ledger schema without touching AWS:
npm run ledger:schemaPreview model pricing SQL without touching AWS:
npm run model-prices -- -- --file config/model-prices.example.jsonAudit an operator-owned price file against the active model catalog without touching AWS:
npm run model-prices -- -- --file prices.json --require-catalog-coverage
npm run check:model-price-coverageApplying price rows rejects zero-rate placeholders by default:
npm run model-prices -- -- --file <reviewed-price-file.json> --applyThe apply path also rejects stale or future-dated sourceCheckedAt evidence by
default. Recheck provider pricing or record an explicit release acceptance
before using --allow-stale-source.
The admin usage API exposes active price-row posture for private dashboards at
GET /api/admin/model-prices/status.
Preview central budget policy SQL without touching AWS:
npm run budget-policies -- -- --file config/budget-policies.example.json
npm run budget-policies -- -- --file config/budget-policies.dogfood.example.jsonValidate the dashboard/admin API contract:
npm run validate:api-contractValidate the public-safe 6529.io dashboard env template:
npm run check:6529-io-envValidate all public env templates:
npm run check:env-templatesGenerate a sanitized support bundle:
npm run support:bundleCollect a private admin API posture snapshot:
npm run admin:snapshot -- -- --base-url <production-bot-origin>Replay a saved GitHub webhook payload without dispatching workers:
npm run webhook:replay -- -- \
--payload payload.json \
--actor-permission write \
--repository-config templates/dogfood-repository-config.yml \
--assume-empty-budgetMinimum required environment:
GH_TOKEN GitHub token that can read PRs and post comments
GH_REPO target repository, owner/name
PR_NUMBER target pull request number
REVIEW_PROVIDER anthropic, openai, or openrouter
Provider keys:
ANTHROPIC_API_KEY
OPENAI_API_KEY
OPENROUTER_API_KEY
Provider defaults:
REVIEWBOT_MODEL_CATALOG_PATH=config/model-catalog.json
REVIEW_DEFAULT_ANTHROPIC_MODEL=claude-opus-4-8
REVIEW_DEFAULT_OPENAI_MODEL=gpt-5.5
REVIEW_DEFAULT_OPENROUTER_MODEL=
Central App job fanout:
REVIEWBOT_REVIEW_LANES=anthropic:claude-opus-4-8,openai:gpt-5.5
REVIEWBOT_MAX_JOBS_PER_DELIVERY=12
The default max-jobs cap is 12, enough for the standard initial set across
two provider/model lanes, or for a one-lane specialist profile such as
6529-safe-app with GLM swarm and responsiveness. Raise it only for trusted
high-volume deployments with reviewed budgets and worker capacity.
Runtime control:
REVIEWBOT_ENABLED=true
REVIEWBOT_DISABLED_ORGS=
REVIEWBOT_DISABLED_REPOS=
REVIEWBOT_DISABLED_PROVIDERS=
REVIEWBOT_DISABLED_MODELS=
REVIEWBOT_DISABLED_REVIEW_KINDS=
Worker adapter:
REVIEWBOT_WORKER_ADAPTER=noop|local|github_actions
REVIEWBOT_WORKER_GITHUB_REPO=6529-Collections/6529reviewbot
REVIEWBOT_WORKER_GITHUB_WORKFLOW=review-job.yml
Run control:
REVIEWBOT_RUN_CONTROL_MODE=off|warn|enforce
REVIEWBOT_RUN_CONTROL_LEDGER_ENABLED=false
REVIEWBOT_RUN_CONTROL_GLOBAL_MAX_CONCURRENT=
REVIEWBOT_RUN_CONTROL_ORG_MAX_CONCURRENT=
REVIEWBOT_RUN_CONTROL_REPO_MAX_CONCURRENT=
REVIEWBOT_RUN_CONTROL_REQUESTOR_MAX_CONCURRENT=
REVIEWBOT_RUN_CONTROL_PR_MAX_CONCURRENT=
REVIEWBOT_RUN_CONTROL_PROVIDER_MAX_CONCURRENT=
REVIEWBOT_RUN_CONTROL_MODEL_MAX_CONCURRENT=
REVIEWBOT_RUN_CONTROL_REVIEW_KIND_MAX_CONCURRENT=
Webhook replay diagnostics:
npm run webhook:replay -- -- --payload payload.json --assume-empty-budgetGitHub App installation auth:
REVIEWBOT_GITHUB_APP_ID=
REVIEWBOT_GITHUB_APP_FETCH_TIMEOUT_MS=10000
REVIEWBOT_GITHUB_APP_FETCH_RETRIES=2
REVIEWBOT_GITHUB_APP_RETRY_BASE_DELAY_MS=500
REVIEWBOT_GITHUB_APP_PRIVATE_KEY=
REVIEWBOT_GITHUB_APP_PRIVATE_KEY_BASE64=
Webhook inbox/backpressure:
REVIEWBOT_WEBHOOK_INBOX_ENABLED=false
REVIEWBOT_WEBHOOK_INBOX_RETRY_DELAY_SECONDS=90
REVIEWBOT_WEBHOOK_INBOX_MAX_ATTEMPTS=6
REVIEWBOT_WEBHOOK_INBOX_BATCH_SIZE=2
Usage API:
REVIEWBOT_USAGE_API_PUBLIC_ENABLED=true
REVIEWBOT_USAGE_API_ADMIN_ENABLED=true
REVIEWBOT_USAGE_API_DEFAULT_DAYS=30
REVIEWBOT_USAGE_API_MAX_DAYS=365
REVIEWBOT_USAGE_API_ADMIN_USAGE_EVENTS_PATH=/api/admin/usage/events/recent
REVIEWBOT_USAGE_API_ADMIN_BUDGET_STATUS_PATH=/api/admin/budget/status
REVIEWBOT_USAGE_API_ADMIN_ALERT_STATUS_PATH=/api/admin/alerts/status
REVIEWBOT_USAGE_API_ADMIN_JOB_EVENTS_PATH=/api/admin/jobs/recent
REVIEWBOT_USAGE_API_ADMIN_RUN_CLAIMS_PATH=/api/admin/run-claims/recent
REVIEWBOT_USAGE_API_ADMIN_WEBHOOK_INBOX_PATH=/api/admin/webhook-inbox/recent
REVIEWBOT_USAGE_API_ADMIN_STATUS_PATH=/api/admin/status
REVIEWBOT_USAGE_API_CACHE_ENABLED=true
REVIEWBOT_USAGE_API_CACHE_TTL_MS=15000
REVIEWBOT_USAGE_API_CACHE_MAX_ENTRIES=100
REVIEWBOT_USAGE_API_PUBLIC_ORGS=6529-Collections
Repository config:
REVIEWBOT_REPOSITORY_CONFIG_SOURCE=none|github
REVIEWBOT_REPOSITORY_CONFIG_REQUIRED=false
When enabled, the App reads .github/6529bot.yml or another supported config
file from the target repository's base ref. Repo config can narrow central
policy, but it cannot add unapproved model lanes or raise central budget caps.
Admin auth bridge:
REVIEWBOT_ADMIN_AUTH_MODE=disabled|shared_secret|hmac
REVIEWBOT_ADMIN_AUTH_REQUIRED_ROLES=reviewbot-admin,admin
Scheduled operator alerts:
REVIEWBOT_ALERTS_ENABLED=false
REVIEWBOT_ALERTS_NOTIFY_MODE=none|stdout|webhook|sns|ses
REVIEWBOT_ALERTS_BUDGET_WARNING_PERCENT=80
REVIEWBOT_ALERTS_SPIKE_DIMENSIONS=global,repo,requestor,provider,model,review_kind
REVIEWBOT_ALERTS_SPIKE_MULTIPLIER=3
REVIEWBOT_ALERTS_JOB_HEALTH_ENABLED=false
REVIEWBOT_ALERTS_JOB_FAILURE_THRESHOLD=1
REVIEWBOT_ALERTS_STALE_CLAIM_HOURS=2
Job lifecycle audit:
REVIEWBOT_JOB_LEDGER_ENABLED=false
REVIEWBOT_JOB_LEDGER_FAIL_CLOSED=false
OpenRouter intentionally has no built-in default model. Set
REVIEW_MODEL or REVIEW_DEFAULT_OPENROUTER_MODEL explicitly so routing and
cost are predictable.
Built-in defaults are defined in config/model-catalog.json. See docs/model-catalog.md for the update process.
The AWS usage ledger is optional but recommended. When enabled, the bot writes one usage event per review run.
REVIEW_USAGE_ENABLED=true
REVIEW_USAGE_AWS_REGION=us-east-1
REVIEW_USAGE_DB_RESOURCE_ARN=arn:aws:rds:...
REVIEW_USAGE_DB_SECRET_ARN=arn:aws:secretsmanager:...
REVIEW_USAGE_DB_NAME=reviewbot
REVIEW_USAGE_DB_SCHEMA=reviewbot
For GitHub Actions, configure AWS access with OIDC and the role stored in:
REVIEW_USAGE_AWS_ROLE_ARN=arn:aws:iam::...:role/...
See docs/aws-usage-ledger.md. Use docs/job-ledger.md when enabling durable budget and dispatch audit events. Use docs/budget-policies.md to dry-run and apply central budget caps that are enforced before worker dispatch or provider calls.
From a configured operator environment, apply the schema explicitly with:
npm run ledger:schema -- -- --applyThe bot treats PR diffs, source files, comments, and metadata as untrusted input. In particular:
- hidden bot metadata is trusted only from configured bot accounts;
- target PR code is read as text and is not executed;
- source context refuses absolute paths, parent traversal,
.gitpaths, and symlinks; npm run check:review-context-boundarykeeps path safety, trusted metadata, prompt hygiene, and context caps synchronized with docs;npm run check:security-modelkeeps the first-principles security model, manual review checklist, and source anchors synchronized;- provider errors are sanitized before logging;
- empty provider responses fail closed instead of becoming no-finding comments;
- worker, dispatch, ledger, alert, preflight, and repository-config diagnostics redact common token, sensitive-header, alert-webhook, AWS access-key id, AWS ARN, AWS account-id, and private-key shapes before they are returned;
- provider requests have explicit timeout and token/context caps;
- AWS access uses OIDC and least-privilege Data API permissions.
See SECURITY.md and Security Model.
- Docs index
- Architecture
- Configuration
- Production deployment
- Container deployment
- Container publish plan
- Dogfood runbook
- Dogfood readiness
- Dogfood promotion packet
- Dogfood go-live packet
- Dogfood status
- GitHub App
- GitHub App registration
- Model pricing
- Budget policies
- Provider setup
- Repository config
- Review jobs
- Review comment format
- Reusable workflow
- Run control
- Support
- Security Model
- Security review status
- Worker adapters
- Worker capacity
- Job ledger
- Usage API
- Admin auth bridge
- 6529.io admin integration
- Alerting and scheduled operator checks
- Alert Delivery Plan
- Admission policy
- Budget admission
- Review workflows
- Roadmap
- AWS usage ledger
- AWS IAM templates
- Operations runbook
- Incident response
- Release process
- Release readiness
- Release operations map
- Release notes draft
- Release tag plan
- Operator workspace
- Operator Drill
- Operator evidence template
- Security review checklist
- Manager Memory
See CONTRIBUTING.md, SECURITY.md, SUPPORT.md, CODE_OF_CONDUCT.md, and GOVERNANCE.md. This project uses the MIT license and expects signed-off commits when that is required by the target 6529 repository.
MIT. See LICENSE.