pr-reviewer/README.md
Adam Moussa 46cd856fb3
Add pr-reviewer local PR review tool
A single-user local dashboard that pulls open PRs from the
Sea-Haven-Industries org, reviews each with a Fireworks model in the
BLOCK/FIX/NIT/QUESTION format, and posts the review to GitHub as the
token owner. Runs only on localhost; secrets stay in a gitignored .env
and never reach the browser.

Structured as an app/ package plus a static/ frontend so the module
imports and static mount resolve. HTTP uses httpx2 (the runtime lib
starlette's TestClient now prefers), pinned in requirements.txt.

Includes a stdlib-only pytest suite (network mocked, no extra test
deps so CI needs only pytest) with a skip-by-default live Fireworks
test, and CI wired to the org ci-python-app reusable workflow to lint
app and tests and run the mocked suite fully offline. Dependabot covers
pip and github-actions.
2026-07-01 13:48:10 -04:00

58 lines
3 KiB
Markdown

# pr-reviewer
A local dashboard that pulls open PRs from your GitHub org, reviews each one with a Fireworks model using the BLOCK / FIX / NIT / QUESTION skill format, and lets you request revisions or post the review to GitHub as yourself.
Everything runs on your machine. This is a local, single-user tool. It is not deployed anywhere, so there is no AWS stack, no CI deploy path, and secrets live only in a local `.env` (gitignored). Your GitHub token and Fireworks key stay in the backend and never reach the browser.
## Setup
```bash
cp .env.example .env # then fill in FIREWORKS_API_KEY (and GITHUB_TOKEN if not using gh CLI)
./run.sh
```
Open http://127.0.0.1:8765
## Auth
- **GitHub**: leave `GITHUB_TOKEN` blank to use your local `gh auth token`, or set a token. Reviews are posted as whoever the token belongs to, so use the token for the account you want to appear as the reviewer.
A **fine-grained personal access token** is recommended (least privilege). Set the resource owner to `Sea-Haven-Industries` and grant only these repository permissions:
| Permission | Level | Why |
|---|---|---|
| Pull requests | Read and write | read PR data and submit the review |
| Contents | Read-only | fetch the PR diff |
| Metadata | Read-only | mandatory (auto-added) |
Give it access to all repositories you review (the search silently skips any it can't see). Fine-grained tokens are single-owner, so this token only covers the `Sea-Haven-Industries` org, which is all this tool searches; an org owner may need to approve the token before it works. A classic PAT with `repo` scope also works but is broader than needed.
- **Fireworks**: set `FIREWORKS_API_KEY`. Change `FIREWORKS_MODEL` in `.env` to swap models.
## How it works
1. **Refresh queue** runs your filter (`PR_SEARCH_FILTER`, default matches your org filter) and lists the PRs.
2. **Run review** fetches the PR diff and sends it to Fireworks. The result is parsed into the four categories plus a summary line and a recommended event.
3. **Request revision** re-runs the review with your notes folded in as a trusted instruction, separate from the untrusted diff.
4. **Post review to GitHub** submits it as a PR review. You confirm the event type (COMMENT / APPROVE / REQUEST_CHANGES) and can edit the body first.
## The @mention rule
Any PR whose author login is in `MENTION_AUTHORS` (default `openswe`) gets an `@author` mention prepended to the review summary. Add more logins comma-separated.
## Notes
- The diff is treated as untrusted input; the model is instructed to ignore any embedded instructions.
- State is in memory and resets on restart. This is a single-user local tool, not a shared service.
- Large diffs are truncated at `MAX_DIFF_BYTES` to control token cost.
## Layout
```
app/
config.py settings from .env
github_client.py search PRs, fetch diffs, post reviews
reviewer.py Fireworks call + skill format + markdown rendering
main.py FastAPI endpoints
static/
index.html the dashboard
```