pr-reviewer/app
Adam Moussa 667afd73f9
Assess Dependabot PRs for merge risk instead of code review
Dependabot dependency-update PRs do not benefit from BLOCK/FIX/NIT/QUESTION
code notes. Route them to a dependency-risk assessment instead: the semver
update type, a safe/low_risk/risky/breaking call, the packages bumped, and
reasons, grounded in the Sea Haven Dependabot merge policy (patch/minor
generally safe; majors need changelog review; grouped PRs assessed at the
riskiest package). Feedback focuses on PR title/description quality.

review() dispatches on the author to a dependabot or code path, each
stamping a "_kind" so consumers can tell the shapes apart (missing "_kind"
reads as code, keeping older cached reviews valid). Enum fields are clamped
to allowlists with cautious defaults so a hallucinated or injected value
cannot reach the posted event. The handbook distillation also captures the
dependency policy, though the prompt carries it regardless.
2026-07-01 19:46:15 -04:00
..
__init__.py Add pr-reviewer local PR review tool 2026-07-01 13:48:10 -04:00
config.py Ground reviews in the engineering-handbook 2026-07-01 17:08:21 -04:00
github_client.py Group PRs by repo in the sidebar and add auto-merge 2026-07-01 19:11:09 -04:00
handbook.py Assess Dependabot PRs for merge risk instead of code review 2026-07-01 19:46:15 -04:00
main.py Group PRs by repo in the sidebar and add auto-merge 2026-07-01 19:11:09 -04:00
reviewer.py Assess Dependabot PRs for merge risk instead of code review 2026-07-01 19:46:15 -04:00
store.py Group PRs by repo in the sidebar and add auto-merge 2026-07-01 19:11:09 -04:00
worker.py Group PRs by repo in the sidebar and add auto-merge 2026-07-01 19:11:09 -04:00