Apache-2.0 · The production source is public

The pull-request reviewer you can read before you trust it.

LlamaPReview reviews the exact head commit of a pull request using bounded, sourced evidence. The model supplies engineering judgment; deterministic code owns every boundary and every published byte — and all of it is open source.

Free for public repositories. Private repositories are never reviewed — their events are discarded before any storage or model call.

What a review actually says

Evidence-led, and explicit when the evidence runs out.

LlamaPReview — Blocking issues found

Do not merge until the nap instruction names the runnable driver path, matching the activation scheme this PR ships; currently the printed instruction tells agents to run summem, not .summem/summem.

Exact-head CI remains unresolved (1 pending); no CI-dependent merge-safety claim is made.

That second sentence is the point. When the evidence does not support a claim, the review declines to make it. Read this review in full on Texarkanine/SumMem#10, another on mmayasaurus/heddle#66, or read the output contract that defines what it will and will not publish.

Open source, actively

This is not a demo or a mirror. The public repository is the production source.

Read the reviewer before you trust it

The Webhook and Pipeline code in JetXu-LLM/LlamaPReview powers the official hosted service under the Apache-2.0 license.

  • Inspect how evidence is retrieved, bounded, and tied to an exact commit.
  • Trace the code-owned safety, accounting, recovery, and publication path.
  • Open an Issue, join a Discussion, or contribute a focused improvement.

Why it is different

Model judgment stays focused on engineering decisions. Code owns the boundaries that make the result safe to publish.

Evidence with boundaries

Every review uses a bounded set of public, exact-head evidence with provenance. Missing coverage is reported instead of guessed away.

Judgment and publication, separated

DeepSeek supplies engineering judgment. Deterministic code decides the public shape, safety, placement, and publication identity.

Pinned to the exact head

Admission, rereads, and publication bind to the same pull-request commit. Recovery reuses the prepared request instead of posting blindly.

How a review works

One production path, from a signed event to a review on the same verified head.

From a public pull request to a review you can audit: a signed public GitHub event, exact-head admission and bounded evidence, DeepSeek engineering judgment, deterministic projection and publication, and a public review from source you can run.
The model owns one step. Code owns the other four — and you can read all five.
1

Verify and admit

Verify the webhook signature, enforce the public-only boundary, and pin the exact pull-request head.

2

Retrieve evidence

Gather bounded repository evidence with provenance, coverage, and explicit gaps.

3

Judge and present

Use model judgment for causal engineering risk, then compress it into owner actions and placement requests.

4

Project and publish

Sanitize, place, account, recover, and publish idempotently to the exact head that was reviewed.

Privacy and trust, plainly

The hosted service reviews public repositories only. Its active source and data boundaries are inspectable.

Private events stop early

After signature verification and minimum visibility parsing, a private event is acknowledged and discarded before product storage, provider processing, or GitHub mutation.

Public-run retention is stated

Run records, artifacts, provider traces, and logs follow documented retention windows. Historical private records were not deleted.

Provider processing is disclosed

Selected public evidence, prompts, and output are sent to DeepSeek. Read the full privacy and retention details.

Join the project

Inspect the source, report a reproducible problem, or help sharpen what useful engineering judgment looks like.