# aicodereview.io > A directory and standard for AI code review tools. 27 tools are scored against 9 public engineering standards, with a source link and a verification date on every claim (last refresh 2026-08-11). Includes head-to-head comparisons, a 57-term glossary, long-form guides, and an engineer-written blog. Scoring formula, sources and editorial policy: https://aicodereview.io/methodology/. Scoring: each tool is rated on 9 standards as documented (1 point), partial (0.5), not offered (0) or undocumented (0). The total is the coverage score out of 9. It measures documented capability, not measured review quality. Every blog post is available as raw markdown by appending `.md` to its URL; the same applies to tool profiles and glossary terms. The full site content is in /llms-full.txt. ## Directory — tools ranked by documented coverage - [Cubic](https://aicodereview.io/tools/cubic/) — 7.5/9 · AI PR Review · proprietary · undocumented on self-hosting · AI code review for GitHub PRs plus scheduled whole-codebase bug scans, with local CLI review, custom agents, and issue checks. - [Augment Code](https://aicodereview.io/tools/augment-code/) — 6.5/9 · AI PR Review · proprietary · cloud-only · Code review agent in the Cosmos platform: risk-triaged inline PR comments with full-codebase context; GitHub-native, others via CLI. - [Baz](https://aicodereview.io/tools/baz/) — 6.5/9 · AI PR Review · proprietary · self-hostable only on an enterprise contract · Review platform running specialized agents (code, spec, security, merge) on GitHub, GitLab, and Azure DevOps PRs with sandbox execution. - [Kodus](https://aicodereview.io/tools/kodus/) — 6.5/9 · AI PR Review · open source (AGPL-3.0 (dual-licensed; enterprise-marked files commercial)) · fully self-hostable on a standard plan · Open-source AI code review built to run where the organization controls: self-hosted or cloud, models under your keys, org-wide Kody Rules. - [CodeAnt AI](https://aicodereview.io/tools/codeant/) — 6.5/9 · AI PR Review · proprietary · self-hostable only on an enterprise contract · PR reviewer with severity-ranked comments and one-click fixes across GitHub, GitLab, Bitbucket, and Azure DevOps, plus SAST scanning. - [Entelligence AI](https://aicodereview.io/tools/entelligence/) — 6.5/9 · AI PR Review · proprietary · fully self-hostable on a standard plan · Reviews PRs on GitHub, GitLab, and Bitbucket with codebase and team context, plus CLI pre-PR review and engineering metrics. - [CodeRabbit](https://aicodereview.io/tools/coderabbit/) — 6/9 · AI PR Review · proprietary · self-hostable only on an enterprise contract · Hosted AI PR reviewer with summaries, linter/SAST integration, and agentic chat across GitHub, GitLab, Azure DevOps, and Bitbucket. - [Semgrep](https://aicodereview.io/tools/semgrep/) — 4.5/9 · Security · open source (LGPL-2.1 (CE engine); AppSec Platform proprietary) · fully self-hostable on a standard plan · Open-source static analysis engine with a commercial AppSec Platform adding cross-file analysis and an AI assistant for triage. - [Greptile](https://aicodereview.io/tools/greptile/) — 4.5/9 · AI PR Review · proprietary · self-hostable only on an enterprise contract · AI code reviewer that indexes the whole codebase into a graph; its TREX agent writes and runs tests for PRs in a sandbox. - [Tabnine](https://aicodereview.io/tools/tabnine/) — 4.5/9 · AI PR Review · proprietary · fully self-hostable on a standard plan · Enterprise AI dev platform whose Code Review Agent checks PRs against plain-language team rules on GitHub, GitLab, and Bitbucket. - [SonarQube](https://aicodereview.io/tools/sonarqube/) — 4/9 · Code Quality · open source (LGPL-3.0 (Community Build); commercial editions proprietary) · fully self-hostable on a standard plan · Deterministic static analysis platform (Server and Cloud) with PR decoration and LLM-generated AI CodeFix suggestions. - [Codacy](https://aicodereview.io/tools/codacy/) — 4/9 · Code Quality · proprietary · cloud-only · Code-quality platform covering 49 languages and 12,000+ static rules, SAST, secrets, SCA, and IaC, with an AI review layer on top. - [Qodana](https://aicodereview.io/tools/qodana/) — 3.5/9 · Static Analysis · proprietary · fully self-hostable on a standard plan · JetBrains' static analysis for CI, running IDE inspections in pipelines with quality gates, baselines, and cloud reports. - [Qodo](https://aicodereview.io/tools/qodo/) — 3.5/9 · AI PR Review · proprietary · self-hostable only on an enterprise contract · AI platform spanning IDE assistant, CLI, and Qodo Merge PR review with test generation; enterprise on-prem and air-gapped options. - [Gemini Code Assist](https://aicodereview.io/tools/gemini-code-assist/) — 3/9 · AI PR Review · proprietary · cloud-only · Google's coding assistant whose GitHub app auto-reviews pull requests with severity-ranked comments and committable fixes. - [OpenReview](https://aicodereview.io/tools/openreview/) — 3/9 · AI PR Review · proprietary · fully self-hostable on a standard plan · Vercel Labs' self-hosted GitHub review bot: mention @openreview for Claude-powered inline suggestions; dormant beta since March 2026. - [Snyk Code](https://aicodereview.io/tools/snyk-code/) — 3/9 · Security · proprietary · self-hostable only on an enterprise contract · Developer-focused SAST built on Snyk's DeepCode AI engine, with PR checks and AI fix suggestions across major git platforms. - [Aikido Security](https://aicodereview.io/tools/aikido/) — 2.5/9 · Security · proprietary · self-hostable only on an enterprise contract · All-in-one AppSec platform (SAST, SCA, secrets, cloud) with AI autotriage and autofix PRs, built on tuned open-source scanners. - [Cursor BugBot](https://aicodereview.io/tools/cursor-bugbot/) — 2.5/9 · AI PR Review · proprietary · cloud-only · Cursor's PR reviewer scoped to bugs, security issues, and rule violations, billed per run (avg $1.00-1.50) since June 2026. - [PR-Agent](https://aicodereview.io/tools/pr-agent/) — 2.5/9 · AI PR Review · open source (MIT) · fully self-hostable on a standard plan · Community-maintained, MIT-licensed PR reviewer with /review, /describe, and /improve commands, self-hosted with your own model keys. - [Bito](https://aicodereview.io/tools/bito/) — 2.5/9 · AI PR Review · proprietary · undocumented on self-hosting · AI Code Review Agent for GitHub, GitLab, and Bitbucket with repo-aware reviews, custom guidelines, Jira integration, and analytics. - [GitHub Copilot code review](https://aicodereview.io/tools/github-copilot-code-review/) — 2/9 · AI PR Review · proprietary · cloud-only · Pull request review bundled into paid GitHub Copilot plans; reviews the diff with instructions-file customization, metered by AI credits. - [Sourcery](https://aicodereview.io/tools/sourcery/) — 1.5/9 · AI PR Review · proprietary · self-hostable only on an enterprise contract · AI reviewer for GitHub and GitLab with line-by-line reviews, summaries and diagrams, custom rules, and BYO-LLM on its Team tier. - [DeepSource](https://aicodereview.io/tools/deepsource/) — 1.5/9 · Code Quality · proprietary · self-hostable only on an enterprise contract · Static-analysis platform (quality, coverage, secrets) with Autofix and a metered AI Review add-on; free for open-source repos. - [Panto](https://aicodereview.io/tools/panto/) — 1.5/9 · AI PR Review · proprietary · self-hostable only on an enterprise contract · AI code reviewer with 30,000+ security checks, IaC and secrets scanning, and business context pulled from Jira and Confluence. - [What The Diff](https://aicodereview.io/tools/what-the-diff/) — 1/9 · AI PR Review · proprietary · cloud-only · Writes PR descriptions from the diff, sends changelog notifications to stakeholders, and does small /wtd refactors on GitHub and GitLab. - [Graphite](https://aicodereview.io/tools/graphite/) — 1/9 · AI PR Review · proprietary · cloud-only · Code review platform built around stacked PRs, with an AI reviewer (formerly Diamond), merge queue, and review automation for GitHub. ## The 9 standards - [Multi-dimensional Context](https://aicodereview.io/standards/01-multi-dimensional-context/): AI that reads only the git diff is useless for architecture and generates hallucinations. Context must be multi-repo and hierarchical. - [Rule-Centric & Default Quiet](https://aicodereview.io/standards/02-rule-centric/): AIs that impose their own opinions on code style generate alert fatigue and are quickly ignored. Code Review in the PR must be Default Quiet. - [Dual-Workflow: Local vs. PR](https://aicodereview.io/standards/03-dual-workflow/): Fixing architecture in the PR is too late and too expensive. Treating the IDE and the PR as the exact same environment is a design flaw. - [Business Logic Validation](https://aicodereview.io/standards/04-business-logic/): Validating if the code compiles is the easy part. The AI needs to know if the code meets the business requirements. - [Continuous Learning](https://aicodereview.io/standards/05-continuous-learning/): Having to correct the bot for the exact same mistake three times in a row destroys team trust in the tool. - [Sandbox Validation](https://aicodereview.io/standards/06-sandbox-validation/): Ability to test the suggested code in Sandbox or Preview Environments. The AI must be able to perform Chaos Testing. - [Economic Transparency](https://aicodereview.io/standards/07-economic-transparency/): You must have the freedom to choose which model to use. The tool's business model cannot be to profit off token usage. - [Actionability](https://aicodereview.io/standards/08-actionability/): If an AI points out a problem, it has the obligation to generate the exact code to fix it. Do not explain the problem, show me the commit. - [Measurable ROI](https://aicodereview.io/standards/09-measurable-roi/): Code is business. A production-grade tool must actively track its impact on DORA metrics and mathematically prove its Return on Investment. ## Head-to-head comparisons - [Augment Code vs CodeRabbit](https://aicodereview.io/compare/augment-code-vs-coderabbit/) - [Augment Code vs Kodus](https://aicodereview.io/compare/augment-code-vs-kodus/) - [Baz vs CodeRabbit](https://aicodereview.io/compare/baz-vs-coderabbit/) - [Baz vs Kodus](https://aicodereview.io/compare/baz-vs-kodus/) - [Bito vs CodeRabbit](https://aicodereview.io/compare/bito-vs-coderabbit/) - [Bito vs Kodus](https://aicodereview.io/compare/bito-vs-kodus/) - [CodeAnt AI vs CodeRabbit](https://aicodereview.io/compare/codeant-vs-coderabbit/) - [CodeAnt AI vs Kodus](https://aicodereview.io/compare/codeant-vs-kodus/) - [CodeRabbit vs Cubic](https://aicodereview.io/compare/coderabbit-vs-cubic/) - [CodeRabbit vs Cursor BugBot](https://aicodereview.io/compare/coderabbit-vs-cursor-bugbot/) - [CodeRabbit vs Entelligence AI](https://aicodereview.io/compare/coderabbit-vs-entelligence/) - [CodeRabbit vs Gemini Code Assist](https://aicodereview.io/compare/coderabbit-vs-gemini-code-assist/) - [CodeRabbit vs GitHub Copilot code review](https://aicodereview.io/compare/coderabbit-vs-github-copilot-code-review/) - [CodeRabbit vs Graphite](https://aicodereview.io/compare/coderabbit-vs-graphite/) - [CodeRabbit vs Kodus](https://aicodereview.io/compare/coderabbit-vs-kodus/) - [CodeRabbit vs OpenReview](https://aicodereview.io/compare/coderabbit-vs-openreview/) - [CodeRabbit vs Panto](https://aicodereview.io/compare/coderabbit-vs-panto/) - [CodeRabbit vs PR-Agent](https://aicodereview.io/compare/coderabbit-vs-pr-agent/) - [CodeRabbit vs Qodo](https://aicodereview.io/compare/coderabbit-vs-qodo/) - [CodeRabbit vs Sourcery](https://aicodereview.io/compare/coderabbit-vs-sourcery/) - [CodeRabbit vs Tabnine](https://aicodereview.io/compare/coderabbit-vs-tabnine/) - [CodeRabbit vs What The Diff](https://aicodereview.io/compare/coderabbit-vs-what-the-diff/) - [Cubic vs Kodus](https://aicodereview.io/compare/cubic-vs-kodus/) - [Cursor BugBot vs GitHub Copilot code review](https://aicodereview.io/compare/cursor-bugbot-vs-github-copilot-code-review/) - [Cursor BugBot vs Greptile](https://aicodereview.io/compare/cursor-bugbot-vs-greptile/) - [Cursor BugBot vs Kodus](https://aicodereview.io/compare/cursor-bugbot-vs-kodus/) - [Cursor BugBot vs Qodo](https://aicodereview.io/compare/cursor-bugbot-vs-qodo/) - [Entelligence AI vs Kodus](https://aicodereview.io/compare/entelligence-vs-kodus/) - [Gemini Code Assist vs Kodus](https://aicodereview.io/compare/gemini-code-assist-vs-kodus/) - [GitHub Copilot code review vs Greptile](https://aicodereview.io/compare/github-copilot-code-review-vs-greptile/) - [GitHub Copilot code review vs Kodus](https://aicodereview.io/compare/github-copilot-code-review-vs-kodus/) - [GitHub Copilot code review vs Qodo](https://aicodereview.io/compare/github-copilot-code-review-vs-qodo/) - [Graphite vs Kodus](https://aicodereview.io/compare/graphite-vs-kodus/) - [Greptile vs Kodus](https://aicodereview.io/compare/greptile-vs-kodus/) - [Greptile vs Qodo](https://aicodereview.io/compare/greptile-vs-qodo/) - [Kodus vs OpenReview](https://aicodereview.io/compare/kodus-vs-openreview/) - [Kodus vs Panto](https://aicodereview.io/compare/kodus-vs-panto/) - [Kodus vs PR-Agent](https://aicodereview.io/compare/kodus-vs-pr-agent/) - [Kodus vs Qodo](https://aicodereview.io/compare/kodus-vs-qodo/) - [Kodus vs Sourcery](https://aicodereview.io/compare/kodus-vs-sourcery/) - [Kodus vs Tabnine](https://aicodereview.io/compare/kodus-vs-tabnine/) - [Kodus vs What The Diff](https://aicodereview.io/compare/kodus-vs-what-the-diff/) ## Guides - [What is code review? A practical guide for engineering teams](https://aicodereview.io/learn/what-is-code-review/): What code review is actually for, the forms it takes, what the research says it catches, and how to tell whether yours is working — before you spend anything on tooling. - [Designing a code review process that survives a growing team](https://aicodereview.io/learn/code-review-process/): How to define scope, routing, response times and escalation so review stays useful past twenty engineers — and which parts to automate as you grow. - [A code review checklist that reviewers actually use](https://aicodereview.io/learn/code-review-checklist/): What to look for in a review, in priority order — correctness, security, design, tests, operability — and which items to hand to automation instead. - [Code review metrics worth tracking (and the ones that mislead)](https://aicodereview.io/learn/code-review-metrics/): Which review measurements predict outcomes, how to baseline them before buying tooling, and why comments-per-PR and lines-of-code will send you the wrong way. - [Security code review: what to check, and what to automate](https://aicodereview.io/learn/code-review-security/): Which vulnerability classes review catches that scanners miss, how to scope security review by risk, and where SAST, dependency scanning and AI review each earn their place. - [Code review at scale: monorepos, many teams, and thousands of pull requests](https://aicodereview.io/learn/code-review-at-scale/): What breaks when review grows past one team — routing, latency, ownership, tooling cost — and the structural fixes that hold at a few hundred engineers. - [How to review the growing volume of AI-generated code](https://aicodereview.io/learn/reviewing-ai-generated-code/): Coding agents produce more code than human reviewers can read. What actually changes about review, which failure modes are new, and how to keep a quality bar without becoming the bottleneck. - [How to reduce pull request review time (without reviewing less)](https://aicodereview.io/learn/reducing-pr-review-time/): Where review time actually goes, which interventions move it, and how to baseline the numbers before you buy anything. The fixes ranked by how much they return. - [Reviewing large and complex pull requests](https://aicodereview.io/learn/reviewing-large-pull-requests/): Why big diffs defeat both human reviewers and AI tools, how to review one when splitting is not an option, and what to check in a tool if large changes are normal for your team. - [Code review in a monorepo: what breaks and what to fix](https://aicodereview.io/learn/code-review-monorepo/): Ownership, routing, CI scope and tooling limits in a monorepo — the failures that only appear at scale, and what to test before buying a reviewer for one. ## Filtered views - [Self-hosted AI code review tools](https://aicodereview.io/tools/self-hosted/) - [Open-source AI code review tools](https://aicodereview.io/tools/open-source/) - [AI PR Review tools](https://aicodereview.io/tools/category/ai-pr-review/) - [Security tools](https://aicodereview.io/tools/category/security/) - [Code Quality tools](https://aicodereview.io/tools/category/code-quality/) - [Static Analysis tools](https://aicodereview.io/tools/category/static-analysis/) - [AI code review tools for GitHub](https://aicodereview.io/tools/platform/github/): the 27 tools documenting GitHub support. - [AI code review tools for GitLab](https://aicodereview.io/tools/platform/gitlab/): the 22 tools documenting GitLab support. - [AI code review tools for Bitbucket](https://aicodereview.io/tools/platform/bitbucket/): the 18 tools documenting Bitbucket support. - [AI code review tools for Azure DevOps](https://aicodereview.io/tools/platform/azure-devops/): the 15 tools documenting Azure DevOps support. - [AI code review tools for Forgejo](https://aicodereview.io/tools/platform/forgejo/): the 1 tools documenting Forgejo support. - [AI code review tools for Gitea](https://aicodereview.io/tools/platform/gitea/): the 1 tools documenting Gitea support. - [Readiness assessment](https://aicodereview.io/assessment/): score your own setup against the 9 standards. - [Methodology and funding](https://aicodereview.io/methodology/) ## Blog — Comparisons - [Free AI Code Review Tools: What "Free" Actually Costs You](https://aicodereview.io/blog/free-ai-code-review-tools-what-free-actually-costs-you/): A hands-on look at what "free" really means across AI code review tools — metered credits, trials, BYO-LLM, and how to evaluate them. - [Pullfrog vs CodeRabbit: don't compare the wrong thing](https://aicodereview.io/blog/pullfrog-vs-coderabbit-dont-compare-the-wrong-thing/): Pullfrog is a BYOK harness over Claude Code and Codex, not a first-party reviewer like CodeRabbit. Review quality is model-attributed, not harness-attributed. Here's what actually separates them. - [Pullfrog vs CodeRabbit: what a BYOK bot actually changes for AI code review](https://aicodereview.io/blog/pullfrog-vs-coderabbit-what-a-byok-bot-actually-changes-for-ai-code-review/): An eval-grounded look at Pullfrog vs CodeRabbit: when a reviewer wraps Claude Code or Codex, review quality is model-attributed, not harness-attributed. The real difference is the credential boundary. - [## Start with the harness, not the feature list Every "X vs CodeRabbit" post li](https://aicodereview.io/blog/pullfrog-vs-coderabbit-the-harness-not-the-model-is-the-review/): Comparing Pullfrog and CodeRabbit properly means separating the reviewer harness from the underlying model, not just lining up features. - [AI code review across many repos: what to actually compare](https://aicodereview.io/blog/ai-code-review-across-many-repos-what-to-actually-compare/): Eval-grounded guide to comparing AI code review tools for large multi-repo teams, on context-fetching, verification, and permission boundary. - [How to evaluate AI review tools for multi-repo teams: an eval-based protocol](https://aicodereview.io/blog/how-to-evaluate-ai-review-tools-for-multi-repo-teams-an-eval-based-protocol/): Stop comparing marketing claims. An eval-based protocol for picking AI code review tools across many repositories: cross-repo context, verification, permission boundaries. - [AI code review for large multi-repo teams: what actually scales](https://aicodereview.io/blog/ai-code-review-for-large-multi-repo-teams-what-actually-scales/): Eval-grounded comparison of AI code review tools for large teams with many repositories: cross-repo context, verification, permission boundary. - [Netlify tested 11 coding models side by side](https://aicodereview.io/blog/netlify-tested-11-coding-models-side-by-side/): Netlify ran the same build prompt across 11 AI models using their open-source AXIS evaluator. Here is what the results tell us about model selection for code generation. - [CodeRabbit vs Greptile: Which to Pick in 2026](https://aicodereview.io/blog/coderabbit-vs-greptile/): CodeRabbit vs Greptile head-to-head: context models, review quality, pricing, self-hosting, and when to pick each. Verified August 2026. - [Cursor BugBot vs CodeRabbit: 2026 Comparison](https://aicodereview.io/blog/cursor-bugbot-vs-coderabbit/): Cursor BugBot vs CodeRabbit: review philosophy, pricing, platform support, and self-hosting compared — plus when neither fits. Verified August 2026. ## Blog — Guides - [AI code review that follows YOUR coding rules: how to evaluate custom-standards support](https://aicodereview.io/blog/ai-code-review-that-follows-your-coding-rules-how-to-evaluate-custom-standards-s/): Most AI reviewers catch generic bugs. Whether one will follow your team's own coding rules is a separate question. Here's how to evaluate custom-standards support before you buy. - [Reduce Pull Request Review Time With AI: A Reproducible Protocol](https://aicodereview.io/blog/reduce-pull-request-review-time-with-ai-a-reproducible-protocol/): Ask the right question: AI review tools cut how long PRs WAIT, not much how long they take to READ. Plus a two-week PR-slice protocol. - [Your AI reviewer is judging its own output. That's a blind spot](https://aicodereview.io/blog/your-ai-reviewer-is-judging-its-own-output-thats-a-blind-spot/): Teams drowning in AI-generated code often let an LLM review the LLM's own patches. Amazon's judge-correlation work shows why that misses real defects. - [Reduce PR review time with AI: what the 45% claim leaves out](https://aicodereview.io/blog/reduce-pr-review-time-with-ai-what-the-45-claim-leaves-out/): Atlassian says Rovo cut PR cycle time 45%. The number is real but self-attested. Here's how to measure whether AI actually reduces your review time. - [Who reviews the AI-generated code before the human does?](https://aicodereview.io/blog/who-reviews-the-ai-generated-code-before-the-human-does/): The volume of AI-generated code is rising faster than review capacity. The fix starts in evaluation design: don't let the model that wrote the code also judge it. - [Reviewing the surge in AI-generated code: what scales and what breaks](https://aicodereview.io/blog/reviewing-the-surge-in-ai-generated-code-what-scales-and-what-breaks/): AI is producing more code than teams can review. First-party data on why the old loop breaks (Salesforce, DORA) and what actually scales. - [Reviewing the volume of AI-generated code: the problem is routing, not speed](https://aicodereview.io/blog/reviewing-the-volume-of-ai-generated-code-the-problem-is-routing-not-speed/): AI made PRs smaller but much more numerous. Reviewing the volume isn't a per-PR speed problem, it's a routing problem. Here's how teams actually triage AI-generated code. - [How to Actually Evaluate an AI Code Review Tool](https://aicodereview.io/blog/how-to-actually-evaluate-an-ai-code-review-tool/): The failure mode that matters in AI review is not missing a bug, it is fluent output that is structurally wrong and easy to trust. How to benchmark for it. - [AI code review benchmarks: offline vs online evals](https://aicodereview.io/blog/ai-code-review-benchmarks-offline-vs-online-evals/): How Martian's Code Review Bench separates reproducible fixed-dataset evals from streaming real-world evals, and the tradeoffs hidden in each. - [How to Evaluate AI Code Review Tools (2026): A Playbook](https://aicodereview.io/blog/how-to-evaluate-ai-code-review-tools/): A practical playbook for how to evaluate AI code review tools: a 9-standard scoring rubric, red flags, a 2-week trial protocol, and vendor questions. - [Open Source AI Code Review: The Real Options (2026)](https://aicodereview.io/blog/open-source-ai-code-review-tools/): Open source AI code review tools compared: Kodus (AGPL), PR-Agent (MIT), and more — real licenses, BYOK costs, and how they stack up against closed SaaS. - [Self-Hosted AI Code Review: Options & Trade-Offs (2026)](https://aicodereview.io/blog/self-hosted-ai-code-review/): Self-hosted AI code review explained: full-stack vs BYOK vs on-prem runners, verified vendor options, and what deployment really costs in 2026. ## Blog — Alternatives - [Qodo Merge alternatives: pick the model, not the wrapper](https://aicodereview.io/blog/qodo-merge-alternatives-pick-the-model-not-the-wrapper/): Qodo folded PR-Agent/Merge into one platform. For teams comparing alternatives, the real question is which model + harness you're actually betting on. - [CodeRabbit Alternatives: 7 Tools Compared (2026)](https://aicodereview.io/blog/coderabbit-alternatives/): Why teams leave CodeRabbit and 7 alternatives compared — Kodus, Greptile, Qodo, BugBot, Copilot, Graphite, Panto. Pricing verified August 2026. ## Blog — Explainers - [AI code review reads the patch, not the execution](https://aicodereview.io/blog/ai-code-review-reads-the-patch-not-the-execution/): When AI writes 30% of your lines, patch-text review hits a ceiling. The fix is an execution layer, not a bigger reviewer. - [Reproducing zizmor's flag on the Snowflake injection](https://aicodereview.io/blog/reproducing-zizmors-flag-on-the-snowflake-injection/): I ran zizmor 1.29.0 against the exact Snowflake GitHub Actions workflow. A deterministic static rule flagged the injection at High confidence while AI review cleared it. - [AI Code Review Statistics (2026): Sourced Data](https://aicodereview.io/blog/ai-code-review-statistics/): AI code review statistics for 2026: adoption, trust, review turnaround, AI code volume, and bug-catch benchmarks — every stat linked to a primary source. - [AI Code Review vs Static Analysis: 2026 Guide](https://aicodereview.io/blog/ai-code-review-vs-static-analysis/): AI code review vs static analysis compared: determinism vs reasoning, false positives, SAST coverage, cost, and why mature teams run both. - [What Is AI Code Review? How It Works (2026)](https://aicodereview.io/blog/what-is-ai-code-review/): AI code review explained: how LLM reviewers work, what they catch and miss, how they differ from linters and static analysis, plus sourced adoption data. ## Blog — Best Of - [Best AI Code Review Tools (2026): 12 Tools Compared](https://aicodereview.io/blog/best-ai-code-review-tools/): The best AI code review tools 2026 offers, compared honestly: Kodus, CodeRabbit, Greptile, Copilot and more — context depth, pricing, self-hosting. ## Glossary - [Agentic AI](https://aicodereview.io/glossary/agentic-ai/): A model given tools and a loop — it can run commands, read files, and act on the results across several steps, instead of producing one answer from one prompt. - [AI code review](https://aicodereview.io/glossary/ai-code-review/): Using a large language model to read a proposed code change and leave findings on it, the way a human reviewer would — as a complement to human review, not a replacement for it. - [Alert fatigue](https://aicodereview.io/glossary/alert-fatigue/): What happens when a tool produces more findings than a team can process, so the team stops processing any of them — including the true ones. - [Blast radius](https://aicodereview.io/glossary/blast-radius/): How much of a system a given change can affect if it is wrong — the practical measure of how carefully it should be reviewed. - [Blocking comment](https://aicodereview.io/glossary/blocking-comment/): A review comment that must be resolved before a change can merge, as opposed to a suggestion the author can acknowledge and move past. - [Branch protection](https://aicodereview.io/glossary/branch-protection/): Rules on a branch that constrain how changes land — required reviews, required status checks, restrictions on force-push and direct commits. - [BYOK (bring your own key)](https://aicodereview.io/glossary/byok/): A model where you supply your own LLM provider credentials, so inference is billed directly to your account instead of being resold by the tool vendor. - [Change failure rate](https://aicodereview.io/glossary/change-failure-rate/): The share of deployments that cause a degraded service — a rollback, a hotfix, an incident — one of the four DORA metrics. - [CI/CD](https://aicodereview.io/glossary/ci-cd/): Continuous integration and continuous delivery: automatically building and testing every change, and keeping it in a state where it can be released. - [Code churn](https://aicodereview.io/glossary/code-churn/): How often a piece of code is rewritten shortly after being written — a signal of unstable requirements or unclear design, not of productivity. - [Code coverage](https://aicodereview.io/glossary/code-coverage/): The percentage of code executed by the test suite — a measure of what is tested, not of how well it is tested. - [Code duplication](https://aicodereview.io/glossary/code-duplication/): The same or near-identical logic existing in more than one place, so a change has to be made more than once to be made correctly. - [Code owner](https://aicodereview.io/glossary/code-owner/): The person or team automatically requested for review on a given path, usually declared in a CODEOWNERS file at the repository root. - [Code review](https://aicodereview.io/glossary/code-review/): The practice of having a change read by someone other than its author before it lands, to catch defects, spread knowledge, and hold a shared standard for the codebase. - [Code smell](https://aicodereview.io/glossary/code-smell/): A surface pattern that suggests a deeper design problem — not a bug, but a signal worth investigating. - [Cognitive complexity](https://aicodereview.io/glossary/cognitive-complexity/): A measure of how hard code is for a human to follow, weighting nesting and interrupted flow more heavily than raw branch count. - [Context window](https://aicodereview.io/glossary/context-window/): The maximum amount of text — code, instructions, conversation — a model can consider in a single request, measured in tokens. - [CVE](https://aicodereview.io/glossary/cve/): Common Vulnerabilities and Exposures: a public identifier for a specific known vulnerability in a specific product, in the form CVE-YYYY-NNNNN. - [CWE](https://aicodereview.io/glossary/cwe/): Common Weakness Enumeration: a catalogue of the categories of software flaw — the class of mistake, rather than a specific instance of it. - [Cycle time](https://aicodereview.io/glossary/cycle-time/): How long a change takes to get from started to shipped — usually first commit to production, and the number most teams feel most directly. - [Cyclomatic complexity](https://aicodereview.io/glossary/cyclomatic-complexity/): A count of the independent paths through a piece of code — effectively the number of branch points plus one. - [DAST](https://aicodereview.io/glossary/dast/): Dynamic application security testing: probing a running application from the outside with crafted requests, to find vulnerabilities that only appear at runtime. - [Defect escape rate](https://aicodereview.io/glossary/defect-escape-rate/): The proportion of defects that reach production instead of being caught by review, tests or staging. - [Deployment frequency](https://aicodereview.io/glossary/deployment-frequency/): How often a team successfully releases to production — a DORA metric, and a proxy for how small and safe its changes are. - [Diff](https://aicodereview.io/glossary/diff/): The line-by-line difference between two versions of a file — what a reviewer sees, and the minimum context most AI review tools work from. - [DORA metrics](https://aicodereview.io/glossary/dora-metrics/): Four measures of software delivery performance — deployment frequency, lead time for changes, change failure rate and time to restore service — from the DevOps Research and Assessment programme. - [Embeddings](https://aicodereview.io/glossary/embeddings/): Numeric vectors that represent text or code, so that similar things sit close together — the mechanism behind most codebase search in review tools. - [False positive](https://aicodereview.io/glossary/false-positive/): A finding that is reported but is not a real problem — the single biggest driver of whether a review tool survives contact with a team. - [Hallucination](https://aicodereview.io/glossary/hallucination/): A model stating something false with the same confidence it states something true — in code review, typically a bug report about code that does not exist or behaviour the code does not have. - [Inference cost](https://aicodereview.io/glossary/inference-cost/): What it costs to run the model behind a review — the underlying spend that every pricing model in this category is a wrapper around. - [Lead time for changes](https://aicodereview.io/glossary/lead-time-for-changes/): The time from a change being committed to that change running in production — one of the four DORA metrics. - [Linter](https://aicodereview.io/glossary/linter/): A tool that checks source code against a fixed set of rules — style, correctness patterns, suspicious constructs — deterministically and fast. - [MCP (Model Context Protocol)](https://aicodereview.io/glossary/mcp/): An open protocol for connecting models to external tools and data sources through a common interface, instead of a bespoke integration per system. - [Merge queue](https://aicodereview.io/glossary/merge-queue/): A system that serialises merges, testing each change against the current tip of the main branch before it lands, so green pull requests cannot break the branch on arrival. - [Model routing](https://aicodereview.io/glossary/model-routing/): Choosing which model handles which part of a review — a cheap fast model for triage, a stronger one for deep reasoning — instead of sending everything to one model. - [Monorepo](https://aicodereview.io/glossary/monorepo/): A single repository holding many projects or services, with one history and usually one build system. - [MTTR](https://aicodereview.io/glossary/mttr/): Mean time to restore: how long it takes to recover service after a failure in production — the fourth DORA metric. - [Nitpick](https://aicodereview.io/glossary/nitpick/): A review comment about something trivial — naming, formatting, ordering — that is technically valid and rarely worth the author's attention. - [Open source](https://aicodereview.io/glossary/open-source/): Software whose source code is published under a licence that permits reading, modifying and redistributing it — which is a licensing property, not a deployment one. - [OWASP Top 10](https://aicodereview.io/glossary/owasp-top-10/): A periodically updated list of the ten most critical web application security risk categories, published by the Open Worldwide Application Security Project. - [Pre-commit hook](https://aicodereview.io/glossary/pre-commit-hook/): A script that runs on a developer's machine before a commit is created, blocking it if a check fails. - [Prompt injection](https://aicodereview.io/glossary/prompt-injection/): An attack where text the model reads — a comment, a README, a pull request description — carries instructions the model follows as if they came from you. - [Pull request](https://aicodereview.io/glossary/pull-request/): A proposal to merge one branch into another, with a diff, a description and a discussion thread — the unit of work most review and AI review tooling operates on. - [RAG (retrieval-augmented generation)](https://aicodereview.io/glossary/rag/): Fetching relevant material from a repository or knowledge base and putting it into the model's prompt, so the answer is grounded in your code rather than in the model's memory. - [Review coverage](https://aicodereview.io/glossary/review-coverage/): The share of changes that actually received a meaningful review before merging — as opposed to the share that received an approval. - [Review latency](https://aicodereview.io/glossary/review-latency/): The time between a pull request being ready and a reviewer responding to it — usually the largest single component of cycle time. - [Sandbox validation](https://aicodereview.io/glossary/sandbox-validation/): Running or testing a proposed change in an isolated environment to confirm a finding is real, instead of only reasoning about it. - [SAST](https://aicodereview.io/glossary/sast/): Static application security testing: scanning source code for vulnerability patterns — injection, unsafe deserialisation, hardcoded credentials — without running the application. - [SCA (software composition analysis)](https://aicodereview.io/glossary/sca/): Scanning a project's dependencies for known vulnerabilities and licence obligations, by matching the dependency tree against vulnerability databases. - [Secret scanning](https://aicodereview.io/glossary/secret-scanning/): Detecting credentials — API keys, tokens, private keys, connection strings — committed into source control or present in a proposed change. - [Self-hosting](https://aicodereview.io/glossary/self-hosting/): Running a tool on infrastructure you control, so the code it analyses stays inside your network boundary rather than passing through a vendor's cloud. - [Shift left](https://aicodereview.io/glossary/shift-left/): Moving quality and security checks earlier in the development process, where problems are cheaper to find and fix. - [Signal-to-noise ratio](https://aicodereview.io/glossary/signal-to-noise/): The proportion of a tool's findings that a team acts on — the practical measure of whether a code review tool is worth keeping. - [Static analysis](https://aicodereview.io/glossary/static-analysis/): Analysing source code without running it, using parsers and rules rather than execution — the deterministic half of automated code review. - [Supply chain attack](https://aicodereview.io/glossary/supply-chain-attack/): Compromising software by attacking something it depends on — a package, a build step, a maintainer account — rather than the application itself. - [Technical debt](https://aicodereview.io/glossary/technical-debt/): The future cost of a shortcut taken now — deliberate or accidental — expressed as the extra work every later change has to carry. - [Token](https://aicodereview.io/glossary/token/): The unit language models read, write and bill in — roughly three-quarters of a word, or a few characters of code.