PASS
No high-confidence blocker was found in the available patch. Read any scope or coverage limitations.
GETTING STARTED / GITHUB
Start with one repository and one change. See what was reviewed, understand the open questions, and keep the final decision with your team.
Updated
From your repository to a human decision.
01 / CONNECT
Repository access remains controlled by GitHub. Start with a repository your team is authorized to connect.
02 / REVIEW
codlab-ai[bot] comment and the CodeCR Review check.A passing automated review is not proof that a change is safe. Consider its scope and limitations alongside tests and human review.
03 / DECIDE
No high-confidence blocker was found in the available patch. Read any scope or coverage limitations.
Findings need a human decision. Inspect the cited lines and suggested action.
A deterministic high- or critical-severity rule identified a merge-blocking risk.
The current GitHub integration returns a failing check only for deterministic BLOCKING findings. Advisory AI findings and a REVIEW result do not by themselves fail the CodLab check. GitHub prevents merging only when your branch rules require that check and it is not bypassed. Configure required human reviews separately.
AI findings remain advisory evidence for reviewers. Inspect separate rule, AI and context coverage; malformed or unavailable analysis cannot establish a clean change. CodLab does not grant human approval or override repository permissions.
FIX / APPROVAL FIRST
If publication reporting fails, GitHub may already contain the approved commit. Check GitHub before starting a second fix.
SECURITY / IMPACT
Security sections label observations, inferences, and proposed hardening. Blast-radius analysis includes supplied changed paths and bounded static JS/TS imports, callers, aliases, re-exports and relevant tests at the reviewed commit. Select a file to inspect its source relationships. It does not establish a complete dependency graph, runtime permissions or production deployment reach.
Skipped or unavailable checks never count as passes. An evidence score measures available context, not merge safety. Explore a synthetic sample report.
04 / SCOPE
Repository owners can use .codecr.yml to configure the review file limit, minimum reported severity, and ignored paths. The GitHub App considers the first 100 changed-file entries and applies a configured limit of 30 files by default, up to 100.
Reviews analyze bounded patches, not the full codebase: up to 20,000 characters per available patch, and up to 60,000 combined patch characters for the AI pass. Ignored files and files without a patch are outside the analyzed scope.
Policy is loaded from the trusted immutable pull-request base. A proposed policy change does not weaken the policy used to review itself.
The public review tool has a separate limit of 30 files and accepts public GitHub pull-request URLs. Use the connected workspace for repositories authorized through the GitHub App.
05 / ACCESS
Select Add repositories in the workspace to change the GitHub App’s repository access. Then sign in again or choose Sync from GitHub to refresh the workspace.
For missing repositories or a review that needs attention, follow the support guide. Include the evidence ID and approximate time when using your agreed support channel.
06 / SECURITY & DATA
See Security for the published security model. The hosted data map distinguishes raw patches processed for review, retained finding excerpts and structured reports, and temporary old/proposed fix content. Proposal expiry and administrator preview-and-apply retention have different scopes. The optional pilot notice covers its separate contact and email workflow.