# How to Integrate code-review-graph with Your CI/CD Pipeline

> Learn how to integrate code-review-graph with your CI/CD pipeline using GitHub Actions or a Python script. Streamline your code review process effectively.

- Repository: [Tirth Kanani/code-review-graph](https://github.com/tirth8205/code-review-graph)
- Tags: how-to-guide
- Published: 2026-08-17

---

**You can integrate code-review-graph into your CI/CD pipeline by using its built-in GitHub Action for GitHub repositories, or by running the [`scripts/render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py) helper script directly in any CI system that supports Docker or Python.**

The **code-review-graph** project from `tirth8205/code-review-graph` is a Python-based static-analysis engine that constructs a knowledge graph of your repository, performs impact analysis on pull request changes, and automatically generates review comments. This guide walks through the exact implementation steps, source file references, and configuration options needed to deploy it in production.

## How the CI Integration Works

The pipeline consists of five discrete stages orchestrated by [`scripts/render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py):

| Stage | Function | Source File |
|-------|----------|-------------|
| Checkout & Setup | Installs dependencies declared in [`pyproject.toml`](https://github.com/tirth8205/code-review-graph/blob/main/pyproject.toml) | [[`pyproject.toml`](https://github.com/tirth8205/code-review-graph/blob/main/pyproject.toml)](https://github.com/tirth8205/code-review-graph/blob/main/pyproject.toml) |
| Graph Construction | `code_review_graph.graph.build()` parses imports and builds a directed symbol graph | [[`code_review_graph/graph.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py)](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py) |
| Impact Analysis | `code_review_graph.flows.analyze()` computes affected files and functions | [[`code_review_graph/flows.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/flows.py)](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/flows.py) |
| Comment Generation | Converts analysis output to markdown review comments | [[`scripts/render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py)](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py) |
| Post to PR | Uses `GITHUB_TOKEN` or equivalent to publish the comment | [[`action.yml`](https://github.com/tirth8205/code-review-graph/blob/main/action.yml)](https://github.com/tirth8205/code-review-graph/blob/main/action.yml) |

The entire execution completes in under one minute for medium-sized repositories, making it suitable to run on every PR without pipeline slowdown.

## GitHub Actions Integration

The fastest way to integrate code-review-graph with your CI/CD pipeline is the ready-made GitHub Action.

### Complete Workflow Configuration

Create [`.github/workflows/code-review-graph.yml`](https://github.com/tirth8205/code-review-graph/blob/main/.github/workflows/code-review-graph.yml) in your repository:

```yaml
name: Code Review Graph

on:
  pull_request:
    types: [opened, synchronize, reopened]

jobs:
  analyze:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      pull-requests: write
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - uses: actions/setup-python@v5
        with:
          python-version: '3.12'

      - name: Install code-review-graph
        run: pip install code-review-graph

      - name: Run code-review-graph
        uses: ./
        with:
          github-token: ${{ secrets.GITHUB_TOKEN }}

```

**Critical permissions note:** The `pull-requests: write` permission is mandatory—the action cannot post comments without it.

### Action Internals

The [`action.yml`](https://github.com/tirth8205/code-review-graph/blob/main/action.yml) file defines:
- `entrypoint: python3` invoking [`scripts/render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py)
- `github-token` input mapped to the authentication secret
- Optional `args` input for custom flags like `--exclude tests/*`

## GitLab, CircleCI, and Other CI Systems

For non-GitHub platforms, invoke the same Python components directly.

### GitLab CI Example

```yaml
stages:
  - review

code_review_graph:
  stage: review
  image: python:3.12-slim
  script:
    - pip install code-review-graph
    - python -m scripts.render_pr_comment \
        --project-dir . \
        --pr-id $CI_MERGE_REQUEST_IID \
        --token $GITLAB_PRIVATE_TOKEN
  only:
    - merge_requests

```

**Token requirements:**
- GitLab: Personal access token with `api` scope
- CircleCI: Project-level environment variable
- Azure Pipelines: Secret variable in pipeline variables

The [`render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/render_pr_comment.py) script auto-detects the CI provider via environment variables, so identical command syntax works across platforms.

## Core Source Files for Customization

When extending your integration, these files contain the implementation details:

| File | Purpose | Key Components |
|------|---------|----------------|
| [`action.yml`](https://github.com/tirth8205/code-review-graph/blob/main/action.yml) | GitHub Action interface definition | Inputs, outputs, Docker configuration |
| [`scripts/render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py) | CI orchestration entry point | Argument parsing, PR detection, markdown formatting |
| [`code_review_graph/graph.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py) | Dependency graph construction | `build()` function, import resolution, symbol mapping |
| [`code_review_graph/flows.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/flows.py) | Impact analysis engine | `analyze()` function, radius algorithm, change propagation |
| [`code_review_graph/hints.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/hints.py) | Custom rule definitions | Project-specific warnings and suggestions |
| [`tests/test_pr_review_workflows.py`](https://github.com/tirth8205/code-review-graph/blob/main/tests/test_pr_review_workflows.py) | Integration test examples | Expected CI behavior validation |

## Configuration Options and Best Practices

### Performance Tuning for Large Repositories

Add the `--max-depth` flag to limit graph traversal:

```yaml
with:
  github-token: ${{ secrets.GITHUB_TOKEN }}
  args: "--max-depth 3 --exclude vendor/* tests/*"

```

### Caching Dependencies

Speed up repeated runs with standard pip caching:

```yaml
- uses: actions/cache@v4
  with:
    path: ~/.cache/pip
    key: ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }}

```

### Failing the Build on Critical Findings

Block merges when the analysis detects severe issues:

```yaml
- name: Run code-review-graph
  uses: ./
  with:
    github-token: ${{ secrets.GITHUB_TOKEN }}
  continue-on-error: false

```

### Security Considerations

- Never commit tokens to version control—always use `${{ secrets.* }}` or equivalent
- The `GITHUB_TOKEN` is automatically scoped to the repository; no additional permissions needed for public repos
- For private repos, ensure the token has `pull_requests:write` and `contents:read`

### Extending Analysis Rules

Add project-specific checks by modifying [`code_review_graph/hints.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/hints.py). The CI integration automatically loads custom hints without workflow changes.

## Summary

- **GitHub users**: Copy the workflow file above; the bundled [`action.yml`](https://github.com/tirth8205/code-review-graph/blob/main/action.yml) handles authentication, analysis, and commenting automatically.
- **Other CI platforms**: Install `code-review-graph` from PyPI and execute `python -m scripts.render_pr_comment.py` with your platform's merge request ID and API token.
- The analysis engine resides in [`code_review_graph/graph.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py) (construction) and [`code_review_graph/flows.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/flows.py) (impact analysis); the CI glue is [`scripts/render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py).
- Runtime is sub-60 seconds for typical repositories, with `--max-depth` and `--exclude` flags available for scaling.

## Frequently Asked Questions

### Can I use code-review-graph with Bitbucket or Jenkins?

Yes. Any CI system that provides Python 3.12 and can supply a repository access token can run [`scripts/render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py). The script detects the CI environment via standard environment variables. For Bitbucket, pass `--token $BITBUCKET_APP_PASSWORD` and `--pr-id $BITBUCKET_PR_ID`.

### Does the GitHub Action require Docker?

No. While [`action.yml`](https://github.com/tirth8205/code-review-graph/blob/main/action.yml) supports Docker execution, the workflow example above uses the composite action pattern with `pip install`, which runs faster and caches dependencies natively. The Docker image is available for air-gapped environments or security policies requiring containerized execution.

### How do I customize the review comment format?

Modify [`scripts/render_pr_comment.py`](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py) between lines 45-78 where the markdown template is constructed. The `format_impact_report()` function accepts a dictionary from `code_review_graph.flows.analyze()` and returns the final comment string. Keep the function signature unchanged to maintain compatibility with [`action.yml`](https://github.com/tirth8205/code-review-graph/blob/main/action.yml).