How to Integrate code-review-graph with Your CI/CD Pipeline

You can integrate code-review-graph into your CI/CD pipeline by using its built-in GitHub Action for GitHub repositories, or by running the scripts/render_pr_comment.py helper script directly in any CI system that supports Docker or Python.

The code-review-graph project from tirth8205/code-review-graph is a Python-based static-analysis engine that constructs a knowledge graph of your repository, performs impact analysis on pull request changes, and automatically generates review comments. This guide walks through the exact implementation steps, source file references, and configuration options needed to deploy it in production.

How the CI Integration Works

The pipeline consists of five discrete stages orchestrated by scripts/render_pr_comment.py:

Stage Function Source File
Checkout & Setup Installs dependencies declared in pyproject.toml [pyproject.toml](https://github.com/tirth8205/code-review-graph/blob/main/pyproject.toml)
Graph Construction code_review_graph.graph.build() parses imports and builds a directed symbol graph [code_review_graph/graph.py](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py)
Impact Analysis code_review_graph.flows.analyze() computes affected files and functions [code_review_graph/flows.py](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/flows.py)
Comment Generation Converts analysis output to markdown review comments [scripts/render_pr_comment.py](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py)
Post to PR Uses GITHUB_TOKEN or equivalent to publish the comment [action.yml](https://github.com/tirth8205/code-review-graph/blob/main/action.yml)

The entire execution completes in under one minute for medium-sized repositories, making it suitable to run on every PR without pipeline slowdown.

GitHub Actions Integration

The fastest way to integrate code-review-graph with your CI/CD pipeline is the ready-made GitHub Action.

Complete Workflow Configuration

Create .github/workflows/code-review-graph.yml in your repository:

name: Code Review Graph

on:
  pull_request:
    types: [opened, synchronize, reopened]

jobs:
  analyze:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      pull-requests: write
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - uses: actions/setup-python@v5
        with:
          python-version: '3.12'

      - name: Install code-review-graph
        run: pip install code-review-graph

      - name: Run code-review-graph
        uses: ./
        with:
          github-token: ${{ secrets.GITHUB_TOKEN }}

Critical permissions note: The pull-requests: write permission is mandatory—the action cannot post comments without it.

Action Internals

The action.yml file defines:

  • entrypoint: python3 invoking scripts/render_pr_comment.py
  • github-token input mapped to the authentication secret
  • Optional args input for custom flags like --exclude tests/*

GitLab, CircleCI, and Other CI Systems

For non-GitHub platforms, invoke the same Python components directly.

GitLab CI Example

stages:
  - review

code_review_graph:
  stage: review
  image: python:3.12-slim
  script:
    - pip install code-review-graph
    - python -m scripts.render_pr_comment \
        --project-dir . \
        --pr-id $CI_MERGE_REQUEST_IID \
        --token $GITLAB_PRIVATE_TOKEN
  only:
    - merge_requests

Token requirements:

  • GitLab: Personal access token with api scope
  • CircleCI: Project-level environment variable
  • Azure Pipelines: Secret variable in pipeline variables

The render_pr_comment.py script auto-detects the CI provider via environment variables, so identical command syntax works across platforms.

Core Source Files for Customization

When extending your integration, these files contain the implementation details:

File Purpose Key Components
action.yml GitHub Action interface definition Inputs, outputs, Docker configuration
scripts/render_pr_comment.py CI orchestration entry point Argument parsing, PR detection, markdown formatting
code_review_graph/graph.py Dependency graph construction build() function, import resolution, symbol mapping
code_review_graph/flows.py Impact analysis engine analyze() function, radius algorithm, change propagation
code_review_graph/hints.py Custom rule definitions Project-specific warnings and suggestions
tests/test_pr_review_workflows.py Integration test examples Expected CI behavior validation

Configuration Options and Best Practices

Performance Tuning for Large Repositories

Add the --max-depth flag to limit graph traversal:

with:
  github-token: ${{ secrets.GITHUB_TOKEN }}
  args: "--max-depth 3 --exclude vendor/* tests/*"

Caching Dependencies

Speed up repeated runs with standard pip caching:

- uses: actions/cache@v4
  with:
    path: ~/.cache/pip
    key: ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }}

Failing the Build on Critical Findings

Block merges when the analysis detects severe issues:

- name: Run code-review-graph
  uses: ./
  with:
    github-token: ${{ secrets.GITHUB_TOKEN }}
  continue-on-error: false

Security Considerations

  • Never commit tokens to version control—always use ${{ secrets.* }} or equivalent
  • The GITHUB_TOKEN is automatically scoped to the repository; no additional permissions needed for public repos
  • For private repos, ensure the token has pull_requests:write and contents:read

Extending Analysis Rules

Add project-specific checks by modifying code_review_graph/hints.py. The CI integration automatically loads custom hints without workflow changes.

Summary

  • GitHub users: Copy the workflow file above; the bundled action.yml handles authentication, analysis, and commenting automatically.
  • Other CI platforms: Install code-review-graph from PyPI and execute python -m scripts.render_pr_comment.py with your platform's merge request ID and API token.
  • The analysis engine resides in code_review_graph/graph.py (construction) and code_review_graph/flows.py (impact analysis); the CI glue is scripts/render_pr_comment.py.
  • Runtime is sub-60 seconds for typical repositories, with --max-depth and --exclude flags available for scaling.

Frequently Asked Questions

Can I use code-review-graph with Bitbucket or Jenkins?

Yes. Any CI system that provides Python 3.12 and can supply a repository access token can run scripts/render_pr_comment.py. The script detects the CI environment via standard environment variables. For Bitbucket, pass --token $BITBUCKET_APP_PASSWORD and --pr-id $BITBUCKET_PR_ID.

Does the GitHub Action require Docker?

No. While action.yml supports Docker execution, the workflow example above uses the composite action pattern with pip install, which runs faster and caches dependencies natively. The Docker image is available for air-gapped environments or security policies requiring containerized execution.

How do I customize the review comment format?

Modify scripts/render_pr_comment.py between lines 45-78 where the markdown template is constructed. The format_impact_report() function accepts a dictionary from code_review_graph.flows.analyze() and returns the final comment string. Keep the function signature unchanged to maintain compatibility with action.yml.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →