How to Integrate code-review-graph with Your CI/CD Pipeline
You can integrate code-review-graph into your CI/CD pipeline by using its built-in GitHub Action for GitHub repositories, or by running the scripts/render_pr_comment.py helper script directly in any CI system that supports Docker or Python.
The code-review-graph project from tirth8205/code-review-graph is a Python-based static-analysis engine that constructs a knowledge graph of your repository, performs impact analysis on pull request changes, and automatically generates review comments. This guide walks through the exact implementation steps, source file references, and configuration options needed to deploy it in production.
How the CI Integration Works
The pipeline consists of five discrete stages orchestrated by scripts/render_pr_comment.py:
| Stage | Function | Source File |
|---|---|---|
| Checkout & Setup | Installs dependencies declared in pyproject.toml |
[pyproject.toml](https://github.com/tirth8205/code-review-graph/blob/main/pyproject.toml) |
| Graph Construction | code_review_graph.graph.build() parses imports and builds a directed symbol graph |
[code_review_graph/graph.py](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py) |
| Impact Analysis | code_review_graph.flows.analyze() computes affected files and functions |
[code_review_graph/flows.py](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/flows.py) |
| Comment Generation | Converts analysis output to markdown review comments | [scripts/render_pr_comment.py](https://github.com/tirth8205/code-review-graph/blob/main/scripts/render_pr_comment.py) |
| Post to PR | Uses GITHUB_TOKEN or equivalent to publish the comment |
[action.yml](https://github.com/tirth8205/code-review-graph/blob/main/action.yml) |
The entire execution completes in under one minute for medium-sized repositories, making it suitable to run on every PR without pipeline slowdown.
GitHub Actions Integration
The fastest way to integrate code-review-graph with your CI/CD pipeline is the ready-made GitHub Action.
Complete Workflow Configuration
Create .github/workflows/code-review-graph.yml in your repository:
name: Code Review Graph
on:
pull_request:
types: [opened, synchronize, reopened]
jobs:
analyze:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- name: Install code-review-graph
run: pip install code-review-graph
- name: Run code-review-graph
uses: ./
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
Critical permissions note: The pull-requests: write permission is mandatory—the action cannot post comments without it.
Action Internals
The action.yml file defines:
entrypoint: python3invokingscripts/render_pr_comment.pygithub-tokeninput mapped to the authentication secret- Optional
argsinput for custom flags like--exclude tests/*
GitLab, CircleCI, and Other CI Systems
For non-GitHub platforms, invoke the same Python components directly.
GitLab CI Example
stages:
- review
code_review_graph:
stage: review
image: python:3.12-slim
script:
- pip install code-review-graph
- python -m scripts.render_pr_comment \
--project-dir . \
--pr-id $CI_MERGE_REQUEST_IID \
--token $GITLAB_PRIVATE_TOKEN
only:
- merge_requests
Token requirements:
- GitLab: Personal access token with
apiscope - CircleCI: Project-level environment variable
- Azure Pipelines: Secret variable in pipeline variables
The render_pr_comment.py script auto-detects the CI provider via environment variables, so identical command syntax works across platforms.
Core Source Files for Customization
When extending your integration, these files contain the implementation details:
| File | Purpose | Key Components |
|---|---|---|
action.yml |
GitHub Action interface definition | Inputs, outputs, Docker configuration |
scripts/render_pr_comment.py |
CI orchestration entry point | Argument parsing, PR detection, markdown formatting |
code_review_graph/graph.py |
Dependency graph construction | build() function, import resolution, symbol mapping |
code_review_graph/flows.py |
Impact analysis engine | analyze() function, radius algorithm, change propagation |
code_review_graph/hints.py |
Custom rule definitions | Project-specific warnings and suggestions |
tests/test_pr_review_workflows.py |
Integration test examples | Expected CI behavior validation |
Configuration Options and Best Practices
Performance Tuning for Large Repositories
Add the --max-depth flag to limit graph traversal:
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
args: "--max-depth 3 --exclude vendor/* tests/*"
Caching Dependencies
Speed up repeated runs with standard pip caching:
- uses: actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }}
Failing the Build on Critical Findings
Block merges when the analysis detects severe issues:
- name: Run code-review-graph
uses: ./
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
continue-on-error: false
Security Considerations
- Never commit tokens to version control—always use
${{ secrets.* }}or equivalent - The
GITHUB_TOKENis automatically scoped to the repository; no additional permissions needed for public repos - For private repos, ensure the token has
pull_requests:writeandcontents:read
Extending Analysis Rules
Add project-specific checks by modifying code_review_graph/hints.py. The CI integration automatically loads custom hints without workflow changes.
Summary
- GitHub users: Copy the workflow file above; the bundled
action.ymlhandles authentication, analysis, and commenting automatically. - Other CI platforms: Install
code-review-graphfrom PyPI and executepython -m scripts.render_pr_comment.pywith your platform's merge request ID and API token. - The analysis engine resides in
code_review_graph/graph.py(construction) andcode_review_graph/flows.py(impact analysis); the CI glue isscripts/render_pr_comment.py. - Runtime is sub-60 seconds for typical repositories, with
--max-depthand--excludeflags available for scaling.
Frequently Asked Questions
Can I use code-review-graph with Bitbucket or Jenkins?
Yes. Any CI system that provides Python 3.12 and can supply a repository access token can run scripts/render_pr_comment.py. The script detects the CI environment via standard environment variables. For Bitbucket, pass --token $BITBUCKET_APP_PASSWORD and --pr-id $BITBUCKET_PR_ID.
Does the GitHub Action require Docker?
No. While action.yml supports Docker execution, the workflow example above uses the composite action pattern with pip install, which runs faster and caches dependencies natively. The Docker image is available for air-gapped environments or security policies requiring containerized execution.
How do I customize the review comment format?
Modify scripts/render_pr_comment.py between lines 45-78 where the markdown template is constructed. The format_impact_report() function accepts a dictionary from code_review_graph.flows.analyze() and returns the final comment string. Keep the function signature unchanged to maintain compatibility with action.yml.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →