Is code-review-graph a Cloud-Based or Local-First Solution?

code-review-graph is a local-first tool that stores your entire code-structure graph in a SQLite database on your development machine, requiring no internet connection or external services for core functionality.

The code-review-graph repository by tirth8205 implements a privacy-centric architecture that processes and stores all code analysis data locally by default. If you are evaluating whether code-review-graph is cloud-based or local-first, the source code confirms that every core operation—from parsing to graph storage—happens entirely on your machine, with optional cloud capabilities strictly limited to semantic search add-ons.

Understanding the Local-First Architecture

According to the source code in README.md, the tool maintains its entire graph structure in a SQLite file located under the .code-review-graph/ directory. This local storage model requires no external database or cloud service, allowing developers to work completely offline while performing blast-radius analysis and MCP integration.

Zero Telemetry by Design

The repository explicitly states "zero telemetry" in its FAQ section. Unlike many modern developer tools, code-review-graph does not transmit usage data or source code to remote servers unless you explicitly opt into optional semantic search features. The architecture ensures that sensitive codebases remain entirely within your local environment, with no data leakage to external endpoints by default.

Core Local Operations

The code_review_graph/cli.py file implements the primary command-line interface that operates without network connectivity. All parsing utilizes Tree-sitter to analyze source files locally, while incremental updates rely on SHA-256 hash comparisons to minimize reprocessing.

Build the complete graph locally using:

code-review-graph build

This parses your entire repository and stores the AST-based graph in the local SQLite database.

Update the graph incrementally with:

code-review-graph update

This command compares file hashes and only re-parses changed content, keeping your local index synchronized in seconds.

Query the local graph for minimal review context:

code-review-graph detect-changes --brief

This displays token savings and blast-radius analysis based solely on the locally stored graph, without contacting any remote service.

Optional Cloud Embeddings (Opt-In Only)

While the core infrastructure is local, the codebase in code_review_graph/main.py supports optional cloud-based semantic search through extras packages. These features are disabled by default and require explicit activation through environment variables and additional installation steps.

Enabling Cloud-Based Features

To use external embedding providers such as Google, MiniMax, Voyage, or OpenAI, you must install the specific extras and configure API keys:

pip install "code-review-graph[embeddings]"
export GOOGLE_API_KEY=YOUR_KEY
code-review-graph embed --provider google

As documented in the README.md, these cloud features only augment the local graph—the core storage, parsing, and query operations remain local even when embeddings are enabled. The tool supports extras like code-review-graph[google-embeddings] for specific providers, but these remain strictly optional.

Key Source Files Confirming Local-First Implementation

Several files in the tirth8205/code-review-graph repository demonstrate the offline-first architecture:

  • code_review_graph/main.py: The entry point that orchestrates local parsing and graph building without external dependencies for core operations.
  • code_review_graph/cli.py: Implements the build, update, and detect-changes commands that interact exclusively with the local SQLite graph.
  • code_review_graph/daemon_cli.py: Provides a background daemon that watches repositories and incrementally updates the local graph using file system events.
  • code_review_graph/parser.py: Uses Tree-sitter to parse source files locally and generate the AST-based graph structures stored in SQLite.

Summary

  • code-review-graph is fundamentally local-first, storing all graph data in .code-review-graph/ as SQLite files on your machine.
  • Zero telemetry is collected by default; your source code never leaves your local environment without explicit configuration.
  • Core CLI commands (build, update, detect-changes) operate entirely offline using local Tree-sitter parsing and SHA-256-based incremental updates.
  • Cloud features are strictly opt-in, requiring installation of extras like code-review-graph[embeddings] and explicit API key configuration for semantic search.
  • The architecture supports complete offline usage for blast-radius analysis and MCP integration.

Frequently Asked Questions

Does code-review-graph require an internet connection to analyze code?

No. The core functionality including building the graph, incremental updates, and blast-radius analysis works entirely offline using local SQLite storage and Tree-sitter parsing. You only need internet connectivity if you explicitly enable optional cloud-based semantic search features by installing extras like code-review-graph[embeddings].

Where does code-review-graph store its analysis data?

All data is stored in a SQLite database within the .code-review-graph/ directory in your project root. According to the source code in README.md, this local storage model requires no external database, cloud service, or network connectivity to function.

Is my source code uploaded to the cloud when using code-review-graph?

No. By default, code-review-graph operates with zero telemetry and keeps your source code local. Cloud embeddings are strictly opt-in features that require additional package installation and API keys. Even when enabled, only embedding vectors—not raw source code—are transmitted to external services if you choose to use semantic search.

Can I use code-review-graph in an air-gapped environment?

Yes. Since all parsing uses Tree-sitter locally and storage uses SQLite in .code-review-graph/, the tool functions perfectly in offline or air-gapped environments. Simply install the base package without the [embeddings] extras to ensure no cloud dependencies are present.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →