AI NewsDev toolsAnnouncement

OpenQodex is open-source AI code review for Claude Code and Codex

OpenQodex is an open-source AI code reviewer that runs 13 scanners on the lines you changed, then starts a separate Claude Code or Codex process to check every finding, before you push.

AI News

Editorial2 min read

LinkedInX
GitHub social card for openqodex/openqodex

Image: OpenQodex

Why it mattersA team using Claude Code or Codex gets a review step on its own machine that checks the scanner's work and sees every changed line, so a release does not depend on finding time to review a diff by hand.

A coding agent writing code and reviewing it is one process checking its own work. OpenQodex changes that: it runs on your machine, uses a different Claude Code or Codex process to review what the first one wrote, and gives that reviewer only read-only access to a frozen copy of the change. The project launched this week under Apache 2.0 and sits at 180 GitHub stars.

OpenQodex says the review runs "before you push, from your coding agent or your terminal". One command, openqodex review, inspects every commit not yet pushed plus everything uncommitted, runs the scanners that fit each changed file type, and keeps only findings on the lines you touched. Then it starts a separate agent process that reads the diff in a sandbox and checks each finding.

Thirteen scanners, each pinned

The scanner list covers the common ground: semgrep 1.94 with bandit, gitleaks 8.21, ruff 0.8, oxlint 1.71, osv-scanner 1.9, actionlint 1.7, hadolint 2.15, shellcheck 0.10, golangci-lint 2.12, brakeman 6.2, rubocop 1.69, and a built-in SQL linter. Each runs only when the diff holds a file it reads: no Ruby files means no brakeman run. Scanners download on first use into ~/.openqodex/tools/, and the eight the built-in demo needs weigh about 700 MB on an Apple Silicon Mac.

A # nosec comment the change adds is not treated as a free pass. OpenQodex says the scan counts it as a minor finding and the reviewer checks each one, because a suppression added inside a diff is itself a signal.

A reviewer with no memory of yours

The reviewer is Claude Code or Codex, picked by a flag or by the agent the command was called from. Claude Code starts with read, search and list tools only, inside the frozen copy of the change, with none of the caller's settings, hooks, plugins, memory or instruction files. Codex starts in its read-only sandbox with no network. Both leave an event stream the report prints, so a reader can see which files the reviewer read.

OpenQodex says a review is complete only when every stage ran, every scanner finding was raised or dropped with a reason, and every changed line was in front of the reviewer. Anything else prints "Review incomplete" and exits with code 2.

Install and limits

Install with npx openqodex init, which detects Claude Code, Cursor, Codex CLI and Cline, prints every file it will write, and asks once. Node 22 or newer, macOS and Linux, Windows through WSL. Cursor cannot be the reviewer: OpenQodex says cursor-agent has no way to limit its tools to reading or to skip rules. A review takes one to three minutes and uses the caller's own Claude Code or Codex plan, with no separate API key.

A GitHub Action and a pre-push git hook can run the review in CI or on the push itself. Both warn by default and block only when .openqodex/config.yaml sets review.block_on_severity.

Source

SourceOpenQodex

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX