openqodex/openqodex

★ 418⑂ 28

Open source AI code review for Claude Code and Codex, before you push. Scanners (SAST, secrets, dependencies, lint) on the lines you changed

About openqodex/openqodex

openqodex/openqodex is an open-source project on GitHub, mainly written in TypeScript. Open source AI code review for Claude Code and Codex, before you push. Scanners (SAST, secrets, dependencies, lint) on the lines you changed It currently holds 418 stars and 28 forks with 0 open issues, and was last pushed on an unknown date (repository created unknown).

Project Overview

AI Homed tracks it on the Today's Trending board.

GitHub Repository Details

Repository openqodex/openqodex · default branch - · size 0 KB · watchers 0 · source: GitHub REST API and repository README

README

https://github.com/openqodex/openqodex/blob/HEAD/OpenQodex

OpenQodex

npm version licence CI

OpenQodex is open source AI code review for Claude Code and Codex. It runs before you push, from your coding agent or your terminal. One command, openqodex review, works out your change: the commits not yet pushed plus everything uncommitted. It runs the scanners that fit the changed files and keeps only findings on the lines you changed. Then it starts its own reviewer, a separate Claude Code or Codex process that reads a frozen copy of the change. The reviewer checks every scanner finding and is given every changed line. OpenQodex checks its answer with scripts, writes one report, and prints a short receipt: the verdict, one line per finding and the path of report.html, a local page that shows each finding under its line of code. You choose which findings your agent fixes. It needs Claude Code or Codex installed and logged in, and no other key, account or server.

Install

For humans, in your terminal:

npx openqodex init

init finds Claude Code, Cursor, Codex CLI and Cline on your machine. It prints every file it will write and asks once. Then it names the reviewer it found, or what to fix, and reviews your change, or asks what to review when there is none. After that, say to your agent "review my change with openqodex", or run ~/.openqodex/bin/openqodex review yourself: init prints that full path, since an npx install puts no openqodex on your PATH.

For agents, the same install, run by the agent for itself with no question:

npx -y openqodex@0.10.0 init --yes --agent 

` is claude-code, codex, cursor or cline`. Or paste this prompt into your agent:

Install OpenQodex for yourself with npx -y openqodex@0.10.0 init --yes --agent , where  is the agent you are: claude-code, codex, cursor or cline. Run it from this repository and allow it up to ten minutes: when a reviewer can start, it ends with a review of my current change.
Then tell me the verdict and the findings, or what its last lines say is missing.

Codex runs commands in a sandbox that by default cannot write outside the project or reach the network: from Codex, run the line in your own terminal instead.

The skill alone, with no push check, launcher or scanner download: npx skills add openqodex/openqodex -g. A later init replaces it with the skill it keeps up to date.

OpenQodex needs Node 22 or newer and git. It runs on macOS and Linux. On Windows, use WSL.

What it does today

Four commands: init, review, update and trust. The commands hooks and agents call are listed in docs/plumbing.md.

What it does not do yet

First run

Scanners download on first use into ~/.openqodex/tools/. A review downloads only the scanners its changed files call for. init and doctor --install download the ones your repository's files call for and print why for each one, such as brakeman: Rails app in backend/. The table below gives each download size.

Installed scanners take more disk than their downloads. The eight scanners the demo needs take about 700 MB of disk on an Apple Silicon Mac. semgrep with its Python takes about 440 MB of that.

A scanner install that takes longer than 45 seconds keeps going in the background. The report lists that scanner as installing. The scanner joins the next run. The review init ends with waits up to two minutes, since init has just started the downloads. To install what a repository needs up front, run npx openqodex doctor --install inside it. --all-scanners installs every scanner.

One measured first run: an Apple Silicon Mac, an empty tool folder, a line of 2 MB per second. The first openqodex demo printed its report in under a minute. That report held the scanners that had finished installing and listed the rest as installing. The next scan included all eight scanners. Your times depend on your line.

OpenQodex does not install language runtimes. brakeman needs Ruby 3.0 or newer and rubocop Ruby 2.7 or newer. golangci-lint needs Go. Without them, the report lists those scanners as not installed, with the reason.

Built-in scanners

| Scanner | Version | Runs when the change holds | Needs | Download (Apple Silicon, Linux x64) | |---|---|---|---|---| | semgrep | 1.94.0 | any file | Python 3.11, downloaded through uv | about 86 MB with bandit, measured on Apple Silicon | | gitleaks | 8.21.2 | any file | nothing | 2.9 MB, 3.0 MB | | bandit | 1.9.4 | .py, .pyi | the same Python as semgrep | included with semgrep | | ruff | 0.8.4 | .py, .pyi | nothing | 9.9 MB, 11.2 MB | | oxlint | 1.86.0 | .js, .jsx, .ts, .tsx, .mjs, .cjs, .mts, .cts | nothing | 5.3 MB, 6.1 MB | | osv-scanner | 2.6.0 | a lockfile, such as package-lock.json, bun.lock, uv.lock or go.mod | network access to osv.dev | 52.6 MB, 54.9 MB | | actionlint | 1.7.7 | .github/workflows/*.yml | nothing | 2.0 MB, 2.1 MB | | hadolint | 2.15.1 | a Dockerfile | nothing | 102.6 MB, 55.7 MB | | shellcheck | 0.10.0 | .sh, .bash, or a file with no extension whose first line (#!) names sh, bash, dash or ksh | xz to unpack | 7.2 MB, 2.4 MB | | golangci-lint | 2.12.2 | .go | Go | 14.4 MB, 15.0 MB | | brakeman | 6.2.1 | a Ruby or Rails file in a Rails app: a folder whose Gemfile or Gemfile.lock names rails and that holds config/application.rb or bin/rails | Ruby 3.0 or newer; see its licence below | from RubyGems, not measured | | rubocop | 1.69.2 | .rb, .rake, .gemspec, Rakefile | Ruby 2.7 or newer | from RubyGems, not measured | | sqllint | built in | .sql | nothing, it runs inside OpenQodex | none |

docs/scanners.md lists every file each scanner reads and what each one sends.

brakeman's licence is the Brakeman Public Use License, which is not an open source licence. It runs only for a Rails app. OpenQodex does not bundle brakeman. It downloads brakeman at run time onto your machine. scanners.disable: [brakeman] switches it off.

Add any scanner

Add a scanner by its GitHub link in your repo's .openqodex/config.yaml:

scanners:
  custom:
  • source: https://github.com/aquasecurity/trivy
run: trivy config --disable-telemetry --skip-version-check --skip-check-update --format sarif --output {report} {target}

A custom scanner is a command that runs on your machine. It never runs until you approve it:

npx openqodex trust

trust picks the release asset for your machine and downloads it. It shows the version, the asset, its sha256 and the run line, then asks yes or no. An edited entry needs a new approval. docs/custom-scanners.md explains each step.

What goes over the network

--offline skips osv-scanner and semgrep and turns scanner downloads, the version check, and the fetch and gh call of a branch or pull request review off.

The built-in scanners send no code anywhere. The reviewer's model sees the brief and what the reviewer reads, as with any Claude Code or Codex session. A custom scanner you approved does whatever its own command does. docs/security.md gives the full list.

Updates

An install made with npx openqodex init from 0.3.0 on keeps itself up to date. At most once a day, after a review, a scan or a push check, a background process looks for a new release. The command never waits for it. A release is installed only when it is at least 24 hours old and its signed build record (npm provenance) shows it was built by this repository's release workflow. It goes into a folder of its own beside the version you run, and the switch is one rename of a small file, so a failed or interrupted update leaves the working version in place.

An update writes only that folder, the file that names the active version and its own state. It never writes your settings, a repository or the files init wrote for your agents (the skill, the rules, the instruction lines, the Claude Code hook and permission rules). In user scope those files hold no procedure: the skill asks the launcher for the procedure of the version that runs. A release that changes how agents run a review, or the config format, is not installed in the background: the next command says so, and openqodex update installs it. When files init wrote are from an older version, the next command after an update says how many and that init refreshes them; init keeps every file you edited. That command also says which version it moved to, and names any change in what leaves your machine, what blocks a push or who reviews. openqodex update --rollback goes back, and that release is never installed again; updates stay on, so the next one comes (going back to 0.8.1 or earlier turns them off instead).

Turn it off with openqodex update --off, update: off in ~/.openqodex/config.yaml or OPENQODEX_AUTO_UPDATE=0. It is also off with --offline and when CI is set, and paused while that file holds a key OpenQodex does not know.

These do not update: the files init wrote for your agents until init runs again, files committed with init --project, the review section init adds to a repository's CLAUDE.md and AGENTS.md, the skill from npx skills add until the next init replaces it, the GitHub Action pin, and machines that are offline or stop background processes. An active install is usually one to two days behind a release. An install made with any earlier version needs one npx openqodex init to start updating. An install of 0.8.1 or earlier does not know about agent contracts yet: its next update installs the newest release whatever it changes, and the command after it names the files init would refresh.

Packages

| Package | What it is | |---|---| | openqodex | One package. It holds the CLI as one bundled file with no runtime dependencies. The skill, the agent templates, the docs, the review patterns and the demo ship as separate files beside it. |

@openqodex/core and @openqodex/scanners are internal workspace packages. The CLI bundles them, and they are not published.

Documentation

The docs ship inside the package. npx openqodex guide prints a page offline.

Telemetry

None. OpenQodex sends no usage data. semgrep runs with its own metrics switched off. See docs/telemetry.md and the privacy policy, docs/privacy.md.

Security

Report a vulnerability through GitHub's private vulnerability reporting on this repo. Never open a public issue for one. See SECURITY.md.

Status

OpenQodex is new and on the way to 1.0. Commands, flags and the config file can change between minor releases. CHANGELOG.md records every change.

Made by Qodex

Made by Qodex

OpenQodex is made by Qodex, which also runs a hosted review on every pull request.

Licensed under Apache 2.0. See NOTICE for the scanners' licences.

GitHub Stars & Activity

418Stars
28Forks
0Open issues
TypeScriptLanguage

GitHub Popularity

GitHub stars418
Forks28
Open issues0
Primary languageTypeScript
License-
Stars gained today0
Created-
Last pushed-

Trending History

Weekly boardrank #100 · ▲ 0 stars

Related AI Projects

1

deepseek-ai / deepseek-harness

TypeScript★ 245,651⑂ 0
→
2

n8n-io / n8n

TypeScript★ 206,719⑂ 0
→
3

firecrawl / firecrawl

TypeScript★ 189,587⑂ 0
→
4

langgenius / dify

TypeScript★ 157,923⑂ 0
→
5

thedotmack / claude-mem

TypeScript★ 98,319⑂ 8,628▲ 662 stars
→
6

koala73 / worldmonitor

TypeScript★ 88,058⑂ 13,438▲ 94 stars
→
7

ItzCrazyKns / Vane

TypeScript★ 37,147⑂ 4,124▲ 51 stars
→
8

tashfeenahmed / freellmapi

TypeScript★ 32,080⑂ 4,457▲ 508 stars
→

More AI Rankings