
ReviewPhin
Self-hosted, agentic code review for GitLab and GitHub. 🐬
FreeAI AgentsAI Coding7,978 impressions#1 of its week12 comments
Comments
>log in to comment@Zain Sheikh I never tested it totally airgapped, but by default database is sqlite file, and model can be configured to point at self hosted api. As long as you can host your model, it has no reason to reach to the Internet (unless there is something in GitHub Copilot SDK/CLI that I don't know about). Just manage your expectations - unless you are able to host quite larger models on your own, results will be limited to the quality of what model can give you. There is some middle ground - run it in private network on azure (or any other cloud that gives you model hosting options) and configure it to work on models that azure hosts for you - e.g. gpt-5.6-terra on high. In such case you both have a smart model and your data stays in "your" network, just not on your machines.
- Zain Sheikh· 3mo ago
Self-hosted agentic review with your own model choice is a great fit for teams that can't ship code to a SaaS. Can it run fully against a local model for air-gapped setups?
@Zain Sheikh There is a bit of prompt composition that makes sure ReviewPhin does not focus on small things and pays more attention to higher importance findings. But in the end that depends on model you chose to use. From using it, I can tell that both GPT-5.4 and GPT-5.5 work great with that, chosing mostly the things that are more impactful. Qwen-27b has tendency to focus more on smaller things, that are less important. And yes, it works with GitLab CE edition. It does not rely on any paid features, nor on GitLab Duo - it's simple webhook + clone + api calls combination on GL platform. I am using it on self-hosted GitLab CE right now and it works perfectly.
- Zain Sheikh· 3mo ago
Bring-your-own-model plus self-hosting is the combo that makes agentic review viable for teams that cannot ship their diffs to a third party. How do you keep the reviewer agent from flooding a large MR with low-signal nits?
- Zain Sheikh· 3mo ago
Pay per review rather than per seat is the detail that matters here, since review load spikes independently of headcount. Does the self-hosted deploy work against GitLab CE?
- PDFops· 3mo ago
The "findings as native, bot-owned review comments you fully control" call is the right one. A separate SaaS dashboard for review output always turns into a second place nobody looks — keeping findings in the MR/PR thread, where the diff already lives, is what gets them acted on. Pay-per-review over per-seat also matches how bursty review load actually is rather than taxing headcount.
@Richard Anderson Optimization at the moment is mostly me trying stuff and playing with context. At the moment it relies only on model knowledge about given language which is perfectly fine if you use smarter models like gpt-5.5. They are still efficient enough to cover team of 5-10 devs with just one GH license (although mileage will vary depending on CR size, repo size etc). There is built-in command that summarizes all run metrics and storage table to record those from past runs. I could share some numbers with you, but tbh they span so wide range, I don't think it will give you much info. Right now I was focusing mostly on efficiency, features and correctness. I didn't have to touch token optimization yet, so I am sure once I do, there will be a lot to cut out. But so far my original strategy worked well: Get what you can programmatically from code review platform, pass that info to reviewer, give it basic tools to find details in code. You are able to specify different model profiles. Each profile has two models at the moment - reviewer and chatter. Context is gathered by platform provider which is not a model at the moment, but a json that gathers MR discussions etc. Beyond that, model has access to checked out branch and has tools to read into the code as it wishes during review. Each model profile can use different models, or different model hosting altogether. That depends on how you configure it. I am thinking on exposing more roles - router to start with to better discover if review is needed (sometimes general comment response, memory or web search will be enough). When it comes to tools per language there are two paths I am planning to explore, once I find time for it: 1. Give reviewer access to CI/CD pipeline summary and allow it to read logs, statuses etc. This will help it understand the state of the branch 2. Preinstal some tools for languages or extract job queue to dedicated workers - While both may be needed, I am simply not there yet. ReviewPhin is barely couple months old and mostly growing on my spare time, so the majority of my focus went into interacting with developers - review, summarize, respond to mentions etc.
@Zain Sheikh At the moment GitLab (including self-hosted) and GitHub are the only supported platforms. However, the server allows you to load custom platform provider as js module as long as it conforms to provider API I prepared. That API is still a bit messy, so until I clean it up, there will probably not be many platforms added. But tbh that depends mostly on how many people are interested in other platforms. If enough people ask e.g. for BitBucket, I'll take the time to model this connection as well.
@Thomas Jankowski I spent a lot of time tuning the prompt fragments for that, but in the end the signal to noise ratio depends highly on the models you've used. E.g. When I used qwen-27b for reviews (we have it in our company network), the findings were rather small things and most of them were accurate. I had to then use ReviewPhin memory to fine tune what is reported in given project. But when gpt-5.4 or 5.5 are used for review, findings are 99% accurate, larger scale issues that are missed and I had to finetune only few details. E.g. it detected that sqlite index was no longer needed after storage provider got different API. Or that one of the cli options, that was required is unnecessary, because in the end I refresh given data every webhook received. I ended up using gpt-5.4 for most of reviews and trusting them to highlight important stuff. And even then, I can respond to comments that are innacurate and either tell ReviewPhin to remember some misunderstood fact for future reference, or simply tell him to resolve given finding.
- PDFops· 3mo ago
Self-hosted is the real unlock here — what kills SaaS code-review bots for most teams is that you can't ship proprietary diffs to someone else's endpoint, so it never clears security review. Running it where the code already lives sidesteps that entirely. The harder problem I'd be curious about is signal-to-noise: agentic reviewers tend to over-flag style nits and miss the one load-bearing logic bug, and trust erodes fast once people start skimming past it. How are you tuning what it stays silent on?
- Zain Sheikh· 3mo ago
Pay-per-review instead of per-seat is a smart angle for teams with lots of occasional contributors. Which self-hosted git platforms beyond GitLab and GitHub are on the roadmap?
- Richard Anderson· 3mo ago
This is really interesting. What steps have you taken to ensure that agents are token efficient? Do you have any stats for token usage per language/LOC per discovered issue? Does the system have tools specific to certain programming language to increase efficiency and accuracy, or are you just relying on the LLMs ability to understand the provided code and context? Are you able to specify different models for the context-analyst + review-author roles in the code review?
Self-hosted, agentic code review tool that automates GitLab and GitHub pull-request reviews on your own infrastructure.
- for
- DevOps operators and engineering teams that want automated code reviews without losing deployment control.
- license
- MPL-2.0
Key features
- One-click deployment — Run ReviewPhin via Docker Compose or Helm chart; a single container hosts the worker, setup flow, and docs.
- Platform registration — Store reusable GitLab or GitHub credentials as platform connections and attach them to projects.
- Model flexibility — Use bundled Copilot CLI or configure OpenAI-compatible, Azure, or Anthropic endpoints via named profiles.
- Pluggable storage — Start with SQLite, switch to Flotiq, or add a custom storage adapter for review persistence.
- Automated review publishing — Trigger reviews from merge-request surfaces; findings, replies, and summaries are posted as native bot-owned comments.
- Container-ready runtime — The same image serves the worker, setup assets, and documentation, simplifying production deployment.
Use cases
- Automatically generate review comments for new pull requests in GitLab or GitHub
- Enforce coding standards and catch obvious errors before human review
- Integrate review automation into CI/CD pipelines to reduce review latency
- Provide consistent, model-driven feedback across multiple repositories
ReviewPhin vs alternatives
ReviewPhin | Pocketenv | ||||
|---|---|---|---|---|---|
| Best for | Agentic code review on self-hosted infra | General AI agent development | Agent sandboxing | Cloud-hosted AI agents | Managed AI agent backend |
| Pricing | Free | Free | Free | Free | Free |
| DevHunt upvotes | 12 | 75 | 73 | 43 | 35 |
| Launched | Jul 2026 | Jan 2023 | Apr 2026 | Jan 2023 | Feb 2026 |
- ReviewPhin vs Fine: Fine focuses on building AI agents broadly, while ReviewPhin is specialized for code-review automation on Git platforms.
- ReviewPhin vs Pocketenv: Pocketenv provides a sandbox runtime for agents, not a self-hosted code-review pipeline.
- ReviewPhin vs SuperAGI Cloud: SuperAGI Cloud runs autonomous AI agents in the cloud, whereas ReviewPhin runs on-premises for code review.
- ReviewPhin vs Calljmp: Calljmp offers a managed backend for AI agents, while ReviewPhin is self-hosted and tied to Git review workflows.
ReviewPhin FAQ
How do I deploy ReviewPhin?+
You can run it with Docker Compose (`docker compose up -d`) or install the Helm chart on a Kubernetes cluster using the provided commands.
Which version control platforms are supported?+
GitLab is the primary setup path, and GitHub is supported via an app-based flow.
Can I use my own LLM model?+
Yes, you can configure OpenAI-compatible, Azure, or Anthropic endpoints, or use the bundled Copilot CLI path.
What storage options are available for review data?+
ReviewPhin ships with SQLite by default, can switch to Flotiq with an admin panel, or you can add a custom storage adapter.
How are review comments delivered to developers?+
When a review is triggered, ReviewPhin posts findings, replies, and summaries as native bot-owned comments on the merge request.
Summarized by DevHunt from reviewphin.com · Sep 27, 2026. Details may change; check the official site.
Pocketenv





-(1).png?auto=compress&fit=max&w=64)



