Get started
AI Code Review
Review pull requests and repositories with security-aware Cortex analysis.
AI Code Review brings security analysis and AI-generated remediation suggestions into GitHub. It supports reviewing a proposed change and scanning a full repository through two separate integrations, with detailed results available in the Pervaziv Console.
Get started
Section titled “Get started”Connect the repository as a Pervaziv project with a Premium or Enterprise plan. Choose the GitHub App for pull-request review or the GitHub Action for scans on push or a schedule. Installation buttons above link to the respective Marketplace entries.
Choose an integration
Section titled “Choose an integration”| GitHub App | GitHub Action | |
|---|---|---|
| Review scope | Changed pull-request files | Full repository |
| Starting point | Connected pull-request review and supported bot commands | Configured push or scheduled workflow |
| Results in GitHub | Review summary, Overall Risk label and eligible inline suggestions | Actions summary and Security code-scanning alerts |
| Suggested fixes | Suggestions in the pull-request review | Optional fix pull request when Auto Code Suggestion is enabled |
| Setup | App installation and project branch controls | Workflow file, project settings and job permissions |
The integrations serve different review points. A team can use the App to review incoming changes and the Action to assess the repository on its chosen schedule.
Security findings in the developer workflow
Section titled “Security findings in the developer workflow”Analysis connects findings to affected code and provides remediation guidance. Pull-request review keeps that feedback close to the change under discussion, while repository scans expose individual alerts with file and line details, severity and rule information. Supported alerts also include CWE and OWASP tags.
The Console report provides the detailed project view. Supported languages are documented in language coverage; actual coverage depends on the files and enabled analysis.
Review assistance and suggested changes
Section titled “Review assistance and suggested changes”The GitHub App supports debugging assistance and inline suggestions alongside security findings. The Action can create a separate pull request containing suggested fixes when the project setting and GitHub permissions allow it. Developers retain the review step for accepting those changes.
An Overall Risk label summarizes the App’s review, while an Action summary identifies the repository, branch, trigger and total finding count. These outputs help prioritize investigation; the detailed findings and validated changes provide the basis for a merge decision.
Two complementary review points
Section titled “Two complementary review points”The App addresses the change being proposed. It keeps findings, suggestions and the risk summary inside the pull-request discussion, where a developer can understand the issue in the context of the diff and respond before merge.
The Action addresses the broader repository. It is useful for recurring scans, branch updates and detecting issues outside the files modified by a particular pull request. Its job summary helps locate the run; code-scanning alerts expose individual findings; the Console supplies the detailed project report.
Using both can give a team change-level feedback and a repository baseline. The outputs have different scopes, so a clear PR review is not a replacement for a full-repository assessment, and a repository scan does not explain every design decision in an incoming change.
Reviewable AI remediation
Section titled “Reviewable AI remediation”AI-generated suggestions shorten the path from a finding to a candidate fix. The App can present eligible inline suggestions in the review. The Action’s optional Auto Code Suggestion capability can produce a separate fix pull request, keeping the proposed remediation visible to the team.
Inspect the affected behavior, adjacent code and tests before accepting the change. Verify authorization, input handling and dependency behavior when relevant to the finding. Run the checks appropriate for the risk and obtain results for the updated revision. A generated fix remains a proposal until the team’s review and validation requirements are met.
Findings that support investigation
Section titled “Findings that support investigation”Use file and line information to locate the affected implementation. Severity and Overall Risk help prioritize attention, while available CWE and OWASP tags provide classification. The detailed report and remediation guidance support the investigation behind that summary.
Different outputs answer different questions: a completed Action shows the job reached an outcome, a code-scanning alert describes a detected issue, and a validated patch supports a remediation decision. The absence of findings is not a claim of exhaustive security coverage.
Product background
Section titled “Product background”- The pull-request review GitHub App
- Full-repository scanning with the GitHub Action
- Optional pull requests with AI-generated fixes
Configuration and access
Section titled “Configuration and access”Project settings expose Enable Auto Update, Enable Auto Code Suggestion, Enable AI Scan and allowed branches. The App’s repository selection controls which repositories it can access. The Action’s permissions control whether it can upload code-scanning results or create a fix pull request.
See reviewing a pull request, Action inputs and repository scanning for the exact configuration. New commits require results for the updated revision.
Connected product reporting
Section titled “Connected product reporting”AI Code Review brings findings into GitHub; DevSecOps provides the wider security, dependency and posture views for the connected project. Account & Billing manages the subscription used by both integrations.

