# anc95/ChatGPT-CodeReview: a Probot bot that comments on pull request diffs

> ChatGPT-CodeReview is a GitHub App and GitHub Action that sends pull request diffs to an OpenAI-compatible model and posts the review as a comment. It is small, self-hostable and honest about its own hosted instance being rate-limited.

**anc95/ChatGPT-CodeReview** — 🐥 A code review bot powered by ChatGPT

- Repository: https://github.com/anc95/ChatGPT-CodeReview
- Website: https://github.com/apps/cr-gpt
- Stars: 4,467 · Forks: 464
- Language: JavaScript
- License: ISC
- Published: 2026-09-14 · Updated: 2026-09-14 · Language: en
- Canonical page: https://hysenlabs.com/projects/anc95-chatgpt-codereview

## The problem: review comments that arrive after the author has moved on

A pull request sits open for a day. The diff is 400 lines across nine files. The first reviewer opens it, skims, leaves two comments about naming, and closes the tab. The mechanical part of review, the part about an unchecked null, a missing await, a log line left in, is exactly the part nobody wants to spend attention on. ChatGPT-CodeReview targets that layer. It registers as a GitHub App, listens for pull request events, and posts model-generated review text into the pull request timeline and the file-changes view.

Who it is for: small teams on GitHub who want a first pass on every push without adding a human to the loop, and who are comfortable pointing a bot at an LLM endpoint. The README is explicit that the maintainer's hosted instance is a testing deployment, not a service: it runs on AWS Lambda with rate limits, and the README says unstable situations are completely normal and recommends deploying an app yourself. That sentence should shape how you evaluate the project. It is a self-hosting tool with a convenience demo attached, not a managed product.

## How the bot gets a diff and where the model call happens

The stack is Probot, the GitHub App framework, plus the official openai client. Probot handles the webhook plumbing: GitHub delivers pull_request events, Probot verifies the signature, and the app's handlers run. The README describes two triggers. A new pull request gets a review automatically. After a git push updates the pull request, the bot re-reviews the changed files, so it does not repeat comments on untouched code.

The same handler code is packaged three ways, which is the most interesting structural decision in the repository. The build script compiles the Probot app with Rollup, then runs ncc twice: one bundle for the GitHub Action entry point (src/github-action.cjs) and one for the Lambda entry point (src/aws-lambda.cjs). The dependencies list the matching adapters, @probot/adapter-github-actions and @probot/adapter-aws-lambda-serverless, and there is a serverless.yml for the Lambda deployment. So the review logic is written once and wrapped for a long-running Probot server, a GitHub Action job, or a serverless function.

Before the diff reaches the model, two filter lists apply. IGNORE_PATTERNS and INCLUDE_PATTERNS take glob or regex patterns separated by commas, matched with minimatch. MAX_PATCH_LENGTH sets a ceiling: the README states that a patch longer than the limit is ignored and will not be reviewed, and that with no MAX_PATCH_LENGTH set there is no limit. That default is worth pausing on. An unbounded diff on a large refactor means an unbounded prompt, and the cost lands on your API key.

## Installing the GitHub Action and getting a first review

The lowest-friction path is the GitHub Action, published on the marketplace as actions/chatgpt-codereviewer. Add OPENAI_API_KEY to your repository secrets, then create a workflow file. The README gives this example, trimmed here to the parts you need first.

```yaml
name: Code Review
permissions:
  contents: read
  pull-requests: write
on:
  pull_request:
    types: [opened, reopened, synchronize]
jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: anc95/ChatGPT-CodeReview@main
        env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
          OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
          LANGUAGE: Chinese
```

Commit that file, open a pull request, and the action runs on the opened event. The review text appears in the pull request timeline and against the changed files, the same place the hosted app posts. The permissions block matters: pull-requests: write is what lets the job comment, and contents: read is all it needs from your code.

The README also shows GitHub Models as an alternative to a raw OpenAI key, using USE_GITHUB_MODELS: true and MODEL: openai/gpt-4o, with models: true added to the permissions block. Azure deployments are configured through AZURE_API_VERSION and AZURE_DEPLOYMENT. For a standard endpoint, OPENAI_API_ENDPOINT defaults to https://api.openai.com/v1 and MODEL is set in the same env block; the README's example value is gpt-3.5-turbo. Tuning knobs mirror the chat completions API: top_p, temperature, max_tokens, and REASONING_EFFORT for reasoning models, which the README notes accepts none, minimal, low, medium, high or xhigh depending on the model.

To run it as a server instead, the README's self-hosting steps are: clone the code, copy .env.example to .env and fill the variables, then build and start under pm2.

```bash
npm i
npm i -g pm2
npm run build
pm2 start pm2.config.cjs
```

The .env.example file lists what the process expects: OPENAI_API_KEY, APP_ID, WEBHOOK_SECRET, PRIVATE_KEY, LOG_LEVEL, WEBHOOK_PROXY_URL, and the bot settings LANGUAGE, MODEL, temperature, top_p, max_tokens, REASONING_EFFORT, TARGET_LABEL, MAX_PATCH_LENGTH, PROMPT, IGNORE_PATTERNS and INCLUDE_PATTERNS. A Dockerfile is also present: node:18-slim, yarn install --production --frozen-lockfile, and a yarn start CMD. The README's Docker steps build it as cr-bot and run it with -e APP_ID and -e PRIVATE_KEY. Note the Node requirement: package.json declares engines node >= 18.

## What the bot will not do, and where the defaults bite

It comments. It does not approve, request changes, or block a merge. Nothing in the README describes a gate, a required check, or a severity threshold. If your process depends on a review bot failing the build on a bad pattern, this is the wrong tool.

The PROMPT variable is the whole instruction set. Its default in .env.example is the sentence Below there is a code diff please help me do a code review, and the README's Action example leaves PROMPT empty with a comment suggesting something like Please check if there are any confusions or irregularities in the following code diff. There is no rule file, no per-language instruction pack, no repository convention document. Whatever your team cares about, you have to write into that one string, and it applies to every file the bot sees.

The MAX_PATCH_LENGTH default is the other sharp edge. Unset means no limit, and the README says an over-limit patch is ignored rather than truncated. So a large pull request either costs whatever the full diff costs, or silently gets no review at all if you set a limit that is too low. Neither failure is visible in the comment thread.

Cost is per push, not per pull request. The README states that after git push updates the pull request, the bot re-reviews the changed files. On a branch that gets twenty commits, that is twenty model calls. The README never documents a token budget, a spend cap, or a way to review only on a label, though the Action example contains a commented-out if condition that would run the job only when a label named gpt review is attached. That line is present but inactive; enabling it is on you.

## Compared with codereview.gpt and other review bots

The README credits codereview.gpt as the inspiration. The difference is packaging. codereview.gpt is a browser tool: you paste a diff and read the output. ChatGPT-CodeReview puts the model call inside the pull request event, so the diff never leaves GitHub and the comment lands where the author is already looking. That is the trade: you get automation, and you give up the ability to pick and choose which diffs get reviewed unless you wire up the label condition yourself.

The other comparison point in the search results for this space is Qodo, which the README does not mention. What can be said from the repository alone is that this project is deliberately thin. It is a Probot app with an openai client, two pattern lists, a length cap, and a prompt string. There is no test-generation feature, no repository indexing, no learned conventions. If you want a bot that understands your codebase rather than the diff in front of it, this is not that.

## Maintenance, releases and the ISC licence

The repository is not archived, and the last push was on 2026-08-10. The most recent release is v1.0.24 from 2026-07-14, preceded by v1.0.23 in February 2026 and v1.0.22 in August 2025. The cadence is irregular: a six-month gap, then a five-month gap, then a two-month gap. That pattern fits a small project maintained in bursts rather than one with a roadmap.

The dependency set is where upgrade cost concentrates. Probot is pinned at ^12.2.4, the openai client at ^6.45.0, minimatch at ^10.0.1, and the build chain runs Rollup 3 with @vercel/ncc. The openai client is the one most likely to move under you, since model names and parameters change on the provider's schedule, not this project's. The README already carries model-specific notes, such as REASONING_EFFORT applying only to reasoning models, which is the kind of detail that ages.

The licence is ISC, a permissive licence functionally similar to MIT: it permits use, modification and redistribution provided the copyright notice and permission notice are retained. The LICENSE file carries the copyright line. This is not legal advice; if you redistribute the bot inside a commercial product, read the LICENSE file yourself. One practical note: the hosted app at apps/cr-gpt is a separate deployment, and installing it does not put you under the ISC grant for the source. Self-hosting is what the licence covers.

## Conclusion

Adopt it if you already have an OpenAI-compatible endpoint, want review comments inside the pull request timeline, and are willing to run it yourself rather than depend on the hosted app, which the README says is deployed on AWS Lambda with rate limits and unstable by design. Skip it if you need Bitbucket or GitLab support, or if you expect the bot to enforce anything: it comments, it does not block merges. Before rolling it out, verify that MAX_PATCH_LENGTH covers the diffs your team actually opens, that IGNORE_PATTERNS excludes your lockfiles, and that your OPENAI_API_KEY budget tolerates one model call per push.

## FAQ

### Can ChatGPT-CodeReview do a code review?

Yes, that is its entire function. It posts model-generated review text into the pull request timeline and file-changes view when a pull request is opened or updated, using an OpenAI-compatible endpoint you configure.

### How do I use ChatGPT-CodeReview?

Either install the hosted app at apps/cr-gpt, add the actions/chatgpt-codereviewer GitHub Action to a workflow with OPENAI_API_KEY in your secrets, or self-host by cloning the repo, filling .env, and starting it under pm2.

### What is ChatGPT-CodeReview?

It is a Probot-based GitHub bot, written in JavaScript and licensed under ISC, that sends pull request diffs to a ChatGPT model and comments the result back on the pull request.

### How much does a ChatGPT-CodeReview run cost?

The repository does not state a price. Cost comes from your own model calls, and the README notes that the bot re-reviews changed files after each git push, so a branch with many commits means many calls. The README gives no token budget or spend cap.

## Sources

- [anc95/ChatGPT-CodeReview on GitHub](https://github.com/anc95/ChatGPT-CodeReview)
- [License: ISC](https://github.com/anc95/ChatGPT-CodeReview/blob/main/LICENSE)
- [Project website](https://github.com/apps/cr-gpt)
- [README](https://github.com/anc95/ChatGPT-CodeReview/blob/main/README.md)
- [Releases](https://github.com/anc95/ChatGPT-CodeReview/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/anc95-chatgpt-codereview
