Skip to content

AI code review that reads every line of the merge request

412 lines, a green pipeline, approved in nine minutes. A code-review checkup read the whole diff and filed the dropped index nobody saw.

The situation

17:50. Merge request !287, Backfill merchant analytics + retire legacy index: +412 −38, pipeline passed, one approval. The review took nine minutes and the only comment is "looks fine".

Line 41 of migrations/0142.sql drops idx_events_merchant_created, an index on a 38-million-row table. Nobody read line 41. A green pipeline says the migration runs. It doesn't say what the dashboard query does once the index is gone.

What Triagic looked at

The GitLab code review checkup takes a target: a repository, or one merge request. We gave it ingest-pipeline !287. It's a read-only procedure, and this run touched:

  • GitLab: the merge request's diff, file by file, plus its approval and pipeline history. It reads the diff through the API. It never checks the code out and it can't push.
  • The repository's recent history: who approved what, which merges were self-approved, and whether anything was force-pushed to a protected branch.

The same checkup exists for GitHub pull requests. Every call is listed on the run page with its arguments.

What it found

high: Migration drops idx_events_merchant_created with no replacement. Evidence: migrations/0142.sql:41. The merchant dashboard's main query filters on exactly those two columns. With the index it runs at 140 ms p95; without it, it's a full scan of 38 million rows. The recommendation gives the safe order: create the replacement index CONCURRENTLY first, deploy, then drop the old one.

medium: !287 merged self-approved. The author and the approver are the same account. That's a process finding, not a code one, and the checkup reads both.

Findings don't reset between runs. Each one has a stable key, so an unfixed finding comes back next week as the same row marked "still open" instead of as a new surprise.

What changed

The index drop moved to a follow-up migration behind the replacement, before the merge reached production. The checkup now runs weekly, Monday 08:00, against the repositories that carry migrations. The team still reviews every merge request. The checkup is the second reader that doesn't skim at 17:50.

The procedures are in the open checkup library: GitLab code review and GitHub code review.

Run this on your own systems

No card, your own model key and read-only credentials.