cujo
A pull request reviewer that runs the code.
It clones the head into a disposable sandbox, runs the tests on base and on head, writes its own probes against the change, boots the app and hits it, and reads what a new dependency does when installed. The review it posts cites what happened.
What lands on a pull request
- One review from cujo-guard[bot]: what ran, what it found, and inline comments on the lines they are about.
- A check run that holds the merge while a critical finding stands, until a person lifts it with one comment.
- Nothing else. It never posts APPROVE, and it never comments on style, architecture or preference; every finding follows from something a sensor observed.
What it will not do
- Hold a credential where the code runs. The sandbox gets a tree and no token; a private repository’s trees are fetched outside it and copied in.
- Read what the code sends. Egress is recorded as a host, a port and a byte count, never intercepted.
- Pretend to have seen everything. A process that opens a socket past the proxy is a gap, and the report says which sensors were watching so the gap is legible.
Where the evidence is
Every run has a page: the commands, the reports, the findings and the review as posted. A public repository’s newest runs are on the board, drawn as a galaxy where each star is one run. A private repository’s runs are its owner’s, signed in.