Review every pull request
Inline findings with severity, category and confidence and a suggested change where one applies. At most ten findings at 0.75 confidence or higher.
CodeRabbit is a pull request review tool. Codna reviews every pull request with a clear verdict and opens the fix when you ask, from the same deterministic map it uses to fix bugs.
The problem
Codna closes it. Findings come with severity, category and confidence. A clean diff gets an approval. A reply of @codna fix on a finding opens a pull request with the fix, and the same map that scoped the review scopes the fix.
How Codna fixes it
Inline findings with severity, category and confidence and a suggested change where one applies. At most ten findings at 0.75 confidence or higher.
Approve when the diff is clean at medium and high and no earlier Codna thread is unresolved. Comment otherwise. Never request changes. Turn approvals off with review.approve: false.
Reply @codna fix, with write access, and Codna opens the fix as a pull request stacked on the branch. Codna never merges.
codna review . --pr 42 --post --effort high # on the PR: reply "@codna fix" on a finding
What you get
Claims about npm and PyPI packages are checked against the registries: contradicted findings are dropped, uncheckable ones marked Unverified.
Reviews run within 4 to 20 minutes by pull request size. A timed-out review says so and asks for @codna review or a smaller PR.
codna review in the terminal, mode: review in the Action, and the GitHub App run the same code path.
The proof
The only measured head-to-head Codna publishes is against Cursor: 87 matched bug-fix cases on identical checkouts, 5× fewer tokens, 1.7× faster, 87 of 87 verified, about $0.02 per fix. Everything else on this page describes Codna's own behaviour, not CodeRabbit's internals.
Codna reviews and fixes. Its check run is named codna review; its approval counts toward branch rules; and @codna fix turns a finding into a pull request.
Because a fix needs to know what a change reaches. Codna builds a dependency and blast-radius graph of the repository from its import patterns. No model call, zero tokens. The same graph scopes the fix that follows a finding.
Yes. Codna is a CLI, an MCP server, a GitHub Action and a GitHub App. Add it where it helps and keep the rest of your workflow.
Bring a key from Anthropic, OpenAI, Google Gemini, Groq, Mistral, OpenRouter or xAI, stored in your OS keychain with codna key set, or sign in and use the managed allowance. The repository map is built from import patterns, so it is not tied to one language. On-device recall covers Python, JavaScript, TypeScript, Go, Rust, Java, C, C++, C#, PHP and Ruby. Your own test command verifies the fix.
Understanding runs on your machine and spends no tokens. Only the evidence bundle or the diff reaches your model provider, with your key from the OS keychain. Set privacy.egress to fail-closed in codna.yaml and Codna runs your tests only under kernel-level network denial. Secret redaction is always on. On 87 matched bug-fix cases against Cursor, Codna averaged 16,159 total tokens and about $0.02 of model spend per verified fix, 5× fewer tokens and 1.7× faster. With your own key you pay your provider directly.
Related