Changelog

What shipped.

Recent changes to Codna, described as you see them on a pull request, in the terminal and in CI.

Changelog

PR
Sep 2026Review

A clear verdict on every pull request

codna review now ends in an approval when the diff is clean at medium and high and no earlier Codna thread is unresolved. Otherwise it comments. It never requests changes.

  • Approvals count toward branch rules. Turn them off with review.approve: false.
  • When a required check is red, the review says so next to the verdict: the verdict is about the diff, not a merge go-ahead.
  • Dependency findings on npm and PyPI manifests are checked against the registries: contradicted findings are dropped, uncheckable ones are marked Unverified.
App
Sep 2026GitHub App

Checks you can see, from push to verdict

One check run per job, named codna review, codna fix or codna secure.

  • The codna review check appears as queued the moment you push. A superseded commit ends neutral; the new head is reviewed.
  • Merge queues are supported: the group commit inherits the pull request's verdict.
  • Reviews run within 4 to 20 minutes by pull request size. A timed-out review says so and asks for @codna review or a smaller PR.
Fix
Sep 2026GitHub App

Fixes from a red check, a comment or a label

A failing check suite on a pull request is triaged before anything is spent.

  • Infrastructure failures end neutral and cost nothing; code failures hand the failing step and log to the agent. One CI-failure fix per pull request head per day.
  • @codna fix works as a reply on a Codna finding and needs write access. Forks get the suggested change instead. Every refusal is explained in a reply.
  • Fix commits are authored by codna-ai[bot]. Set fix.test_command in codna.yaml when your tests are not pytest.
CLI
Sep 2026CLI

Incremental review, effort levels, and new commands

codna review re-reviews only the commits since Codna's last review. Pass --full for the whole pull request.

  • --effort low, medium or high sets the review depth: higher is more thorough and costs more. Defaults: at most 10 findings at 0.75 confidence or higher.
  • codna impact lists the tests a diff can affect, offline and for zero tokens. codna memory export writes a compact read-only recall index.
  • codna report files a bug, feature or question to the public feedback repository from the terminal.
CI
Sep 2026GitHub Action

Fix, review and secure in your own CI

thyn-ai/codna-action@v1 installs codna from PyPI and runs the same commands you run locally.

  • mode: fix opens a pull request and never merges. mode: review posts findings and a verdict on the pull request. mode: secure classifies SARIF findings read-only.
  • Pin package-spec to a codna version and the action to a full commit SHA for reproducible runs.
  • Review in CI gets the same approvals, red-check notes and registry-checked dependency findings as the App.
MCP
Sep 2026MCP

Five tools for Cursor and Claude

codna mcp install --client cursor or --client claude wires the server into your editor without writing credentials.

  • codna_triage, codna_fix, codna_secure, codna_recall and codna_report_bug.
  • codna_fix plans by default; open_pr needs a git URL and a write token in the server environment.
  • Recall runs on Telys, on-device, from an index under your home directory.