AI code review should end in a verdict.
A review that lists possibilities is another thing to read. Codna posts findings with a severity, a category and a confidence score, drops anything below 0.75 confidence, caps the list at ten, and checks dependency claims against npm and PyPI before posting.
Then it decides. A clean diff at medium and high gets an approval that counts toward branch rules. Anything else is a comment. When a required check is red, the review says so next to the verdict. Re-reviews cover only the new commits.
Core pattern
- Review the diff read-only, with no write token.
- Post findings with severity, category and confidence.
- Ground dependency claims against the registry.
- Approve a clean diff. Comment otherwise. Never request changes.
- Re-review only what changed.