DevOps & Infrastructure Code Review on Every PR — IonWarp
Skip to content
IonWarpRouter
AgentsPricingBenchmarks
Try for free
Infrastructure code review

Add Security Review_Security Review
to every pull request.

Route pull requests to open source models for a multi-dimensional review.

Try for free

Pull request review preview

IonWarpbotcommented 15 min ago

IonWarp Review — PR #87

3 issues| 2 P0 1 P1
#SevIssueFile
1Request ID lets a member read another workspaceapi/projects/[id].ts
2Provider secret included in the public client bundleapp/config.ts
3Unsigned webhook can enqueue account actionsapi/webhooks.ts
api/projects/[id].ts
42434445
−+++
const project = await projects.get(params.id);const project = await projects.getForMember({  projectId: params.id, userId: session.user.id,});

A signed-in user can cross the workspace boundary · Security Review

The endpoint authenticates the caller but never binds the requested project to their membership. Changing the URL ID returns another workspace’s private project. Resolve membership before returning it.

Suggested fixAI fix prompt

How to review infrastructure-as-code changes

Infrastructure changes arrive as pull requests like any other code: a Terraform module, a Helm values file, a Kubernetes manifest, a Dockerfile, a GitHub Actions workflow. Linters and policy scanners check them against rules, and they belong in CI. tflint finds possible errors such as invalid instance types and enforces naming conventions;[1] Checkov scans Terraform, Kubernetes, Helm, Dockerfiles and CI workflow files for security and compliance misconfigurations with over 1,000 built-in policies;[2] actionlint checks GitHub Actions workflows for syntax errors, expression type errors and script injection;[3] hadolint lints Dockerfiles against best practices.[4]

A rule can say a value is wrong. It cannot say what the pull request was trying to do, what else in the repository depends on the line it changed, or what an outside caller can now reach. That is review work. Install the IonWarp GitHub app and every pull request — infrastructure included — is reviewed by AI reviewers that read the diff and the repository around it. A planner picks the reviewers each diff calls for.

Code Review traces the change across files and names its blast radius; Security Review looks for exposed secrets, auth and trust-boundary mistakes and newly exposed attack surface; CI/CD Performance flags pipeline changes that make every future run slower or weaker; SOC 2 Review flags a deploy gate or encryption setting the change turned off. IonWarp is not a linter and has no Terraform- or Helm-specific reviewer: keep tflint, Checkov, hadolint and actionlint for syntax and policy, and let IonWarp review the intent, the blast radius and the security of the change.

What a reviewer catches in an infrastructure pull request

  • A secret in a deploy config

    A token or key moved into a config file, a container environment or a log line, where everyone who can read the repository or the run can see it.

    Security Review →On Starter, Pro and Max

  • Newly exposed attack surface

    An endpoint, webhook or access rule the change opens to an outside caller — the finding names who can reach it and what they gain.

    Security Review →On Starter, Pro and Max

  • A change other files still depend on

    A renamed value, a changed default or a removed key that other files in the repository still read, traced to where it breaks.

    Code Review →On Starter, Pro and Max

  • A cache that never hits

    A cache step removed, or keyed so it never restores, so every future run repeats a cold dependency build.

    CI/CD Performance →On Max

  • A weaker pipeline

    A required check that can no longer fail, cancel-in-progress dropped, or a heavy workflow that now runs on every change.

    CI/CD Performance →On Max

  • A deploy that skips review

    A deploy workflow that bypasses environment protection, a CODEOWNERS rule removed for infrastructure paths, or an at-rest encryption flag turned off.

    SOC 2 Review →On Max

Linters check the rules; IonWarp reviews the change

  1. Keep your linters in CI

    tflint, Checkov, hadolint and actionlint keep checking syntax and policy on every push. IonWarp changes nothing about them and uses none of your CI minutes.

  2. Open the pull request

    IonWarp reads every reviewable file in the diff — Terraform, YAML, Dockerfiles, workflows and application code alike — and the repository around it. Lock files and generated, vendored and binary files are skipped.

  3. The reviewers post findings

    Each reviewer the diff calls for posts findings with a severity, a suggested fix and an AI fix prompt.

    Code Review →On Starter, Pro and Max

  4. Fix, push, re-review

    The next push is re-reviewed, and the findings ledger shows what was resolved, declined with a reason, or still open.

IonWarp next to infrastructure linters and scanners

Tool facts are from each project's README on GitHub, read on 2026-10-01. Each answers a different question, and they run side by side.

IonWarp next to infrastructure linters and scanners
CriterionIonWarptflintCheckovactionlint
What it isA GitHub app that reviews every pull request with a swarm of AI reviewersA pluggable Terraform linter[1]A static code analysis tool for infrastructure as code, and a software composition analysis tool for images and open source packages[2]A static checker for GitHub Actions workflow files[3]
What it readsEvery reviewable file in the diff — Terraform, YAML, Dockerfiles, workflows and application code — plus the repository around itTerraform; each feature comes from a plugin[1]Terraform, CloudFormation, Kubernetes, Helm, Kustomize, Dockerfile, Ansible, Bicep, ARM and OpenTofu files, and CI workflow files including GitHub Actions[2]GitHub Actions workflow files, and the scripts in run steps through shellcheck and pyflakes[3]
What it findsDefects in the change and their blast radius: exposed secrets, newly exposed attack surface, slower or weaker pipelines, disabled gatesPossible errors such as invalid instance types for AWS, Azure and GCP, deprecated syntax, unused declarations, best practices and naming conventions[1]Security and compliance misconfigurations from over 1,000 built-in policies; secrets; CVEs in open source packages and images[2]Syntax and expression type errors, wrong action inputs, script injection by untrusted inputs and hard-coded credentials[3]
How it decidesAI reviewers judge the change in the context of the repository and explain each finding with a suggested fixRules provided by its plugins[1]Built-in policies, plus custom policies written in Python or YAML[2]Its own checks against workflow syntax and expression types[3]
Where it runsIonWarp's hosted service, through its GitHub app — no CI minutesA binary or Docker image you run; a setup-tflint action runs it on GitHub Actions[1]A CLI installed with pip or run from a Docker image[2]A command you run in your repository, locally or on GitHub Actions[3]

Every finding, followed to the fix.

Each reviewer comments on the line it is about, with the change that fixes it. Reply learn: to teach the whole project, push the fix, and the re-review closes the finding.

api/projects/[id].tsPR #87
IonWarpbotcommented on line 45

P0A signed-in user can cross the workspace boundary · Security Review

The endpoint authenticates the caller but never binds the requested project to their membership. Changing the URL ID returns another workspace’s private project. Resolve membership before returning it.

Suggested change
− const project = await projects.get(params.id);+ const project = await projects.getForMember({+   projectId: params.id, userId: session.user.id,+ });
Commit suggestionAI fix prompt
MmayaAuthor

learn: every project read goes through projects.getForMember.

IonWarpbot

✅ Learned — every reviewer of this project will read it.

maya pushed 1 commit3520158Resolve membership before returning a project

IonWarpbotre-reviewed 3520158

Round 2 FixedA signed-in user can cross the workspace boundary

Pricing

Best pricing in the game.

One workspace price with seats included. Credits pool across your team. Unlimited repos on every plan.

Starter

$0 /mo

Try AI PR review.

  • Starter Swarm across 2 models
    • Code Review
    • Security Review
  • 3 seats included
  • 15,000 credits to start, then 5,000/mo
  • Unlimited repos
Get Started

Pro

Most popular
$49 /mo

Get AI PR review right from day 1.

  • Pro Swarm across 3 models
    • Docs Freshness
    • AI Architecture
    • Log & Errors
    • Cost Review
  • 5 seats included
  • +25,000 credits/mo
  • +$29/mo per added seat
  • Unlimited repos
Choose Pro

Max

$149 /mo

Scale AI PR review.

  • Max Swarm across 5 models
    • UX Review
    • API Performance
    • Analytics Review
    • SEO Review
    • Changelog
    • CI/CD Performance
    • Plan Review
    • Repeat-Failure Learnings
    • SOC 2 Review
  • 10 seats included
  • +75,000 credits/mo
  • +$29/mo per added seat
  • Unlimited repos
  • Priority support
Choose Max
Enterprise

Custom swarms + credits · GitHub Enterprise · SSO/SAML + audit logs · Custom security review + SLA

Contact us
IonWarp for Startups

Get the Max plan at half price. — Full Swarm. Proactive PRs.

Apply
FAQ

Frequently asked questions

No. IonWarp has no Terraform- or Helm-specific reviewer and does not check syntax, formatting or naming. Keep tflint in CI for that. IonWarp reviews what a change does: its intent, its blast radius across the repository and its security.

No. Checkov checks infrastructure files against a library of built-in policies and is worth keeping in CI. IonWarp is a reviewer, not a policy engine: it reads each pull request in the context of your repository and explains what the change breaks or exposes, with a suggested fix.

Every reviewable file in the pull request: Terraform, Kubernetes and Helm YAML, Dockerfiles, GitHub Actions workflows and actions, build scripts and application code. Lock files and generated, vendored, fixture and binary files are skipped, and you can exclude more paths with the project's path filters.

No. IonWarp reads the code in pull requests. It does not build images, run terraform plan or connect to your cluster or cloud account, so it reports no CVEs in images and no drift in live infrastructure. Use an image or cloud scanner for those.

No. Reviews run on IonWarp's hosted service, so they use none of your Actions runners or minutes.

Code Review runs on Starter, Pro and Max, Security Review on Starter, Pro and Max, CI/CD Performance on Max and SOC 2 Review on Max. Starter is free for 3 seats with 15,000 credits on signup; Max is $149/mo for the workspace with 10 seats included.

IonWarp runs a multi-domain swarm — code review, security, UX, SEO, performance, analytics — across multiple models, not one, at one workspace price: a 5-seat team pays $49/mo on Pro, with unlimited repos on every plan. Our Greptile vs CodeRabbit comparison cites each vendor's current pricing page.

Deepseek v4.1 Flash, GLM 5.3 Flash, GPT 5.6 Luna Pro. Each reviewer is pinned to the model that measured best for its lens, and the pins are re-trialed as models and prices move. On Enterprise you can bring your own keys.

Starter $0/mo (3 seats included), Pro $49/mo (5 seats included), Max $149/mo (10 seats included) — one workspace price, extra seats à la carte. Each tier unlocks a deeper review Swarm and more credits, and credits pool across your team. Unlimited repos on every plan.

Yes — Get the Max plan at half price.. Full Swarm. Proactive PRs. See the Startup discount section above.

Yes — the Learner agent tracks recurring findings and human feedback, so the same issue stops getting flagged once your team resolves the pattern. Every review sharpens the next.

Yes. Drop an agents.md in your repo and IonWarp runs your custom checks on every PR, using any model you choose. Available on Pro and Max.

GitHub Enterprise support, SSO/SAML, audit logs, a custom security review, an SLA, and a dedicated Slack channel.

Sources

  1. TFLint — terraform-linters on GitHub, read 2026-10-01.
  2. Checkov — bridgecrewio on GitHub, read 2026-10-01.
  3. actionlint — rhysd on GitHub, read 2026-10-01.
  4. Hadolint — hadolint on GitHub, read 2026-10-01.

Put a reviewer on every infrastructure change

Install IonWarp on GitHub. Code Review runs on Starter, Pro and Max and Security Review on Starter, Pro and Max — Starter is free for 3 seats — and CI/CD Performance runs on Max.

Try for free
IonWarp
All agentsDocsBlogContactSecurityPrivacyTerms