To catch defects, security problems and design issues before they merge, and to spread knowledge of the codebase across the team.
What is code review? How to review a pull request
Code review is a second engineer reading a change before it merges, to catch defects, security holes and design problems while they are cheap to fix. On GitHub it happens on the pull request: the author opens it, a reviewer comments line by line, and the change merges once it is approved.
A good review is fast and specific: it checks that the change does what it says, breaks nothing outside the diff and keeps the codebase simple. IonWarp runs that first pass on every pull request: Code Review traces each change across files, and its planner adds a specialist such as Security Review when the change needs one, so the human reviewer can focus on intent and design. This page is the reviewer's side; our pull request checklist covers the author's.
What a reviewer checks
Correctness
The change does what the pull request says, including the edge cases: empty input, retries, timeouts and concurrent requests.

What it breaks elsewhere
Callers, tests and contracts outside the diff that depend on what changed.
Code ReviewOn Starter, Pro and Max

Security
Authorization checks, untrusted input, secrets in logs, and new endpoints an attacker can reach.
Security ReviewOn Starter, Pro and Max

Design and duplication
One implementation of each thing: no second helper beside an existing one, no dead code left behind.
AI ArchitectureOn Pro and Max

Docs that still match
README, comments and error messages that describe what the code does after this change.
Docs FreshnessOn Pro and Max
Code review checklist
Read the description first
Know what the change is meant to do before reading the diff. A pull request with no description gets that as its first comment.
Check the tests
A test covers the new behavior and would fail without the change.
Follow the change outside the diff
Search for the callers of anything renamed, removed or retyped.
Look at the failure paths
Errors are handled or surfaced, never swallowed, and a retry cannot charge or send twice.
Check access and secrets
New routes check who is calling, input is validated, and no secret lands in code or logs.
Separate blocking from suggestions
Comment on the code, not the author, mark what must change before merge, and approve once it has.
Starter is free for 3 seats. Pro is $49 a month with 5 seats, and Max is $149 a month with 10 seats. Compare plans
Frequently asked questions
Keep pull requests small, review them within a day, read the description before the diff, comment on the code rather than the author, and separate blocking issues from suggestions.
A pull request is the proposed change. The code review is the reading and discussion of it before it merges.
An AI model reads the pull request and the code around it and posts findings before a human reviews it. IonWarp runs Code Review on every pull request and adds specialist reviewers when a change needs them.
No. It takes the first pass (defects, security, duplication) so the human reviewer can spend their time on intent, design and product decisions.
Sources
- Pricing — CodeRabbit, read 2026-10-02.
Get a review on your next pull request
Install IonWarp on GitHub. Starter is free for 3 people, with 15,000 credits to start.
Try for free