Skip to content
IonWarpRouterTry for free
Guide

What is code review? How to review a pull request

Code review is a second engineer reading a change before it merges, to catch defects, security holes and design problems while they are cheap to fix. On GitHub it happens on the pull request: the author opens it, a reviewer comments line by line, and the change merges once it is approved.

A good review is fast and specific: it checks that the change does what it says, breaks nothing outside the diff and keeps the codebase simple. IonWarp runs that first pass on every pull request: Code Review traces each change across files, and its planner adds a specialist such as Security Review when the change needs one, so the human reviewer can focus on intent and design. This page is the reviewer's side; our pull request checklist covers the author's.

What a reviewer checks

  • Correctness

    The change does what the pull request says, including the edge cases: empty input, retries, timeouts and concurrent requests.

  • What it breaks elsewhere

    Callers, tests and contracts outside the diff that depend on what changed.

    Code ReviewOn Starter, Pro and Max

  • Security

    Authorization checks, untrusted input, secrets in logs, and new endpoints an attacker can reach.

    Security ReviewOn Starter, Pro and Max

  • Design and duplication

    One implementation of each thing: no second helper beside an existing one, no dead code left behind.

    AI ArchitectureOn Pro and Max

  • Docs that still match

    README, comments and error messages that describe what the code does after this change.

    Docs FreshnessOn Pro and Max

Code review checklist

  1. Read the description first

    Know what the change is meant to do before reading the diff. A pull request with no description gets that as its first comment.

  2. Check the tests

    A test covers the new behavior and would fail without the change.

  3. Follow the change outside the diff

    Search for the callers of anything renamed, removed or retyped.

  4. Look at the failure paths

    Errors are handled or surfaced, never swallowed, and a retry cannot charge or send twice.

  5. Check access and secrets

    New routes check who is calling, input is validated, and no secret lands in code or logs.

  6. Separate blocking from suggestions

    Comment on the code, not the author, mark what must change before merge, and approve once it has.

Starter is free for 3 seats. Pro is $49 a month with 5 seats, and Max is $149 a month with 10 seats. Compare plans

FAQ

Frequently asked questions

Sources

  1. Pricing — CodeRabbit, read 2026-10-02.

Get a review on your next pull request

Install IonWarp on GitHub. Starter is free for 3 people, with 15,000 credits to start.

Try for free