Baloo is an open source GitHub App for AI pull request review. It installs on your repositories, reads PR diffs and relevant project context, and posts actionable review comments that catch bugs, security issues, missing error handling, and repository guideline violations before humans review the code.
Baloo is built for teams that want a self-hosted AI code review agent instead of a hosted SaaS reviewer. You run the service, control the GitHub App installation scope, and provide your own model API keys for Claude or Gemini.
Website: BlueBear Security
-
Catches what linters can't β logic errors, silent failures, security antipatterns, missing error handling
-
Respects your conventions β reads
AGENTS.mdandCONTRIBUTING.mdfrom your repo and enforces them -
Follows per-PR review briefs β when a PR includes
## Review guidance for Baloo, Baloo verifies those falsifiable, context-aware checks and cites them in findings -
Posts like a teammate β inline comments on specific lines, severity labels, approval/request-changes decisions
-
Runs on every push β new commits get reviewed automatically, with discussion thread tracking across iterations
-
Self-hosted & private β your code never leaves your infrastructure; bring your own API keys
-
AI code review for GitHub pull requests β review opened, reopened, synchronized, and ready-for-review PRs
-
Security review assistance β flag injection risks, unsafe auth patterns, secret handling mistakes, and missing validation
-
Repository guideline enforcement β apply project-specific rules from
AGENTS.mdandCONTRIBUTING.md -
Dependency update review β use Dependabot-aware prompts for dependency PRs
-
Plan fidelity checks β compare an implementation against plan documents before approval
-
Local review before opening a PR β run the same review pipeline against a local git diff
When a PR is opened or updated, Baloo posts a review:
π» Baloo review completed in 45s.
Found 2 issue(s): 0 critical, 1 high, 1 medium, 0 low.
Inline comments appear on the exact lines:
[HIGH] Security β src/auth.py:55
SQL query uses string concatenation instead of parameterized bindings. This is vulnerable to SQL injection.
Recommendation: Use parameterized queries: cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))
| Feature | Description |
|---|---|
| Agentic review | Uses PI to read files, grep patterns, and explore the repo β not just the diff |
| Multi-provider | Runs every agent through the configured Anthropic, Amazon Bedrock, Google, OpenAI, or Databricks AI Gateway provider |
| Severity routing | CRITICAL/HIGH β request changes; MEDIUM β Checks annotations + collapsible PR digest; LOW β filtered |
| Guideline enforcement | Reads repo-level AGENTS.md /CONTRIBUTING.md and flags violations |
| Per-PR review briefs | Reads ## Review guidance for Baloo in the PR description and verifies falsifiable, diff-specific checks |
| Discussion tracking | Follows up on existing threads, skips duplicates, detects addressed feedback |
| Fidelity analysis | Optionally compares PR against design plan documents |
| Documentation drift | Optionally asks authors to update mapped docs when implementation changes make them stale |
| FP reduction | Optional second LLM pass to verify findings and drop false positives |
| Dashboard | Optional PostgreSQL-backed review history UI with cost tracking |
| Dependabot-aware | Specialized review logic for dependency update PRs |
| Local dry-run | Run scripts/local_review.py against a local git diff β no GitHub webhook or posted comments |
| Need | Baloo's fit |
|---|---|
| Hosted AI reviewer alternative | Self-host Baloo as your own GitHub App and choose the model credentials |
| Static analysis complement | Baloo reviews intent, behavior, edge cases, and repo-specific conventions that linters may not express |
| GitHub Copilot review complement | Baloo runs automatically as an app on every PR update and can route findings to reviews or Checks |
| Security review workflow | Baloo combines LLM review with severity routing, false-positive verification, and GitHub-native comments |
Go to GitHub Settings β Developer settings β GitHub Apps β New GitHub App:
- Webhook URL : Your public HTTPS endpoint (e.g.
https://baloo.example.com/webhook) - Permissions : Pull requests (read/write), Contents (read), Checks (read/write)
- Events : Pull request, Check run, Check suite (the last two power the Re-run button)
- Download the private key
.pemfile
git clone https://github.com/Blue-Bear-Security/baloo-bear.git
cd baloo-bear
cp .env.example .env
docker compose up --build
Install the GitHub App on your repositories. Open a PR β Baloo will review it automatically.
π Full setup guide: docs/getting-started.md
π Get sharper reviews: docs/how-to-get-the-most.md β conventions, per-PR review briefs, and workflows that turn Baloo into a context-aware reviewer
ββββββββββββββββ webhook βββββββββββββββββββββ
β GitHub β ββββββββββββββββ β FastAPI β
β (PR event) β β webhook_handler β
ββββββββββββββββ ββββββββββ¬βββββββββββ
β
ββββββββββΌβββββββββββ
β PI Agent (RPC) β
β read / grep / β
β find / ls β
ββββββββββ¬βββββββββββ
β
ββββββββββΌβββββββββββ
β Processor β
β filter β route β
β β decide β
ββββββββββ¬βββββββββββ
β
ββββββββββββββΌβββββββββββββ
βΌ βΌ βΌ
ββββββββββββ ββββββββββββ ββββββββββββ
β Review β β Checks β β Dashboardβ
β comments β β API β β (opt.) β
ββββββββββββ ββββββββββββ ββββββββββββ
baloo/
βββ agent/ # PI runtime, prompts, structured output parsing
βββ config/ # Settings (env + DB runtime overlay)
βββ db/ # PostgreSQL models + migrations (optional)
βββ dashboard/ # Review history UI (optional)
βββ documentation/ # Documentation drift analysis (optional)
βββ fidelity/ # Plan-vs-implementation analysis (optional)
βββ github/ # Webhooks, API client, auth, Checks API
βββ processor/ # Findings filter, severity routing, decisions, FP verification
Settings are configured via environment variables; allowlisted agent knobs can also be overridden at runtime when DATABASE_ENABLED=true. Key variables:
| Variable | Default | Description |
|---|---|---|
GITHUB_APP_ID |
β | Numeric GitHub App ID |
GITHUB_PRIVATE_KEY |
β | Path to .pem file or inline PEM |
GITHUB_WEBHOOK_SECRET |
β | Webhook signature secret |
ANTHROPIC_API_KEY |
β | Anthropic API key |
GEMINI_API_KEY |
β | Google Gemini API key (when using the Google provider) |
AGENT_PROVIDER |
anthropic |
LLM provider for all agents: anthropic ,google ,openai ,amazon-bedrock ,databricks |
AGENT_MODEL |
sonnet |
Model short name: flash ,haiku ,sonnet ,gemini-pro ,opus |
REVIEW_AUTO_APPROVE |
false |
Auto-approve PRs with no blocking findings (opt-in) |
REVIEW_MIN_SEVERITY |
MEDIUM |
Minimum severity to post |
FP_VERIFICATION_ENABLED |
true |
Enable LLM false-positive verification |
DATABASE_ENABLED |
false |
Enable PostgreSQL review history |
DASHBOARD_ENABLED |
true |
Enable review dashboard UI (needs DATABASE_ENABLED + credentials) |
REPO_CACHE_ENABLED |
true |
Check out the PR repo so the agent reads real code, not just the diff |
REPO_SANDBOX_MODE |
bwrap |
Sandbox the agent subprocess to the review worktree (falls back to off if unavailable) |
FIDELITY_ENABLED |
true |
Compare PRs against plan docs |
DOCUMENTATION_DRIFT_ENABLED |
false |
Enable PR-time documentation drift checks |
Full reference: docs/configuration.md
π Full documentation β Feature guides, configuration reference, and more
Feature guides:
- How to Get the Most Out of Baloo β Conventions, per-PR review briefs, high-signal workflows
- Review Agent β How the agentic review works
- Guidelines Enforcement β Repo convention checking
- Fidelity Analysis β Plan-vs-implementation scoring
- Documentation Drift β PR-time stale docs detection
- Models β Supported providers, models, and tiers
- Severity Routing β How findings reach developers
- Discussion Tracking β Thread follow-ups across iterations
- FP Verification β False-positive reduction
- Dashboard β Review history UI
uv sync && npm install # install deps
uv run python main.py # run locally
uv run pytest # test
uv run ruff check baloo # lint
uv run black --check baloo # format check
When changing Python dependencies, regenerate the hash-pinned production requirements before committing:
uv export --frozen --no-dev --no-emit-project --no-header --output-file requirements-prod.txt
CI checks this file against uv export, and the Docker image installs production dependencies from it.
You can run the same review pipeline against your working tree before opening a PR. The script builds a synthetic pull request from a git diff (base...head), loads AGENTS.md / CONTRIBUTING.md from the head ref when present, and prints findings to stdout β nothing is posted to GitHub.
Requires the same LLM credentials as production (for example ANTHROPIC_API_KEY or GEMINI_API_KEY in your environment).
uv run python scripts/local_review.py
uv run python scripts/local_review.py --base origin/main --head HEAD
uv run python scripts/local_review.py --json
uv run python scripts/local_review.py --fail-on-blocking # exit 1 if CRITICAL/HIGH findings
uv run python scripts/local_review.py --git-workdir /path/to/other-repo --base origin/main --head HEAD
See docs/development.md for the full contributor guide.
Yes. Baloo runs as your own service and GitHub App. You control deployment, repository installation scope, database persistence, and model credentials.
No. Baloo does not require a Baloo-hosted backend. The running service reads repository content through your GitHub App installation and sends review context to the LLM provider you configure.
Baloo supports Anthropic, Amazon Bedrock, Google, OpenAI, and Databricks AI Gateway providers. The selected provider applies to every agent. See docs/features/models.md and docs/features/databricks.md.
No. Baloo is a review agent that complements static analysis. Keep deterministic scanners for known patterns and use Baloo for reasoning-heavy findings, project conventions, and PR-level review context.
Yes. Use scripts/local_review.py to run a dry review against a local git diff.
- Issues & Bug Reports :GitHub Issues
- Feature Requests :GitHub Issues
- Questions : Open aGitHub Discussion or file an issue
Contributions are welcome! See CONTRIBUTING.md for workflow and conventions, and AGENTS.md for AI-agent-specific guidance.
Please read SECURITY.md before reporting vulnerabilities.
MIT β see LICENSE.