alden

Briefings and checks

alden review produces a briefing. Every claim in it says how it was checked, so you can decide what to trust.

What a briefing contains

Checks marked ~ are heuristic: they infer from the diff (and the code graph) rather than proving something. Treat them as leads.

The checks

Check Flags Severity
Likely secrets (secrets.likely) Added lines that look like credentials: known key formats and high-entropy strings. Values are masked in the output. High
CI status (ci.status) CI failing on the latest commit. Skipped when CI is pending, absent, or for local changes. High
Callers outside the diff (callers.outside) Changed public code that's still called from places the PR didn't touch. See The code graph. High when removed or re-signed code is still called, medium if only by name match, low for behaviour changes
Database migrations (migrations.changed) Changed migrations. High when they drop, rename or reshape data (SQL, Django, Laravel, Doctrine). Medium or high
Changed public signatures (signatures.changed) Exported functions, classes and methods whose signature changed or that were removed, in TS/JS, Python, PHP and Go. Go and PHP use the code graph; TS/JS and Python read the diff. Low or medium
Code changed without tests (tests.missing) Code changes with no test changes alongside them. Medium
Dependencies (dependencies.changed) Added, removed or re-versioned dependencies in package.json, composer.json, go.mod, requirements.txt and pyproject.toml. Low, or medium for risky changes
Configuration and environment (config.changed) Config files (.env, settings, Docker, Terraform, CI, deploy config) and new environment variable references. Medium
Sensitive paths (paths.sensitive) Files matching your sensitive paths. Medium

How Alden picks where to look

"Needs your eyes" holds at most 3 places:

  1. The most severe findings come first. Alden takes them in turn across checks, so one noisy check can't fill every slot.
  2. Each file and each directory gets at most one slot, so ten workflow files don't crowd out everything else. Secrets are exempt.
  3. CI status never takes a slot: a failing build is already at the top of the checks, and the fix is the author's.
  4. Lockfiles never take a slot, except for secrets.

A low-severity check gets one slot at most, so a harmless change with many callers doesn't fill the list.

With a model, its medium and high findings fill the slots that deterministic checks leave. A high-severity check always keeps its slot. Model findings that point at a line outside the diff are dropped, and the footer counts them.

Local reviews

alden review with no argument reviews your uncommitted changes (staged, unstaged and untracked) against HEAD. It's the same briefing, without CI status. Use it before opening a PR.