[AI code review]

GitHub Copilot code review and Aevral, at a glance

GitHub Copilot code review reviews pull requests for bugs, code-quality issues, and security issues, and suggests fixes in the GitHub UI.

Copilot code review runs where you already merge: it reviews each pull request for bugs, code-quality issues, and security issues, and suggests fixes in the GitHub UI. Aevral is built for a different reading of the same change: does this diff widen who has access to what. With Aevral's opt-in PR review, the two reviews sit side by side on the same pull request: Copilot code review doing the review it states, and Aevral adding the authorization and business-logic reading.

GitHub Copilot code review focuses on

  • Reviewing pull requests for bugs, quality, and security issues.
  • Suggesting fixes directly in the pull request.
  • Running inside GitHub, where you already merge.

Aevral adds alongside

  • The access reading of the same diff: dropped ownership checks, caller-controlled object references, gates that went from a role to a login.
  • With the opt-in add-on: up to two findings per review, grounded on the added lines, posted as a Check plus inline comments. It never blocks a merge.
  • A finding as a lead with evidence: the author decides with full information.

Run them together

Let Copilot code review run its review and suggested fixes; let Aevral add the authorization and business-logic reading of the same pull requests, with the opt-in add-on.

Copilot code review and Aevral, in depth; Aevral PR security review.

Also alongside


Scan your whole repo for access bugs.

One GitHub App. A report with evidence. A prompt for the agent you already use.