Baloo Offers Self-Hosted AI Code Review for GitHub Pull Requests
Summary
Baloo is an open-source, self-hosted GitHub App for AI-assisted pull-request review. It reads a pull request's diff together with relevant repository context, then posts inline comments about logic bugs, security issues, missing error handling, and violations of project conventions. The agent uses PI to inspect files, search the repository, and reason beyond the changed lines; it can read AGENTS.md and CONTRIBUTING.md and follow a falsifiable review brief placed in the pull request description. Baloo runs reviews when pull requests are opened, reopened, synchronized, or marked ready for review, and tracks discussion threads across later commits to avoid duplicate or already-addressed feedback. Findings receive CRITICAL, HIGH, MEDIUM, or LOW severity handling: critical and high findings can request changes, medium findings can appear through Checks and a digest, and low findings can be filtered. An optional second model pass verifies findings to reduce false positives, while optional modules compare implementation with plan documents, detect documentation drift, review Dependabot updates, and store history and cost data in a PostgreSQL-backed dashboard. The service is deployed as a GitHub App under the operator's infrastructure, with repository installation scope and model credentials controlled by the operator; code is sent to the configured provider rather than to a Baloo-hosted backend. Supported provider options include Anthropic, Google, OpenAI, Amazon Bedrock, and Databricks AI Gateway. Docker deployment requires a GitHub App, webhook endpoint, permissions, private key, and API credentials. A local review script can run the same pipeline against a git diff without posting GitHub comments. The project positions Baloo as a complement to deterministic tools such as CodeQL, Semgrep, and Ruff, rather than a replacement for them, and is released under the MIT license.