The decision
A score from 1 to 5 for risk, with each level described, plus noul questions such as "changes authentication or permissions", "changes database migrations" and "has no tests".
How to build it
- Write a GitHub Action that runs on
pull_request. - Build the state from the title, the description and a summary of the diff: files touched, lines changed, and a few hunks.
- Ask the questions, then label the pull request (
risk:high,needs-security-review) and request reviewers. - Keep humans in charge: the model only labels and requests.
Make it better
Label past pull requests with whether they caused an incident or a revert, and fine-tune on those. Your own history is the best signal.