Skip to content

Releases: openqodex/openqodex

openqodex@0.9.0

Choose a tag to compare

@github-actions github-actions released this 08 Oct 18:44
2811974

Minor Changes

  • #62 45267e0 Thanks @siddhant-mohan! - - init follows CLAUDE_CONFIG_DIR and CODEX_HOME: it finds Claude Code and Codex by those folders and writes the skill, the instructions and the push hook where each agent reads them, never half in the default folder.

    • Inside Cursor's agent, review tries Cursor first among the reviewers, as it does for Claude Code and Codex, and init knows it runs inside an agent.
    • init replaces a skill file that holds the skill exactly as some version shipped it, such as the copy npx skills add writes, with the skill it keeps up to date. Before, it kept that copy as yours and it never updated. A copy you edited is still left alone.
    • init asks one question, "Write these files?", after a plan that lists every file under "For you, on this machine" or "For the team, in this repo". The git pre-push hook and the team review section are lines of that plan, on by default; --hook none and --no-repo leave them out. Before, it asked up to three questions.
    • Inside Claude Code, Codex or Cursor with no terminal, init writes its plan without --yes. With no terminal and no agent it still exits 2, now after printing the plan and the flags that change it.
    • Answering no to "Write these files?" stops init: it writes nothing, removes nothing from ~/.openqodex and starts no review. Before, the review after init still ran and created the .openqodex folder, and old runtimes, receipts and locks were cleaned up anyway.
    • When init finds no coding agent and has a terminal, it asks which of Claude Code, Cursor, Codex CLI and Cline to install into. Without a terminal it still exits 2 with the --agent list.
    • The line init adds to each agent's global instruction file (such as ~/.claude/CLAUDE.md) is now one sentence: "Before any push, review the change with the openqodex skill." The next init puts it in place of the longer section of earlier versions. Project scope and the Cursor and Cline rules keep the longer section.
    • After writing, init lists what it wrote for you, with the command that undoes it, and what it wrote for the team, to commit, and names init --project, which puts the agent files inside the repository instead (the scanners and init's record stay in ~/.openqodex).
    • Every command init prints (the next review, the undo, init --project) starts with the launcher's full path, so it runs when pasted: an npx install puts no openqodex on your PATH, and init never edits a shell profile. Its last line is the command to run next.
    • init checks every reviewer at once after writing and prints "Reviewer ready" with the one it found, or "No reviewer can start yet" with each one's reason and fix and the review --agent command. It no longer runs a first review that cannot start, and it ends with one line: First review: finished, incomplete, skipped or unavailable.
    • The review init ends with waits up to two minutes for a scanner its change needs that init has just started downloading, then names any still downloading. Before, it ran with downloads off, so the first review had the fewest scanners of any.
    • The README, the quickstart and the skill give agents one install line, npx -y openqodex@<version> init --yes --agent <host>: the same install as init in a terminal, push check included. npx skills add openqodex/openqodex -g stays as the skill-only option, labelled so, in user scope so it writes nothing into the repository.
    • init --yes keeps what a repository chose before (--no-repo, --hook none) and takes the defaults only for what it never answered. Before, --yes put the team review section back where the repository had left it out.
    • With no terminal, no agent and no --yes, init writes nothing at all, its record of choices included, and runs no review, even when there is no file to write.
    • init says every push from the repository is checked only when its git pre-push hook is in place. Where husky or lefthook runs the hooks, or a pre-push hook it did not write is there, it says the hook is not set up and what to add.
    • init decides each write from where the path really lands, never from its spelling: it never writes through a symbolic link that lies in the repository, in either scope (an agent folder set inside the repository with CLAUDE_CONFIG_DIR or CODEX_HOME included), nor to a place outside the repository, your home folder, the agents' folders and ~/.openqodex. It checks each path when it plans the file and again right before the write lands. A link outside the repository, such as a dotfiles link into your home, is still followed; one that lands outside those folders is now refused.
    • Every file init writes, renames or removes, OpenQodex's own record, launcher and runtime copies in ~/.openqodex included, goes through one checked path that knows each folder by its identity on disk, not its spelling: a repository named in another case or Unicode form, or a work tree inside its bare repository, no longer slips past the link check, and install.json or runtime/ as a link to somewhere else is refused, never written or cleaned up through.
    • In a terminal, init also asks "Write these files?" when it would only record a choice or clean up old runtimes, receipts or lock files.
    • A skill file that spells out the placeholder the ownership check uses is kept as yours.
  • #62 568d264 Thanks @siddhant-mohan! - review now ends with a short receipt instead of the whole report: the verdict, the reviewer's summary, one line per finding (number, severity, category, title, file and line) and the absolute paths of report.html and report.md, which --quiet keeps. --format markdown, json and sarif still print the whole report. Each review writes report.html, one local page with each changed file as a diff and each finding under its line, then the coverage, the scanners and the blast radius; it runs no script, loads nothing and redacts the secrets the scanners found. The skill (which guide skill prints), the project Cursor and Cline rules, the team section and the push gate tell the agent to show the receipt, ask "Fix all, or tell me which?" and fix only the findings you name; the new openqodex findings 1,3 prints the named findings in full. The report prints the reviewer's summary, and its coverage says "Files the reviewer opened" and "Files not opened (their changed lines were in the brief)". Each line of a multi-line secret, such as a private key, is now redacted wherever it appears alone. --report-dir reached through a symbolic link stops review and scan with exit 2 before anything is written, and a link the repository holds is refused at every write after that. When the first review after init could not write report.html, init says First review: incomplete with that reason.

  • #62 584ee32 Thanks @siddhant-mohan! - Scanners now download only where a repository's files call for them. doctor --install inside a repository installs the scanners its files need, less scanners.disable and review.paths.exclude, and prints why for each one; doctor --install --all-scanners installs every scanner, as doctor --install did before. init picks its downloads the same way, from tracked and untracked files alike, prints one line per scanner it downloads, such as brakeman: Rails app in backend/, and init --dry-run prints those lines without downloading. The GitHub Action installs what the repository needs and keys its cache on the pinned scanner versions and those scanners, so a release that pins nothing new reuses the cache.

    Each changed file now belongs to its nearest project, read from that project's manifests as text. brakeman runs only for a file in a Rails app (rails in the Gemfile or Gemfile.lock, and config/application.rb or bin/rails), from that app's folder, so a Rails app in backend/ is scanned and a React Native app's CocoaPods Gemfile no longer pulls in brakeman. rubocop no longer runs for a Gemfile alone and loads its Rails cops only in a Rails app. oxlint runs its React, accessibility and Next.js rules in projects that depend on them, and then the reviewer is no longer handed the useEffect dependency pattern oxlint already checks. ruff adds its Django, FastAPI and Airflow rules in those projects. shellcheck checks an extensionless script whose first line names sh or bash. scan.json records the projects of the change.

    osv-scanner moves to 2.6.0 and reads bun.lock, uv.lock, pdm.lock, pylock.toml, the NuGet lockfiles and more; it no longer gets go.sum, which it cannot read and which stopped the whole lockfile check. It sends dependency names and versions to osv.dev only: its deps.dev and file-hash lookups are off. Aliased advisories are one finding, and a lockfile with no package is no longer a failure.

    oxlint moves to 1.86.0 and installs from its GitHub release, checked against its sha256, with no npm. semgrep, bandit, brakeman and rubocop install from lock files shipped in the package that name every dependency at one version with its sha256, and each download is checked against it, so their dependencies no longer float between machines. brakeman now asks for Ruby 3.0 or newer, which its pinned gem needs.

    The README and docs now say which scanners download when, and every trivy example passes `--disable-telemetry --skip-version-check --skip-c...

Read more

openqodex@0.10.0

Choose a tag to compare

@github-actions github-actions released this 08 Oct 19:14
5b50fe7

Minor Changes

  • #65 d42e17e Thanks @siddhant-mohan! - - The code graph finds callers across the packages of a workspace (pnpm, npm or yarn workspaces), through the nearest tsconfig.json of each file, and across Python src roots. Before, a change to a function of one package listed no caller in another.
    • Every caller in the brief says how sure the graph is: certain (an import, a definition in the same scope or a known receiver type proves it) or likely, with a note naming the convention it rests on, such as a workspace package reached through its built dist entry with no tsconfig paths, project reference or source condition mapping it to source, or possible, when a name two export * statements bring from different modules could be either. A method inherited from a base class is no surer than the binding of the base. A path a package's exports map does not expose, a Python module found in two places and a call on a value typed any, unknown or object are never bound, and each is said with its cause.
    • The brief's block is now "What this change reaches". It lists the public names the change stopped exporting or bound to another definition, with every place that used them and what each binds now; a function moved to another file under another name with the same body as moved and renamed; and what the graph could not see near the change, with the cause. A caller list that may be short is marked as a floor, with the reasons.
    • Every cut the graph makes says what it left out: a hub's callers past the 20 nearest, the second hop past 20 callers of each caller, files past the parse cap, the time budget or the memory bound.
    • The graph keeps its work between reviews in the repository's .openqodex/graph/, ignored by the folder's own .gitignore: a file that did not change is never parsed again. Builds are kept whole and never changed after they are written; a review holds the build it read until it ends; the folder is held under graph.max_cache_mb (512 MB by default). With --report-dir nothing is kept. The folder is used only while it and each file read from it are yours alone: a folder other users can write is refused with the reason and the graph is built in memory, and a build or a facts file is used only when ~/.openqodex/graph/ records it, for this repository, as one your own runs saved; anything else is parsed again.
    • Each kept build's files stay readable with git show <tree>:<path> through a local ref, refs/openqodex/graph/<tree>, deleted with the build. A plain git push does not send it.
    • The review writes the graph's files into its snapshot under .openqodex-review/graph/ (every caller, the second hop, what the change calls, importers, the changed public names, what the graph could not see, the base version of removed code), so its reviewer can open everything the brief leaves out without leaving the snapshot. Before, the brief pointed at impact.json beside it, outside the folder the reviewer may read, and following it ended the review (#58).
    • When the build the next review needs is predicted, from this machine's own measurements, to take under five seconds, the graph is built fresh from what is cached. Over five seconds, a graph command uses the kept index of the same files when there is one, and a review builds under its time budget and keeps an index.
    • graph.max_files now counts new parses, never files whose facts are cached. New keys: graph.max_cache_mb and graph.max_heap_mb.
    • The graph also runs when a change edits only a manifest (package.json, tsconfig.json, pyproject.toml, go.mod, ...), and lists the imports whose target it changed.
    • A manifest, lockfile or tsconfig the graph cannot read is named with what failed. One whose loss can hide a call (a package.json, a tsconfig, a workspace file, a go.mod) also marks the build partial and floors the callers in its folder; docs/graph.md has the table. A name re-exported through more than 8 modules is said as such. A file: or link: dependency binds to a workspace package only when its path leads to that package's folder.
    • A kept index is reused only when every file the project model read or looked for (tsconfig chains, whatever they are named, manifests, workspace files, lockfiles) and every file left out are the same as when it was built.
    • Hidden commands, which may change before 1.0: openqodex graph build | status | search | symbol | callers | callees | importers | changes | unknowns | explain | capabilities, with --json. docs/graph.md describes the graph.

openqodex@0.8.1

Choose a tag to compare

@github-actions github-actions released this 07 Oct 00:02
549d330

Patch Changes

  • #54 8c9041a Thanks @siddhant-mohan! - A new docs page, claude-code-review, on code review in Claude Code.

  • #55 0d9bcbe Thanks @siddhant-mohan! - The README, the docs, the Claude Code plugin's README, openqodex --help and the CLI's messages now name .openqodex/config.yaml as the config file. A root .openqodex.yaml is still read when .openqodex/config.yaml does not exist.
    openqodex --help, the docs index and the Claude Code marketplace entry now describe OpenQodex as it works today: AI code review before you push, from your coding agent or your terminal, with the scanners and a separate reviewer.

openqodex@0.7.1

Choose a tag to compare

@github-actions github-actions released this 06 Oct 01:01
5646d11

Patch Changes

  • #49 d27a66b Thanks @siddhant-mohan! - A review no longer ends incomplete when the reviewer searches with a brace list of paths, such as {src/**,scripts/*.mjs}, that stays inside the change; a list with any path outside still ends it.

    A review no longer ends incomplete when the reviewer reads or searches a name with two dots in it, such as Next.js's app/[...slug]/page.tsx; a .. step that climbs out still ends it.

    A review no longer ends incomplete when the reviewer reads a file named with $ or %, such as Remix's app/routes/posts.$slug.tsx, that exists in the change; a path like $HOME/.ssh/id_rsa that names no such file still ends it.

    The check of what the reviewer read now reads each call as Claude Code does: a Grep file filter split at a space or comma, a filter that starts with !, or a path with spaces around it ends the review when any reading points outside the change, and on a disk that keeps case, a folder whose name differs from the change's copy only in case counts as outside.

openqodex@0.7.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 21:42
36d1106

Minor Changes

  • #46 ee608c8 Thanks @siddhant-mohan! - - The GitHub Action runs the full review on a pull request when the workflow sets ANTHROPIC_API_KEY on its step from a secret: the scanners, the code graph and a Claude Code reviewer, with the report in the job summary and the findings in code scanning. Without a key it runs the scanners only, as before, and says in one line how to turn the review on. Each review spends the repository's own API credit.
    • The new Action input review takes auto (the review with a key, the default), off or required, which fails the job without a complete review. The new input claude-code-version pins the Claude Code the Action installs. The new outputs reviewed, review-status and reviewer say what ran.
    • In a pull request the Action's review reads the custom instructions from the base branch, like the config, so a pull request cannot write its own. The reviewer's web tools are off in the Action, the key reaches the review command alone, and the review never runs on pull_request_target.
    • When the Action's review does not complete, the job also runs the scanners, so an incomplete review never hides a scanner finding: the summary shows the partial review and then the scan, code scanning gets the scan's findings, and a blocking finding from either fails the job.
    • The Action's version and claude-code-version inputs take an exact SemVer release version only, such as 0.6.1; a tag such as latest, a range, a path or a file: package now fails the step. The Action runs its helpers from the system folders only, runs git, node, npx, npm and claude only from outside the checkout and gives its programs a PATH of those alone plus the system folders, keeps every program's output from writing workflow commands into the job log, escapes the text it puts in the job summary, and sets the key empty on its other steps. A pull request that commits .openqodex/reviews or .openqodex as a link no longer turns a blocking finding into a tool failure.
    • openqodex review takes --block-on-severity, as scan does, --instructions <file> to read the owners' instructions from another file, --reviewer-web on|off to set the reviewer's web tools for one run over the user config, and --report-dir <folder> to write every file of the run, and a reviewer.json that says whether a reviewer started and which, to a folder of your choice instead of .openqodex/, touching nothing under .openqodex/ in the repository. openqodex scan takes --report-dir too.
    • A .openqodex/latest.json that is a link no longer fails a finished review: review warns and keeps its exit code.
    • The markdown scan report escapes every markdown and HTML character in scanner messages and reasons, as the review report does.

openqodex@0.6.1

Choose a tag to compare

@github-actions github-actions released this 05 Oct 02:28
aa80d94

Patch Changes

  • #41 9c0a2e5 Thanks @siddhant-mohan! - The package and the three plugins now name https://qodex.ai/openqodex as their homepage.

  • #20 da8878f Thanks @siddhant-mohan! - OpenQodex is packaged for three plugin directories: the Claude Code plugin gains a README and an icon, a new Codex plugin in plugins/codex/ carries the skill for the OpenAI plugin directory, and .cursor-plugin/plugin.json makes the repository a Cursor plugin.
    A new privacy page, docs/privacy.md, says what OpenQodex collects (nothing) and lists every network call it makes. openqodex guide privacy prints it.
    The skill's description now names the requests it answers: a code review, a security scan, a diff or a pull request.
    The npm package, the GitHub Action and the plugins have new descriptions and keywords, and the README opens with a banner.

openqodex@0.6.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 23:53
f0ce48e

Minor Changes

  • #35 dfef509 Thanks @siddhant-mohan! - Codex can now be the reviewer. openqodex review --reviewer codex runs the full review with codex exec on your Codex login, and auto picks Codex when you run the command from Codex or when Codex is the only reviewer installed.
    The Codex reviewer reads the copy of the change in a read-only sandbox with no network for its commands. It still loads your global ~/.codex/AGENTS.md.
    Before each Codex review, OpenQodex checks that the sandbox refuses a read outside the copy and a write inside it. If it does not, the review does not start and you get "Full review unavailable" with the fallback.
    With Codex, the report says file reads were not recorded, because Codex does not show every command it runs. Changed lines count only when the brief or a correction round put them in front of the reviewer.
    Inside Codex's own sandbox, where a second Codex cannot start, review --reviewer codex prints "Full review unavailable" and the review --agent fallback.
    The reviewer brief no longer tells the reviewer which tools it has; it says to inspect the copy with its own tools, edit nothing and run none of the repository's code.

  • #35 8e614e4 Thanks @siddhant-mohan! - The reviewer can now search the web and open web pages by default; set reviewer_web: off in ~/.openqodex/config.yaml to remove the web tools.

Patch Changes

  • #37 0b0b923 Thanks @siddhant-mohan! - A scanner download that is stopped for being too large or too slow no longer leaves its partial file behind.

  • #35 59bb4b6 Thanks @siddhant-mohan! - - The terminal report no longer prints a line reading only "agent" under a finding the reviewing agent raised from its own reading; a scanner finding the agent verified still names its scanner.

    • The line hook install prints for husky or a pre-push hook of your own now passes git's hook arguments ("$@"), so a push to a remote other than origin is checked against that remote. The lefthook line passes none, because lefthook would put a remote URL into the command as raw shell text; with lefthook a push is still checked against origin.
    • docs/security.md now lists the problem report among the network uses: what the issue holds, and that it is sent only when you choose it.
    • The skill now says that two scanners go online: semgrep downloads its rule packs, and osv-scanner sends dependency names and versions to osv.dev. --offline skips both.
    • A brief written by a local build of OpenQodex (run with node <path>/dist/bin.js) now names that same node and file in its finalize command, and in the fallback line when no reviewer can start, instead of npx -y openqodex@<version>. A run through npx or the launcher is unchanged.
    • init and the first scan or review no longer tell you to commit a file that git ignores in your repository; they say it is ignored and not shared with your team.
  • #35 379c2ca Thanks @siddhant-mohan! - In a work tree nested inside its bare repository (such as repo.git/main), the review after init no longer includes the files init itself wrote.

  • #35 1ce2fac Thanks @siddhant-mohan! - The pre-push hook now finds a complete review of the pushed branch even after a later review of other work.

openqodex@0.5.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 18:52
3008a84

Minor Changes

  • #31 4e5b25d Thanks @siddhant-mohan! - - The GitHub Action reads a pull request's OpenQodex config from its base branch, so the pull request cannot hide findings through its own config; when the base cannot be read it uses the built-in defaults, never the pull request's file. The new input config-from: head reads the pull request's config instead. A wrong config-from or block-on-severity value now fails the step.

    • The GitHub Action handles a failed scanner install like a failed scan: a warning and status: tool-failed, and a failed job only with fail-on-tool-error: true. An incomplete review in SARIF is now a failed run that names what is missing.
    • The push hooks check each range a push sends against the commit the remote holds, so a force push over work the review never saw is not covered by it. The agent hook checks your current work for a plain git push and says it cannot tell for any other push command (a deny when block_on_severity is set); the git pre-push hook stays the check that sees the exact commits. A pre-push that sends nothing passes.
    • A review stops before the reviewer starts when a file name holds a secret the scanners found, and the reviewer's trace is redacted like the report.
    • A review counts a changed file that was too large to map or brief as unread until the reviewer reads it.
    • A finding must start on a changed line and end within the file and 200 lines.
    • Ctrl-C during a review stops the reviewer and its children and removes the snapshot.
    • The review init ends with now reviews your own earlier edits to files init writes, such as CLAUDE.md, without init's own section.
    • A review from the older two-step protocol counts for the push hooks only when this machine ran its scan.
    • The review init ends with now runs when init also installs the git pre-push hook or adds a .git/info/exclude line; before, it stopped with "the review after init did not run".
    • The git pre-push hook accepts a review of a branch made with no upstream set when it is pushed over its remote tip, as long as the review covered exactly the pushed commit; before, such a push counted as unreviewed and, under block_on_severity, was stopped every time. When a branch the remote has is still unreviewed and has no upstream, the hook's line says to set the upstream, review, then push.
    • When no reviewer can start (only Codex or only Cursor installed, or Claude Code logged out), review now names a fallback after "Full review unavailable": the agent you are in runs review --agent and follows the brief it prints. The skill tells the agent to follow it.
    • A review finished through review --agent and review --finalize says "Reviewed by the coding agent you are using." on the first line after the verdict, in the terminal, report.md, report.json (reviewed_by) and report.sarif (a run property). Its brief ends by telling the agent to show you the report as printed.
  • #31 a3eb515 Thanks @siddhant-mohan! - - --reviewer now takes auto, claude, codex or cursor, and reviewer: in ~/.openqodex/config.yaml sets it for every review. Only Claude Code is enabled as a reviewer: Codex and Cursor say why they are not and the review exits 2.

    • reviewer_web: on in ~/.openqodex/config.yaml gives the reviewer Claude Code's web tools. It is off by default.
    • init now ends with a review of your change, or asks what to review when there is none (the whole repository, a pull request, a branch, or not now). Without a terminal it prints the three commands. --no-review skips it, and a review that cannot run never fails init.
    • The push hooks now look up the review of exactly what is pushed. A complete passing review is silent, a missing one asks for openqodex review, an incomplete one never blocks, and a review from the older two-step protocol counts, with a line naming who reviewed.
    • The push hooks trust only the review record in your own ~/.openqodex/receipts/, never report files a branch carries under .openqodex/. init and update remove records older than 30 days.
    • The git pre-push hook no longer scans or prints scanner findings.
    • The GitHub Action says first that it runs the scanners only. A tool failure (exit 2) no longer fails the job: it shows a warning annotation and a job summary line, and sets the new status output to tool-failed. The new input fail-on-tool-error: true fails the job instead, and the new input block-on-severity sets a gate that the pull request's own config cannot weaken.
    • scan --block-on-severity <severity> wins over the config's review.block_on_severity.
    • The skill, the agent rules and the team section now give the agent one command, review, and tell it to show the report exactly as printed. Claude Code is allowed to run review and review --all without asking; the older review --agent and review --finalize rules are removed.
    • Progress shows one line for the scanner stage, such as "Scanners: 6 ran, 5 had nothing to check, 14 candidates to check", instead of a line per scanner.
  • #31 93a4a4a Thanks @siddhant-mohan! - - openqodex review now does the whole review in one run: it copies your change into a temporary snapshot, runs the scanners and the code graph on it, starts Claude Code as a separate reviewer that can only read the snapshot, checks the answer with a script and prints one report. Each finding says where, the problem, why it matters and the fix, and the report ends with which reviewer ran, how long it took and what it used.

    • A review is complete only when every scanner candidate was raised or dropped with a reason and every changed range was given to the reviewer. Otherwise the report says what is missing and the command exits 2.
    • With no reviewer installed and logged in, review prints "Full review unavailable", says what is missing, saves the unchecked scanner candidates to a file and exits 2. It never shows scanner output as a review.
    • New flags: --reviewer auto|claude and --timeout <seconds> (600 by default).
    • review --agent and review --finalize still work for older skills; a review finished that way is recorded as a legacy review.

openqodex@0.4.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 03:54
6613eaa

Minor Changes

  • #25 000d3df Thanks @siddhant-mohan! - - openqodex review <branch> and openqodex review '[#42](https://github.com/openqodex/openqodex/issues/42)' (or a pull request link) review a branch or a pull request that is not your current work. OpenQodex fetches it, checks it out in a temporary folder without running anything from it, and reviews what it added since it left its base. Your own settings and approvals apply, never the target's.
    • The base of a branch or pull request review comes from --base, the pull request's base when gh is installed, review.default_base, or the remote's default branch, and the output says which.
    • review --finalize --run <id> finalizes one run by name; the brief of a branch or pull request review prints it.
    • A change to a scanner's own settings or ignore file, such as .gitleaksignore or ruff.toml, is raised as a candidate the reviewer must clear, since it can hide that scanner's findings. A scan shows it as a note that never counts toward the verdict.
    • A change that only deletes code can now carry a finding that counts: the lines next to a deletion count as changed, and the brief lists each deletion point (issue #22).

openqodex@0.3.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 00:13
e1fbdf7

Minor Changes

  • #21 db539cd Thanks @siddhant-mohan! - init inside a repository adds a short review section to the repository's CLAUDE.md and AGENTS.md, so a teammate's agent reviews before pushing with nothing installed; the files show in git status to be committed. --no-repo skips it, and --uninstall removes exactly that section.
    Every user-scope install gets the launcher in ~/.openqodex/bin/, even for Cursor or Cline alone. The user-scope skill is now a short stub that runs <launcher> guide skill for the full procedure of the active version, and the user-scope Cursor and Cline rules call the launcher instead of npx -y openqodex@<version>. The next init replaces a skill or rule an earlier init wrote, while it is unchanged.
    New guide skill: prints the review procedure of the running version, with its commands written for the launcher when the launcher started it.
    The launcher runs the version named on the first line of ~/.openqodex/runtime/current, and the version init installed when that line is missing, malformed or names a copy that is gone. A runtime copy is never replaced once written.
    The skill installed with npx skills add uses ~/.openqodex/bin/openqodex when it exists.

  • #21 3f53203 Thanks @siddhant-mohan! - In user scope, init adds rules so Claude Code runs the exact review command lines the skill names (review --agent, review --finalize, their --all and --offline forms) and guide without asking. When the launcher's path holds *, no rule is written and init says so, so a review can run unattended; any other flag or command still asks. init --uninstall removes exactly the rules it added.
    The skill init writes in project scope keeps the committed npx -y openqodex@<version> commands and no longer tells an agent to prefer the launcher.
    init skips the team review section for a CLAUDE.md or AGENTS.md the repository's git ignore rules hide, and says why.
    init --uninstall removes the update state, and ~/.openqodex/config.yaml when openqodex update created it and it is unchanged.
    openqodex update --rollback turns updates off before anything else and changes nothing when it cannot.
    openqodex --help now shows four commands; scan is part of review; the other commands still work.
    init, uninstall, hook install and the update's switch take one lock that the operating system releases when a process ends: a listener on 127.0.0.1 that accepts no data. Lock files from earlier versions are removed by init.

  • #21 23f6714 Thanks @siddhant-mohan! - An install made with init updates itself: at most once a day, after a review, scan or push check run through the launcher, a background check installs a newer release that is at least 24 hours old and whose npm provenance was signed by this repository's release workflow. The command never waits for it, and the next command says once which version it moved to.
    New openqodex update command: --now, --rollback, --off, --on and --status. doctor shows the update state. Updates are off with update: off in ~/.openqodex/config.yaml, OPENQODEX_AUTO_UPDATE=0, --offline and in CI.
    review --finalize runs on the openqodex version that wrote the brief, and the brief's finalize command names that version's own runtime when the launcher started it.
    A run through npx or a project-scope file never checks for updates; doctor, review and scan say when that pinned version is behind the newest one a check on this machine saw.

Patch Changes

  • #21 58b8578 Thanks @siddhant-mohan! - A review no longer misses a file edited at the same size within the same second that git last wrote its index.