Appearance
Limits and defaults
Per-repository defaults
The values a repository starts with. All are editable by an admin on the repository's settings page — see Repository settings.
| Setting | Default |
|---|---|
| Enable AI review | on |
| Trigger on PR events | opened, synchronize (reopened off) |
| Skip draft pull requests | on |
| Exclude patterns | the starting list |
| Post review on GitHub | on |
| Comment severities | warning, critical (info off) |
| Post summary comment | on |
| Max comments per review | on, 20 |
| Status branch | the repository's GitHub default branch |
Marking a draft pull request ready for review always triggers a review, regardless of the trigger events chosen.
Status branch is the one setting here that does not affect reviews: it picks the branch the project status scan runs on.
Because info is off by default, minor maintainability findings are kept but not posted inline. Findings held back — by severity, by the comment limit, or because another run already raised them — are counted in the review body and listed in the review detail.
Per-user defaults
| Setting | Default |
|---|---|
| Display mode | Developer mode |
Your display mode is yours alone; changing it affects no one else and nothing on your pull requests.
Organization defaults
| Setting | Default |
|---|---|
| Enable review for new repositories | on |
| Data retention (days) | Depends on your subscription plan — review findings and project-status metadata are deleted after the configured period |
Merge confidence bands
| Reading | Score | Meaning |
|---|---|---|
| High | 8.0 and above | safe to merge |
| Medium | above 5.0, below 8.0 | review before merging |
| Low | 5.0 and below | do not merge |
Only completed reviews are rated. One that produced no rating counts as Unrated and is left out of the percentage. See Merge confidence.
The starting exclude list
A repository's exclude list begins with these patterns. Every one of them is editable — remove any entry and the files it matched are reviewed again, and an empty list reviews every file.
text
*.lock
*.min.js
*.min.css
*.generated.*
**/*.d.ts
**/dist/**
**/node_modules/**
package-lock.json
npm-shrinkwrap.json
pnpm-lock.yaml
bun.lockb
go.sum
packages.lock.json
gradle.lockfile
.pnp.cjs
.pnp.loader.mjs
**/.yarn/**
**/build/**
**/out/**
**/.next/**
**/.nuxt/**
**/coverage/**
**/.turbo/**
**/__pycache__/**
**/.venv/**
*.map
*.bundle.js
*.pb.go
*_pb2.py
*_pb2_grpc.py
*.g.dart
*.freezed.dart
zz_generated.*
*_generated.go
**/__snapshots__/**
CHANGELOG.md
*.svg
*.csv
*.sqlite
*.sqlite3
*.sqlite-journal
*.sqlite-wal
*.sqlite-shmThe list covers common lock and dependency metadata, build and coverage output, source maps and bundles, generated code, test snapshots, and selected non-code assets. Lockfiles ending in .lock — yarn.lock, Cargo.lock, Gemfile.lock, composer.lock — are already matched by *.lock. See Excluding files.
Validation
| Field | Rule | Message when it fails |
|---|---|---|
| Exclude pattern | 1–255 characters | Pattern cannot be empty. · Pattern must be 255 characters or fewer. |
| Exclude pattern | Must be a valid glob | Pattern is not a valid glob. |
| Exclude pattern | No duplicates within a repository | Pattern already exists. |
| Exclude patterns | At most 200 per repository | Exclude patterns are limited to 200. Remove some before adding more. |
| Max comments per review | Whole number, 1 or more | — |
| Data retention (days) | Whole number, 1 or more | — |
| Ticket subject | 5–160 characters | The counter beside the field reads Minimum 5 characters · 3/160 until it is long enough |
| Ticket description | 10–10,000 characters | The counter reads Minimum 10 characters · 4/10,000 |
| Ticket reply | 1–10,000 characters | — |
| Attachment | An accepted type, not empty, 10 MiB or less | This file type is not accepted. · This file is empty. · File is larger than 10 MiB. |