# Mira

> Self-hosted, open-source AI code reviewer that posts inline comments and walkthroughs on GitHub, GitLab, and Forgejo pull requests using the LLM of your choice.

Mira is a self-hostable, open-source AI code reviewer from miracodeai. It connects to GitHub, GitLab, or Forgejo (including Codeberg), watches pull and merge requests, and posts inline comments and walkthroughs using a model you choose via OpenRouter or Codex CLI. The documentation lists version v0.9.1 and an Apache 2.0 license.

## What It Is

Mira is a code review tool that runs on your own infrastructure as a single Docker image backed by SQLite or Postgres. It indexes your whole repository so each diff is reviewed with project context, rather than just the changed lines. Each comment is tagged with a severity (blocker, warning, suggestion, nitpick) and a confidence score. Noise filtering, deduplication and per-PR comment caps control what is posted.

## How a Review Works

On each PR, Mira posts a placeholder comment, then a walkthrough with merge confidence, review stats, blast radius and an optional Mermaid sequence diagram, followed by the full review. The reviewer can call `read_file` and `grep_repo` to verify callers beyond the pre-fetched context. Large diffs are reviewed in parallel chunks. Mira also compares the PR with other open PRs to flag likely merge conflicts or duplicate effort. Actionable fixes appear as GitHub suggestion blocks. Mentioning the bot supports commands such as review, pause, resume and reject, plus free-form questions answered from the indexed code.

## Security, Packages and Dashboard

A dedicated security pass looks for issues such as injection, XSS, SSRF and auth bypass. A local regex and entropy scan catches committed secrets, and packages added in a PR are checked against OSV.dev, with an hourly background poll. Org-wide package search answers questions such as which repos use a given package version. The dashboard shows review activity, severity breakdowns, dependency and blast-radius graphs, cost estimates, review-health metrics and contributor analytics.

## Rules and Learning Loop

Teams can define per-repo and global custom rules. Rejecting a comment feeds a learning loop that synthesizes suppression rules, and merged-PR human review patterns can also become rules. New learnings sit in a pending queue until approved.

## Models and Deployment

Mira is bring-your-own-LLM: OpenRouter routing, OpenAI-compatible endpoints, a fallback model, and separate indexing and review models. Reference deployments exist for Docker, Railway, Fly.io and Render. The docs state there is no phone-home or required telemetry. The README publishes its own benchmark results, which are vendor-reported.

## Features
- Inline PR comments with severity and confidence
- PR walkthrough with merge confidence and blast radius
- Full-repository indexing for context-aware reviews
- Agentic verification with read_file and grep_repo
- Cross-PR overlap detection
- Security pass and added-line secret scanning
- OSV.dev vulnerability checks and hourly polling
- Org-wide package search
- Custom per-repo and global rules
- Learning loop from rejected comments and human review patterns
- PR chat commands (review, pause, resume, reject)
- Dashboard with analytics, dependency graphs and cost estimates
- Bring your own LLM via OpenRouter or Codex CLI
- Fallback model chain and split indexing/review models
- Self-hosted via Docker with SQLite or Postgres

## Integrations
GitHub, GitLab, Forgejo, Codeberg, OpenRouter, Anthropic, OpenAI, Google, DeepSeek, Codex CLI, OSV.dev, Docker, Railway, Fly.io, Render, SQLite, Postgres

## Platforms
WEB, API, CLI

## Pricing
Open Source

## Version
v0.9.1

## Links
- Website: https://docs.miracode.ai
- Documentation: https://docs.miracode.ai
- Repository: https://github.com/miracodeai/mira
- EveryDev.ai: https://www.everydev.ai/tools/mira
