OpenQodex
Open source AI code review CLI that runs scanners on your changed lines, then a separate Claude Code or Codex reviewer checks them before you push.
At a Glance
OpenQodex is open source (Apache 2.0) AI code review for Claude Code and Codex, running on your machine before you push. Free to use; reviews use your own Claude Code or Codex plan.
Engagement
Available On
Alternatives
Listed Oct 2026
About OpenQodex
OpenQodex is an open source, Apache 2.0 licensed code review tool from Qodex that runs on your machine before you push. It works with Claude Code and Codex, running scanners that fit your changed files and then starting a separate reviewer process. The latest release listed is openqodex@0.8.1, and the README says the project is new and on the way to 1.0.
What It Is
OpenQodex is a command-line review tool for changes written by coding agents or by hand. The command openqodex review works out your change (the commits not yet pushed plus everything uncommitted), freezes a copy of it, and produces a single report. It needs Claude Code or Codex installed and logged in, and no other key, account or server. It requires Node 22 or newer and git, and runs on macOS and Linux (Windows through WSL).
How a Review Works
The review runs in stages:
- Scanners run first with no model. Thirteen are built in, including semgrep, gitleaks, osv-scanner, actionlint, hadolint, shellcheck, ruff, bandit, oxlint, golangci-lint, brakeman, rubocop and a built-in SQL linter. Each runs only when the change holds a file it reads, and only findings on changed lines are kept.
- A separate Claude Code or Codex process then reads the frozen copy of the change with none of your settings, plugins or hooks. It checks every scanner finding and is given every changed line.
- Scripts check the answer: every scanner finding must be raised or dropped with a reason, and every changed line must have been in front of the reviewer. Otherwise the report says "Review incomplete".
- Output is printed in the terminal and written to report.md, report.json and report.sarif.
Where It Runs
You can trigger it from a coding agent (Claude Code, Cursor, Codex, Cline) or from the terminal. Cursor and Cline can run it but cannot act as the reviewer. review --all reviews a whole repository, and a branch or pull request can be reviewed by name. A push gate for Claude Code and Codex and an optional git pre-push hook warn by default and block only when configured. A GitHub Action runs the full review when given an Anthropic API key, and scanners only without one. A pre-commit hook runs scanners only.
Extending and Privacy
Any scanner can be added by its GitHub link in .openqodex/config.yaml; it never runs until you approve that entry with openqodex trust. OpenQodex sends no telemetry. The reviewer sends the review brief and what it reads to the model behind your own Claude Code or Codex login, and web search can be turned off with reviewer_web: off.
Tradeoffs to Know
Documented limits include no reviewer other than Claude Code or Codex, no MCP server, no Windows support outside WSL, and no offline vulnerability database. A review takes one to three minutes. Brakeman is not open source licensed and can be disabled. The hosted Qodex product from the same team is a separate offering for team-wide pull request review.
Community Discussions
Be the first to start a conversation about OpenQodex
Share your experience with OpenQodex, ask questions, or help others learn from your insights.
Pricing
Open Source
OpenQodex is open source (Apache 2.0) AI code review for Claude Code and Codex, running on your machine before you push. Free to use; reviews use your own Claude Code or Codex plan.
- Apache 2.0 license
- No telemetry
- Runs on Mac and Linux (Windows via WSL)
- Requires Claude Code or Codex installed and logged in (own plan, external cost)
- Thirteen built-in scanners, downloaded on first use
Capabilities
Key Features
- Reviews the unpushed commits plus uncommitted changes in one command
- Thirteen built-in scanners (SAST, secrets, dependencies, lint) filtered to changed lines
- Separate Claude Code or Codex reviewer process on a frozen copy of the change
- Script checks that every scanner finding and changed line was reviewed
- Reports in terminal, report.md, report.json and report.sarif
- Custom scanners by GitHub link with explicit trust approval
- Push gate and optional git pre-push hook
- GitHub Action and pre-commit hook
- Review of whole repo, branch or pull request
- Demo repo with planted bugs
- No telemetry
- Automatic background updates with rollback
