
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@diff-review-system/drs
Advanced tools
Intelligent code review platform for GitLab and GitHub - Enterprise-grade automated analysis
Intelligent Code Review Platform for GitLab and GitHub
Enterprise-grade automated code review for Merge Requests and Pull Requests, powered by OpenCode SDK and Claude.
Install OpenCode CLI (required for in-process server mode):
npm install -g opencode-ai
npm install -g @diff-review-system/drs
cd your-project
drs init
# Copy example env file
cp .env.example .env
# Edit .env and set:
# - GITLAB_TOKEN: Your GitLab access token (for GitLab MRs)
# - GITHUB_TOKEN: Your GitHub access token (for GitHub PRs)
# - OPENCODE_SERVER: URL of your OpenCode instance (optional - will start in-process if not set)
# - Provider API Key: Set the API key for your chosen model provider
# - ANTHROPIC_API_KEY for Claude models (e.g., anthropic/claude-opus-4-5-20251101)
# - ZHIPU_API_KEY for GLM models (e.g., zhipuai/glm-4.7)
# - OPENAI_API_KEY for OpenAI models (e.g., openai/gpt-4)
# - See .env.example for all supported providers
Note: OPENCODE_SERVER is optional. If not provided, DRS will automatically start an OpenCode server in-process. For production deployments or when sharing across multiple tools, you can run a dedicated OpenCode server and set the URL.
# Review unstaged changes
drs review-local
# Review staged changes
drs review-local --staged
# Use specific agents
drs review-local --agents security,quality
Review code locally before pushing:
# Review local changes
drs review-local
# Review specific GitLab MR
drs review-mr --project my-org/my-repo --mr 123 --post-comments
# Review GitLab MR and generate code quality report
drs review-mr --project my-org/my-repo --mr 123 --code-quality-report gl-code-quality-report.json
# Review specific GitHub PR
drs review-pr --owner octocat --repo hello-world --pr 456 --post-comments
Add to your .gitlab-ci.yml:
include:
- remote: 'https://raw.githubusercontent.com/manojlds/drs/main/src/ci/gitlab-ci.template.yml'
ai_review:
extends: .drs_review
stage: review
See GitLab CI Integration Guide for:
ghcr.io/anomalyco/opencode)DRS includes a secure, pre-configured workflow at .github/workflows/pr-review.yml with built-in protection against external PR abuse.
Security Features:
safe-to-review labelQuick Setup:
Configure API Keys in repository Settings → Secrets:
ANTHROPIC_API_KEY (for Claude models), orOPENCODE_ZEN_API_KEY (for OpenCode Zen), orZHIPU_API_KEY (for ZhipuAI GLM models), orOPENAI_API_KEY (for OpenAI models)Set up External PR Protection (Important!):
external-pr-reviewsafe-to-review labelSee GitHub Actions Integration Guide for:
See External PR Security Guide for:
Deploy as a standalone service:
# Using Docker Compose
cd examples
docker-compose up -d
# Configure webhooks:
# GitLab: http://your-server:8080/webhook/gitlab (Merge request events, Comments)
# GitHub: http://your-server:8080/webhook/github (Pull request events)
DRS can generate GitLab-compatible code quality reports that integrate seamlessly with GitLab CI/CD. This provides an alternative (or complement) to inline MR comments.
Benefits:
When to Use:
--post-comments) for critical issues requiring discussion--code-quality-report) for comprehensive static analysis# Generate code quality report only
drs review-mr --project my-org/my-repo --mr 123 \
--code-quality-report gl-code-quality-report.json
# Use both comments and code quality report
drs review-mr --project my-org/my-repo --mr 123 \
--post-comments \
--code-quality-report gl-code-quality-report.json
Add to your .gitlab-ci.yml:
code_review:
stage: review
image: node:20-alpine
before_script:
- npm install -g @diff-review-system/drs opencode-ai
script:
- drs review-mr --project $CI_PROJECT_PATH --mr $CI_MERGE_REQUEST_IID
--code-quality-report gl-code-quality-report.json
artifacts:
reports:
codequality: gl-code-quality-report.json
expire_in: 1 week
only:
- merge_requests
The code quality report will appear in:
DRS generates reports in GitLab's CodeClimate-compatible format:
[
{
"description": "Query uses string concatenation. Use parameterized queries instead.",
"check_name": "drs-security",
"fingerprint": "7815696ecbf1c96e6894b779456d330e",
"severity": "blocker",
"location": {
"path": "src/api/users.ts",
"lines": { "begin": 42 }
}
}
]
Severity Mapping:
For more details, see GitLab Code Quality Documentation.
DRS supports two modes of OpenCode server operation:
If OPENCODE_SERVER is not set, DRS will automatically start an OpenCode server within the same process. Note: This still requires the OpenCode CLI to be installed globally.
# Install OpenCode CLI first (required)
npm install -g opencode-ai
# Then run DRS (server starts automatically)
drs review-local
Pros:
Cons:
For production deployments or when sharing across multiple tools, run a dedicated OpenCode server:
# Set the server URL
export OPENCODE_SERVER=http://opencode.internal:3000
drs review-local
Pros:
Cons:
DRS uses OpenCode SDK with markdown-based agent definitions:
.opencode/
├── agent/
│ ├── gitlab-reviewer.md # GitLab MR orchestrator
│ ├── github-reviewer.md # GitHub PR orchestrator
│ ├── local-reviewer.md # Local diff reviewer
│ └── review/
│ ├── security.md # Security specialist
│ ├── quality.md # Code quality expert
│ ├── style.md # Style checker
│ └── performance.md # Performance analyzer
└── opencode.jsonc # Configuration
Create custom agents in your project:
# Create custom security agent
mkdir -p .drs/agents
cat > .drs/agents/security.md << 'EOF'
---
description: Custom security reviewer
model: opencode/claude-sonnet-4-5
---
You are a security expert for this specific application.
## Project-Specific Rules
[Add your custom rules here]
EOF
Edit .drs/drs.config.yaml:
review:
agents:
- security
- quality
ignorePatterns:
- "*.test.ts"
- "*.md"
Focuses on:
Reviews:
Checks:
Analyzes:
# Required (depending on platform)
GITLAB_TOKEN=glpat-xxx # For GitLab MR reviews
GITHUB_TOKEN=ghp-xxx # For GitHub PR reviews
# Provider API Keys (set the one for your chosen model provider)
ANTHROPIC_API_KEY=sk-ant-xxx # For Anthropic Claude models
ZHIPU_API_KEY=xxx # For ZhipuAI GLM models
OPENAI_API_KEY=sk-xxx # For OpenAI models
# Optional
OPENCODE_SERVER=http://localhost:3000 # Leave empty to start in-process server
GITLAB_URL=https://gitlab.com
REVIEW_AGENTS=security,quality,style,performance
.drs/drs.config.yaml - DRS-specific configuration.gitlab-review.yml - Alternative location.opencode/opencode.jsonc - OpenCode configurationSee the examples/ directory for:
For comprehensive local development and testing instructions, see DEVELOPMENT.md.
Quick start:
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
# Development mode
npm run dev
npm install -g opencode-ai) - Required even for in-process modeApache-2.0
Contributions welcome! Please read the contributing guidelines first.
FAQs
Workflow-first AI code maintenance for reviews, changelogs, docs, and repository upkeep.
The npm package @diff-review-system/drs receives a total of 188 weekly downloads. As such, @diff-review-system/drs popularity was classified as not popular.
We found that @diff-review-system/drs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.