
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@diff-review-system/drs
Advanced tools
Intelligent code review platform for GitLab and GitHub - Enterprise-grade automated analysis
Intelligent Code Review Platform for GitLab and GitHub
Enterprise-grade automated code review for Merge Requests and Pull Requests, powered by OpenCode SDK and Claude.
Install OpenCode CLI (required for in-process server mode):
npm install -g opencode-ai
npm install -g @diff-review-system/drs
cd your-project
drs init
# Copy example env file
cp .env.example .env
# Edit .env and set:
# - GITLAB_TOKEN: Your GitLab access token (for GitLab MRs)
# - GITHUB_TOKEN: Your GitHub access token (for GitHub PRs)
# - OPENCODE_SERVER: URL of your OpenCode instance (optional - will start in-process if not set)
# - Provider API Key: Set the API key for your chosen model provider
# - ANTHROPIC_API_KEY for Claude models (e.g., anthropic/claude-opus-4-5-20251101)
# - ZHIPU_API_KEY for GLM models (e.g., zhipuai/glm-4.7)
# - OPENAI_API_KEY for OpenAI models (e.g., openai/gpt-4)
# - See .env.example for all supported providers
Note: OPENCODE_SERVER is optional. If not provided, DRS will automatically start an OpenCode server in-process. For production deployments or when sharing across multiple tools, you can run a dedicated OpenCode server and set the URL.
# Review unstaged changes
drs review-local
# Review staged changes
drs review-local --staged
# Use specific agents
drs review-local --agents security,quality
Review code locally before pushing:
# Review local changes
drs review-local
# Review specific GitLab MR
drs review-mr --project my-org/my-repo --mr 123 --post-comments
# Review GitLab MR and auto-generate a description (optionally post it)
drs review-mr --project my-org/my-repo --mr 123 --describe
drs review-mr --project my-org/my-repo --mr 123 --describe --post-description
# Review GitLab MR and generate code quality report
drs review-mr --project my-org/my-repo --mr 123 --code-quality-report gl-code-quality-report.json
# Review specific GitHub PR
drs review-pr --owner octocat --repo hello-world --pr 456 --post-comments
# Review GitHub PR and auto-generate a description (optionally post it)
drs review-pr --owner octocat --repo hello-world --pr 456 --describe
drs review-pr --owner octocat --repo hello-world --pr 456 --describe --post-description
# Override base branch used for diff hints
drs review-pr --owner octocat --repo hello-world --pr 456 --base-branch release/2026-01
# Generate review JSON first, then post comments after manual review
drs review-pr --owner octocat --repo hello-world --pr 456 -o review.json
drs post-comments --input review.json --owner octocat --repo hello-world --pr 456
# Show the diff context passed to agents
drs show-changes --owner octocat --repo hello-world --pr 456
# Show diff context for a single file
drs show-changes --owner octocat --repo hello-world --pr 456 --file src/app.ts
# Show diff context using a specific base branch
drs show-changes --owner octocat --repo hello-world --pr 456 --base-branch release/2026-01
# Generate PR/MR descriptions on demand
drs describe-pr --owner octocat --repo hello-world --pr 456
drs describe-pr --owner octocat --repo hello-world --pr 456 --post-description
drs describe-mr --project my-org/my-repo --mr 123
drs describe-mr --project my-org/my-repo --mr 123 --post-description
Add to your .gitlab-ci.yml:
include:
- remote: 'https://raw.githubusercontent.com/manojlds/drs/main/src/ci/gitlab-ci.template.yml'
ai_review:
extends: .drs_review
stage: review
See GitLab CI Integration Guide for:
ghcr.io/anomalyco/opencode)DRS includes a secure, pre-configured workflow at .github/workflows/pr-review.yml with built-in protection against external PR abuse.
Security Features:
safe-to-review labelQuick Setup:
Configure API Keys in repository Settings → Secrets:
ANTHROPIC_API_KEY (for Claude models), orOPENCODE_ZEN_API_KEY (for OpenCode Zen), orZHIPU_API_KEY (for ZhipuAI GLM models), orOPENAI_API_KEY (for OpenAI models)Set up External PR Protection (Important!):
external-pr-reviewsafe-to-review labelSee GitHub Actions Integration Guide for:
See External PR Security Guide for:
DRS can generate GitLab-compatible code quality reports that integrate seamlessly with GitLab CI/CD. This provides an alternative (or complement) to inline MR comments.
Benefits:
When to Use:
--post-comments) for critical issues requiring discussion--code-quality-report) for comprehensive static analysis# Generate code quality report only
drs review-mr --project my-org/my-repo --mr 123 \
--code-quality-report gl-code-quality-report.json
# Use both comments and code quality report
drs review-mr --project my-org/my-repo --mr 123 \
--post-comments \
--code-quality-report gl-code-quality-report.json
Add to your .gitlab-ci.yml:
code_review:
stage: review
image: node:20-alpine
before_script:
- npm install -g @diff-review-system/drs opencode-ai
script:
- drs review-mr --project $CI_PROJECT_PATH --mr $CI_MERGE_REQUEST_IID
--code-quality-report gl-code-quality-report.json
artifacts:
reports:
codequality: gl-code-quality-report.json
expire_in: 1 week
only:
- merge_requests
The code quality report will appear in:
DRS generates reports in GitLab's CodeClimate-compatible format:
[
{
"description": "Query uses string concatenation. Use parameterized queries instead.",
"check_name": "drs-security",
"fingerprint": "7815696ecbf1c96e6894b779456d330e",
"severity": "blocker",
"location": {
"path": "src/api/users.ts",
"lines": { "begin": 42 }
}
}
]
Severity Mapping:
For more details, see GitLab Code Quality Documentation.
DRS supports two modes of OpenCode server operation:
If OPENCODE_SERVER is not set, DRS will automatically start an OpenCode server within the same process. Note: This still requires the OpenCode CLI to be installed globally.
# Install OpenCode CLI first (required)
npm install -g opencode-ai
# Then run DRS (server starts automatically)
drs review-local
Pros:
Cons:
For production deployments or when sharing across multiple tools, run a dedicated OpenCode server:
# Set the server URL
export OPENCODE_SERVER=http://opencode.internal:3000
drs review-local
Pros:
Cons:
DRS uses OpenCode SDK with markdown-based agent definitions:
.opencode/
├── agent/
│ └── review/
│ ├── security.md # Security specialist
│ ├── quality.md # Code quality expert
│ ├── style.md # Style checker
│ └── performance.md # Performance analyzer
└── opencode.jsonc # Configuration
Create custom agents in your project:
# Create custom security agent
mkdir -p .drs/agents/security
cat > .drs/agents/security/agent.md << 'EOF'
---
description: Custom security reviewer
model: opencode/claude-sonnet-4-5
---
You are a security expert for this specific application.
## Project-Specific Rules
[Add your custom rules here]
EOF
Edit .drs/drs.config.yaml:
review:
agents:
- security
- quality
ignorePatterns:
- "*.test.ts"
- "*.md"
describe:
enabled: true
postDescription: false
describe:
model: opencode/glm-4.7-free
Notes:
review.describe controls auto-description when running review-mr or review-pr.--describe / --skip-describe and --post-description / --skip-post-description.describe.model is used by describe-mr/describe-pr and by review-driven descriptions.Focuses on:
Reviews:
Checks:
Analyzes:
# Required (depending on platform)
GITLAB_TOKEN=glpat-xxx # For GitLab MR reviews
GITHUB_TOKEN=ghp-xxx # For GitHub PR reviews
# Provider API Keys (set the one for your chosen model provider)
ANTHROPIC_API_KEY=sk-ant-xxx # For Anthropic Claude models
ZHIPU_API_KEY=xxx # For ZhipuAI GLM models
OPENAI_API_KEY=sk-xxx # For OpenAI models
# Optional
OPENCODE_SERVER=http://localhost:3000 # Leave empty to start in-process server
GITLAB_URL=https://gitlab.com
REVIEW_AGENTS=security,quality,style,performance
.drs/drs.config.yaml - DRS-specific configuration.gitlab-review.yml - Alternative location.opencode/opencode.jsonc - OpenCode configurationSee the examples/ directory for:
For comprehensive local development and testing instructions, see DEVELOPMENT.md.
Quick start:
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
# Development mode
npm run dev
npm install -g opencode-ai) - Required even for in-process modeApache-2.0
Contributions welcome! Please read the contributing guidelines first.
FAQs
Workflow-first AI code maintenance for reviews, changelogs, docs, and repository upkeep.
The npm package @diff-review-system/drs receives a total of 188 weekly downloads. As such, @diff-review-system/drs popularity was classified as not popular.
We found that @diff-review-system/drs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.