Code review decision workflow with Jev
Linters, typecheckers, and SAST prove or pattern-match. Jev can decide whether leftover PR language looks like “needs security eyes” or “reviewer load is high.” It will not compile the repo or write the fix.
This unofficial page is the decision workflow slice of the code review routing pack. Intent: apply the Jev (TypeSafe System One) decision model to code review routing decision workflow. Primary search language: Code review Jev decision workflow. Confirm patterns on docs.typesafe.ai. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.
Independent angle (cover ≠ clone): Analyzers own AST truth; Jev routes review judgment on PR prose + small hunks. Not a SAST clone and not a rival “agent skill” IA photocopy. Fan-out extra atoms on one request; open a second HTTP call only for a new artifact, not the same state. Deep taxonomies use a Choice cascade with confidence abort — not one 200-leaf Choice.
Code review use-case context
Code review routing is a workflow, not a chat. Assemble a narrow state, ask the primitives below, and let the review router branch. TypeSafe’s docs say a good question is a snap decision a knowledgeable person could make in a few seconds — not an open-ended analysis of the PR description + selected hunks.
Hub: Use cases. Compare, when the other tool is the real job: code analyzers.
Decision Workflow inputs
Keep only fields the questions name:
{
"pr": { "id": "1234", "title": "Relax auth on internal debug route", "body": "Temp bypass for the oncall drill." },
"hunks": ["- if (!user) return 401;", "+ // skip auth in staging"],
"ci": { "sast_blockers": 0, "lint_errors": 0 },
"policy": { "secrets": "Flag prose that describes committing keys or disabling auth in prod-shaped paths." }
}
Point instructions at pr.title, pr.body, hunks, policy.secrets. Drop the entire monorepo or minified bundles; binary / assembly dumps (official jaggedness: semantic > numeric encodings).
Decision signals and actions
| Id | Type | Job |
|---|---|---|
needs_security |
Noul | Does the PR prose/hunks look like an auth or secrets risk vs policy.secrets? |
review_load |
Score | How much human judgment does this leftover diff still need? |
route |
Choice | merge_ok_if_ci / request_changes / security_review / other |
All of these share state and run in parallel. Code owns the graph:
def review_route(ans, ci):
if ci["sast_blockers"] or ci["lint_errors"]:
return "ci_block" # analyzers win
if ans["needs_security"].noul >= T_SEC:
return "security_review"
if ans["route"].confidence < FLOOR or ans["route"].choice == "other":
return "human_review"
return ans["route"].choice
Do not treat a Noul of 0.5 as a “medium” code review routing score — it means yes and no are equally likely. Conjunctions stay in your code.
Guardrails and escalation
TypeSafe’s confidence-gated examples use a lower bar for recoverable reads than for irreversible actions. Those numbers are illustrations. For code review routing, treat auto_approve_merge as the high bar (approving a merge or skipping required review). Tune on labels — see offline evaluation.
Low confidence, or a policy miss → human or safe default; do not auto-approve the merge.
Evaluation and rollout notes
Shadow: Merges follow today’s required reviewers; log Jev route.
Canary: Only comment “consider security review” on one repo; never auto-approve.
Pin jev-1.13.0 (the versioned id) after you fit thresholds. jev-latest and the marketing line jev-1.13 can move. Log the response model. TypeSafe’s published list price for jev-1.13 is $0.042 per million input tokens (vendor claim — confirm on the models page); output tokens are free on that same page. Unused distractors still bill as input.
Official Python and JavaScript SDKs read TYPESAFE_API_KEY and retry documented 429/529. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.
Pack map
| Slice | Page |
|---|---|
| Graph and primitives | you are here |
What may enter state |
input contracts |
| What to gather first | evidence collection |
| Atomic rules | policy checks |
| Act / review / abstain | confidence thresholds |
| Reviewer payload | human handoff |
| What to persist | audit trail |
| How it breaks | failure modes |
| Labeled replay | evaluation |
| Shadow → canary | production rollout |
FAQ
Does Jev execute the review router action? No. It returns typed answers. Your review router code calls queues, models, or humans.
Why several questions in one request?
TypeSafe’s fan-out pattern: extra questions are cheap versus another HTTP call. needs_security + review_load + route in one call. TypeSafe’s agent-skill docs batch System One questions — that still does not replace tsc or CodeQL.
Where is the rest of the Code review pack? Start with Code review input contracts and Code review confidence thresholds. Cluster hub: Use cases.
Does the TypeSafe agent skill replace our linter? No. It teaches agents to batch questions. Analyzers still own AST truth. See agent skill.
Can Jev score cyclomatic complexity? Do not use a 2–10 Score as complexity math. Count in code or skip.
What this page does not claim
- Not a SAST, linter, or merge bot product.
- No published precision on vulnerability finding.
- Not official TypeSafe.
- Official TypeSafe status, or that jev.pro issues API keys.
- That a schema-constrained answer is automatically factually correct.
Disclaimer
This is an independent unofficial site and is not affiliated with TypeSafe AI; official documentation is available at https://docs.typesafe.ai.
Primary documentation: https://docs.typesafe.ai. Hub: Use cases.
Sources
Public TypeSafe or adjacent documentation only. No private claims.