Skip to main content
Press release

Vibgrate Review brings architecture-aware change review to the command line and the editor

vg review reads a change from the local code map, gives one policy-owned decision, and ships the result as a versioned receipt — locally, before the pull request. A new Review panel in Vibgrate for VS Code runs the same review on uncommitted changes.

AI coding agents write changes faster than anyone can judge their architectural consequences. A pull request that compiles and passes its tests can still make a controller reach into the database directly, drop an authorization check from an endpoint, or add a dependency with a known vulnerability. Those are the questions a senior reviewer asks, and they are asked after the change is already in the queue.

Vibgrate Review asks them first. vg review reads the working tree against HEAD — or, with --base, a branch against its merge-base — from the local Vibgrate Graph, runs deterministic scanners over the change, and produces a single decision: pass, needs_review, fail, or undetermined. The decision is written once, by policy, from a policy version recorded in the result. Findings never decide, and an optional local model may explain a finding but cannot bless one away.

Some findings are protected. An unguarded entrypoint, a removed guard, and a known-vulnerable dependency cannot be turned into a pass by low confidence, by an approved exception, or by anything a model says. The only way a protected rule stops gating is to turn it off in the repository's .vibgrate/review.toml, which a pull-request run reads from the trusted base branch so a change cannot weaken the policy applied to itself.

The result is a versioned receipt, vg.review.receipt.v1, carrying the decision, every finding with the evidence it rests on, the policy and model versions, and content digests. vg review --format json writes it for CI; --format md renders a pull-request summary; --format sarif exports the security findings — and only those, by design — for GitHub code scanning. vg review explain <id> shows the evidence behind one finding: the graph edge, the source span, the layering rule. Where Review could not observe something, it reports an unknown rather than a green tick nobody earned.

The same review now runs inside Vibgrate for VS Code. A new Review panel lists uncommitted changes with their line counts, runs vg review on them, marks each finding on the file it names, and shows the evidence for any finding with every path one click from the editor. The receipt or the Markdown summary opens in the editor for a pull request, and the result is flagged as stale the moment the tree changes again.

Review prepares its own prerequisites: a missing code map is built and a drifted one refreshed before the review runs, and the first run in a repository with no review policy writes a starter, advisory .vibgrate/review.toml seeded from the layering the repository already exhibits. Source stays on the machine; --push sends the receipt, never the repository, so Vibgrate Cloud can show a repository's review decisions commit by commit.

Vibgrate Review reports change integrity against the architecture and security controls a repository declares. It does not prove code is secure, it does not replace Semgrep, CodeQL, compilers, or tests, and absence of findings is not a certification. It is distinct from DriftScore, which measures how far a stack has drifted from current versions; the two are never blended.

Vibgrate Review ships in the Vibgrate CLI, free and open source under Apache 2.0, and in Vibgrate for VS Code on the Visual Studio Marketplace and Open VSX.

“Agents write changes faster than anyone can judge their architectural consequences. Review reads the change the way a senior reviewer would — against the architecture you actually declared — and it is honest about what it could not see. An unknown is not a pass, and nothing a model says can turn a removed guard into one.”
Peter Chapman — Founder, Vibgrate

Facts and primary sources

About Vibgrate

Vibgrate is a software intelligence platform that helps teams find aging dependencies, assess security exposure, and plan modernization. Its free CLI maps codebases and produces DriftScore, a transparent measure of dependency, framework, and runtime drift. Vibgrate Cloud adds portfolio visibility, governance workflows, and verifiable evidence for security and regulatory decisions. Vibgrate Evidence preserves version-specific component and release records so teams can reproduce historical exposure findings. Vibgrate AI Context gives coding agents version-matched documentation and precise repository context while reducing unnecessary token use. Vibgrate publishes its scoring methodology openly, allowing researchers to inspect the evidence, assumptions, and formulas behind its results.

25-word boilerplate

Vibgrate helps software teams find aging dependencies, assess security exposure, and plan modernization using verifiable evidence produced by its free code-scanning CLI and cloud platform.

50-word boilerplate

Vibgrate is a code drift intelligence platform for software teams. Its free CLI maps a codebase and identifies drift across dependencies, frameworks, and runtimes. Vibgrate Cloud turns the same scan data into portfolio visibility, governance workflows, security prioritization, and verifiable evidence for modernization decisions, regulatory reporting, and ongoing software assurance.

Press inquiries

Peter Chapman, Founder · press@vibgrate.com