Code review evidence collection with Jev
Linters, typecheckers, and SAST prove or pattern-match. Jev can decide whether leftover PR language looks like “needs security eyes” or “reviewer load is high.” It will not compile the repo or write the fix.
This unofficial page is the evidence collection slice of the code review routing pack. Intent: apply the Jev (TypeSafe System One) decision model to code review routing evidence collection. Primary search language: Code review Jev evidence collection. Confirm patterns on docs.typesafe.ai. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.
Independent angle (cover ≠ clone): Analyzers own AST truth; Jev routes review judgment on PR prose + small hunks. Not a SAST clone and not a rival “agent skill” IA photocopy. Fan-out extra atoms on one request; open a second HTTP call only for a new artifact, not the same state.
Code review use-case context
Evidence collection for code review routing happens before POST /v1/systemone. Jev does not browse your warehouse, retriever, or ESP. You gather the PR description + selected hunks facts, filter them, then ask snap questions. This slice is where fan-out cost math belongs: batch questions, do not re-send state.
Hub: Use cases. Compare, when the other tool is the real job: code analyzers.
Evidence Collection inputs
Collect:
- PR title + body
- A small set of hunks the questions name (not the whole diff by default)
- CI blocker counts you already computed
Never send:
- Asking Jev to type-check or run Semgrep
- Secrets in the clear — redact before POST
- Generated lockfiles and vendor trees as distractors
Shape the payload like this once the gather step finishes:
{
"pr": { "id": "1234", "title": "Relax auth on internal debug route", "body": "Temp bypass for the oncall drill." },
"hunks": ["- if (!user) return 401;", "+ // skip auth in staging"],
"ci": { "sast_blockers": 0, "lint_errors": 0 },
"policy": { "secrets": "Flag prose that describes committing keys or disabling auth in prod-shaped paths." }
}
Decision signals and actions
Each evidence field should change a named answer:
| Id | Type | Job |
|---|---|---|
needs_security |
Noul | Does the PR prose/hunks look like an auth or secrets risk vs policy.secrets? |
review_load |
Score | How much human judgment does this leftover diff still need? |
route |
Choice | merge_ok_if_ci / request_changes / security_review / other |
needs_security + review_load + route in one call. TypeSafe’s agent-skill docs batch System One questions — that still does not replace tsc or CodeQL.
Do not treat a Noul of 0.5 as a “medium” code review routing score — it means yes and no are equally likely. Conjunctions stay in your code.
Guardrails and escalation
If the gather step fails (empty PR description + selected hunks, redaction stripped everything, retriever empty), fail closed on approving a merge or skipping required review. Do not invent evidence so Jev has something to say. TypeSafe’s confidence-gated examples use a lower bar for recoverable reads than for irreversible actions. Those numbers are illustrations. For code review routing, treat auto_approve_merge as the high bar (approving a merge or skipping required review). Tune on labels — see offline evaluation.
Evaluation and rollout notes
Your eval set should include thin-evidence cases, not only happy PR description + selected hunkss. Label security_review / request_changes / merge_ok gold from staff engineers. Pin jev-1.13.0 (the versioned id) after you fit thresholds. jev-latest and the marketing line jev-1.13 can move. Log the response model. TypeSafe’s published list price for jev-1.13 is $0.042 per million input tokens (vendor claim — confirm on the models page); output tokens are free on that same page. Unused distractors still bill as input.
Official Python and JavaScript SDKs read TYPESAFE_API_KEY and retry documented 429/529. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.
Pack map
| Slice | Page |
|---|---|
| Graph and primitives | decision workflow |
What may enter state |
input contracts |
| What to gather first | you are here |
| Atomic rules | policy checks |
| Act / review / abstain | confidence thresholds |
| Reviewer payload | human handoff |
| What to persist | audit trail |
| How it breaks | failure modes |
| Labeled replay | evaluation |
| Shadow → canary | production rollout |
FAQ
Should evidence live in the question text?
Put facts in state and point instructions at pr.title, pr.body, hunks, policy.secrets. Criteria stay stable so you can replay.
When do I split calls?
needs_security + review_load + route in one call. TypeSafe’s agent-skill docs batch System One questions — that still does not replace tsc or CodeQL.
Where is the rest of the Code review pack? Start with Code review input contracts and Code review decision workflow. Cluster hub: Use cases.
Does the TypeSafe agent skill replace our linter? No. It teaches agents to batch questions. Analyzers still own AST truth. See agent skill.
Can Jev score cyclomatic complexity? Do not use a 2–10 Score as complexity math. Count in code or skip.
What this page does not claim
- Not a SAST, linter, or merge bot product.
- No published precision on vulnerability finding.
- Not official TypeSafe.
- Official TypeSafe status, or that jev.pro issues API keys.
- That a schema-constrained answer is automatically factually correct.
Disclaimer
This is an independent unofficial site and is not affiliated with TypeSafe AI; official documentation is available at https://docs.typesafe.ai.
Primary documentation: https://docs.typesafe.ai. Hub: Use cases.
Sources
Public TypeSafe or adjacent documentation only. No private claims.