Code review policy checks with Jev
Linters, typecheckers, and SAST prove or pattern-match. Jev can decide whether leftover PR language looks like “needs security eyes” or “reviewer load is high.” It will not compile the repo or write the fix.
This unofficial page is the policy checks slice of the code review routing pack. Intent: apply the Jev (TypeSafe System One) decision model to code review routing policy checks. Primary search language: Code review Jev policy checks. Confirm patterns on docs.typesafe.ai. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.
Independent angle (cover ≠ clone): Analyzers own AST truth; Jev routes review judgment on PR prose + small hunks. Not a SAST clone and not a rival “agent skill” IA photocopy.
Code review use-case context
A policy check is a typed question whose instructions + criteria are your rules about the PR description + selected hunks. Jev scores compliance; the review router enforces. This is not a certification, and it is not a photocopy of a rival “policy engine” page — we keep rules atomic and ANDed in code.
Hub: Use cases. Compare, when the other tool is the real job: code analyzers.
Policy Checks inputs
Put policy text and the artifact in structured state (never hope the model memorized last quarter’s PDF):
{
"pr": { "id": "1234", "title": "Relax auth on internal debug route", "body": "Temp bypass for the oncall drill." },
"hunks": ["- if (!user) return 401;", "+ // skip auth in staging"],
"ci": { "sast_blockers": 0, "lint_errors": 0 },
"policy": { "secrets": "Flag prose that describes committing keys or disabling auth in prod-shaped paths." }
}
Name pr.title, pr.body, hunks, policy.secrets.
Decision signals and actions
| Id | Rule | Enforce |
|---|---|---|
sast_first |
Definite AST defects block in CI | analyzer |
auth_prose |
PR language about bypassing auth | Jev Noul |
secret_regex |
Known key patterns | pre-commit / scanner, not Jev |
Typical primitives on the same request:
| Id | Type | Job |
|---|---|---|
needs_security |
Noul | Does the PR prose/hunks look like an auth or secrets risk vs policy.secrets? |
review_load |
Score | How much human judgment does this leftover diff still need? |
route |
Choice | merge_ok_if_ci / request_changes / security_review / other |
violations = [name for name, ans in policy_nouls.items() if ans.noul >= T_VIOLATION]
if violations:
return review(violations)
Do not treat a Noul of 0.5 as a “medium” code review routing score — it means yes and no are equally likely. Conjunctions stay in your code.
Guardrails and escalation
Policy-in-state can be attacked (“ignore the policy”). High-risk approving a merge or skipping required review still needs deterministic checks. TypeSafe’s confidence-gated examples use a lower bar for recoverable reads than for irreversible actions. Those numbers are illustrations. For code review routing, treat auto_approve_merge as the high bar (approving a merge or skipping required review). Tune on labels — see offline evaluation.
Evaluation and rollout notes
Gold labels are policy-versioned. A criteria edit without replay is how silent false-allows ship. Pin jev-1.13.0 (the versioned id) after you fit thresholds. jev-latest and the marketing line jev-1.13 can move. Log the response model. TypeSafe’s published list price for jev-1.13 is $0.042 per million input tokens (vendor claim — confirm on the models page); output tokens are free on that same page. Unused distractors still bill as input.
Official Python and JavaScript SDKs read TYPESAFE_API_KEY and retry documented 429/529. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.
Pack map
| Slice | Page |
|---|---|
| Graph and primitives | decision workflow |
What may enter state |
input contracts |
| What to gather first | evidence collection |
| Atomic rules | you are here |
| Act / review / abstain | confidence thresholds |
| Reviewer payload | human handoff |
| What to persist | audit trail |
| How it breaks | failure modes |
| Labeled replay | evaluation |
| Shadow → canary | production rollout |
FAQ
One Score for “compliant”? No. Atomic Nouls per rule, AND/OR in code. Money and dates: extract in code first (jaggedness).
If a regex can enforce it, should I still call Jev? Skip Jev. Official “how to build” guidance: keep deterministic rules in code when you can.
Where is the rest of the Code review pack? Start with Code review decision workflow and Code review human handoff. Cluster hub: Use cases.
Does the TypeSafe agent skill replace our linter? No. It teaches agents to batch questions. Analyzers still own AST truth. See agent skill.
Can Jev score cyclomatic complexity? Do not use a 2–10 Score as complexity math. Count in code or skip.
What this page does not claim
- Not a SAST, linter, or merge bot product.
- No published precision on vulnerability finding.
- Not official TypeSafe.
- Official TypeSafe status, or that jev.pro issues API keys.
- That a schema-constrained answer is automatically factually correct.
Disclaimer
This is an independent unofficial site and is not affiliated with TypeSafe AI; official documentation is available at https://docs.typesafe.ai.
Primary documentation: https://docs.typesafe.ai. Hub: Use cases.
Sources
Public TypeSafe or adjacent documentation only. No private claims.