Gate Alpha — AI review & SAST
Gate Alpha is the always-on first gate of the QualityMax pipeline. For every pull request it fetches the diff, runs an AI code review, and pairs it with a static application security test (SAST) scan. Findings from both land as inline PR comments — critical and high security findings are posted directly on the offending lines.
What the review covers
Section titled “What the review covers”The reviewer checks the diff against your configured review categories. By default that includes security, secrets scanning, performance, test coverage, type safety, accessibility, and style, plus agent-safety checks for code that touches AI tooling. You can narrow or widen the scope globally, and override it per repository — see review learning & preferences.
Evidence and uncertainty
Section titled “Evidence and uncertainty”The AI reviewer is instructed to report actionable defects introduced or exposed by the change, with a concrete trigger, execution path, observable impact, and supporting code evidence. It checks whether visible validation or another layer already handles a suspected issue and suggests the smallest practical fix. Security patterns such as secret masking, JSON escaping, and parameterized queries are assessed in their visible context.
This review uses the supplied diff and review context; it does not browse the repository or execute tests. Concrete unresolved material risks appear under Uncertainty in the summary as WARN, with the evidence needed to resolve them. They do not become inline defect findings unless a defect is confirmed. Missing context alone is not a defect, and a PASS is not proof that the change is defect-free.
Dismissal memory
Section titled “Dismissal memory”When you dismiss a finding, QualityMax remembers it for the repository. Future reviews of similar code retrieve those past dismissals before commenting, so the same false positive does not resurface on every PR. The memory is repo-scoped: dismissing a pattern in one repository never silences it in another.
SAST inside Alpha
Section titled “SAST inside Alpha”The security scan runs as part of the same gate and posts inline comments for critical- and high-severity findings with line context. Lower-severity findings are summarized in the check output rather than spammed onto the diff.
Verdicts
Section titled “Verdicts”| Verdict | Internal pipeline state | GitHub check conclusion | Blocks merge? |
|---|---|---|---|
PASS |
success |
success |
No |
WARN |
action_required |
neutral |
No |
BLOCK |
failure |
failure |
Yes |
A BLOCK is reserved for evidenced, reachable critical defects, including critical security issues, severe data loss or corruption, and correctness regressions that make a core path unusable. Confirmed non-critical defects and concrete unresolved material risks produce WARN. QualityMax retains that warning as action_required in its own UI and audit history, while publishing a terminal neutral GitHub check so a required check does not block the merge.
Request another review
Section titled “Request another review”On the pull request’s Checks tab, open a completed QualityMax Pipeline check and select Re-review. Repository writers can use this action to start a fresh Gate Alpha review of the current pull-request head. If the check belongs to an older commit, use the check for the current commit instead. You can also comment @qmax on the pull request to request another review.
When Alpha skips
Section titled “When Alpha skips”Alpha skips only when there is no PR context — a push to a branch without an open pull request. Every real PR gets reviewed.