{"id":20838453,"url":"https://github.com/reload/reviewbot","last_synced_at":"2026-04-10T06:02:50.034Z","repository":{"id":35809672,"uuid":"189959960","full_name":"reload/reviewbot","owner":"reload","description":"An experimental bot posting pending team review requests to Zulip. And a Google Cloud Function turning Github webhooks into Zulip messages requesting review.","archived":false,"fork":false,"pushed_at":"2026-02-09T05:05:10.000Z","size":520,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":2,"default_branch":"main","last_synced_at":"2026-02-09T11:16:46.279Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/reload.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2019-06-03T07:53:55.000Z","updated_at":"2026-02-09T05:04:33.000Z","dependencies_parsed_at":"2023-02-17T12:01:09.367Z","dependency_job_id":"b86eddda-1b62-40fa-a25d-b8f9108f221a","html_url":"https://github.com/reload/reviewbot","commit_stats":{"total_commits":130,"total_committers":3,"mean_commits":"43.333333333333336","dds":0.4076923076923077,"last_synced_commit":"504c4cea1c897d5ce5c05ed2d884eab4d7ffbf81"},"previous_names":[],"tags_count":181,"template":false,"template_full_name":null,"purl":"pkg:github/reload/reviewbot","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/reload%2Freviewbot","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/reload%2Freviewbot/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/reload%2Freviewbot/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/reload%2Freviewbot/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/reload","download_url":"https://codeload.github.com/reload/reviewbot/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/reload%2Freviewbot/sbom","scorecard":{"id":769964,"data":{"date":"2025-08-11","repo":{"name":"github.com/reload/reviewbot","commit":"f5946b367b01bceb36a9c410daf9522057f33965"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":6.1,"checks":[{"name":"Code-Review","score":3,"reason":"Found 1/3 approved changesets -- score normalized to 3","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":10,"reason":"12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/codeql-analysis.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dependency-review.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/dependency-review.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dependency-review.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/dependency-review.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-build.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/docker-build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-docker.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-docker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-docker.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-docker.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-docker.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-docker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-docker.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-docker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-docker.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-docker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-docker.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-docker.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-webhook.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-webhook.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-webhook.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-webhook.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-webhook.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-webhook.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-webhook.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-webhook.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-webhook.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/release-webhook.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/reload/reviewbot/test.yml/main?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1","Info:   0 out of  11 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  11 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: topLevel 'security-events' permission set to 'write': .github/workflows/codeql-analysis.yml:16","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:13","Info: topLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:14","Info: topLevel 'pull-requests' permission set to 'read': .github/workflows/codeql-analysis.yml:15","Info: topLevel 'contents' permission set to 'read': .github/workflows/dependency-review.yml:5","Info: topLevel 'contents' permission set to 'read': .github/workflows/docker-build.yml:9","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release-docker.yml:10","Warn: topLevel 'packages' permission set to 'write': .github/workflows/release-docker.yml:11","Info: topLevel 'actions' permission set to 'read': .github/workflows/release-docker.yml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/release-webhook.yml:10","Info: topLevel 'actions' permission set to 'read': .github/workflows/release-webhook.yml:11","Info: topLevel 'contents' permission set to 'read': .github/workflows/test.yml:10","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release-docker.yml:15"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (28) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-23T01:57:24.857Z","repository_id":35809672,"created_at":"2025-08-23T01:57:24.858Z","updated_at":"2025-08-23T01:57:24.858Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30113108,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-05T03:40:26.266Z","status":"ssl_error","status_checked_at":"2026-03-05T03:39:15.902Z","response_time":93,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-18T01:10:19.337Z","updated_at":"2026-03-05T07:00:58.829Z","avatar_url":"https://github.com/reload.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Reviewbot\n\n[![MIT Licensed](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n[![Go](https://img.shields.io/badge/language-Go-blue.svg)](https://go.dev/)\n\nAn experimental bot that posts pending team review requests to Zulip,\nplus a Google Cloud Function that turns GitHub webhooks into Zulip\nmessages requesting reviews.\n\n## Overview\n\n**Reviewbot** bridges the gap between GitHub pull requests and your\nteam’s Zulip chat. Whenever code is ready for review, Reviewbot\nnotifies your Zulip stream or topic, making it easier for teams to\ntrack PRs awaiting attention.\n\n- **GitHub → Zulip Integration:** Converts webhooks into Zulip\n  messages when PRs need review.\n- **Cloud Function Support:** Deployable as a Google Cloud Function\n  for scalable automation.\n- **Team Notifications:** Ensures timely notifications for code review\n  requests.\n\n## Features\n\n- Monitors GitHub repositories for new or pending PRs.\n- Posts relevant review requests in designated Zulip streams/topics.\n- Intended for team environments to reduce review friction.\n- Written in Go for performance and cloud-native deployment.\n\n## Requirements\n\n- [Go](https://go.dev/) (for development, building, or local running)\n- GitHub repository with webhook permissions\n- Zulip account, stream, and API information\n- [Google Cloud Functions](https://cloud.google.com/functions/)\n  (optional; for serverless deployment)\n\n## Installation\n\n1. **Clone the Repo**\n\n   ```bash\n   git clone https://github.com/reload/reviewbot.git\n   cd reviewbot\n   ```\n\n2. **Configure**\n   - Set up your GitHub webhook to point to your Reviewbot endpoint.\n   - Provide Zulip bot credentials and stream configuration.\n\n3. **Deploy**\n   - _As a Google Cloud Function_: Follow Google’s deployment\n     instructions and provide the proper environment variables.\n   - _Locally_: Run with `go run main.go` (additional configuration\n     may be needed).\n\n## Usage\n\n- When a pull request is created or marked ready for review in your\n  GitHub repository:\n  - Reviewbot receives the webhook, parses it, and posts a structured\n    message in your Zulip stream/topic requesting review from assigned\n    users or teams.\n\n## License\n\nMIT © [Reload](https://github.com/reload)\n\n---\n\n_Experimental project. Contributions and feedback welcome!_\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Freload%2Freviewbot","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Freload%2Freviewbot","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Freload%2Freviewbot/lists"}