Overview

Bubo 🦉

Bubo is patient — it sits silently, sees all, and strikes only when sure. It watches your repositories and speaks only when it finds something.

Agentic AI code review — with the LLM of your choice

01Self-hosted automated review and inline posting
02Bring-your-own-LLM
03GitLab or GitHub
04Built-in metrics
05Governance, provenance, audit, and ROI metrics
06MCP for on-demand reviews

Trust

Security & compliance posture

Secrets never leak

Sensitive information is redacted before it touches the LLM, reports, logs, or the database.

Signed & attested

Release artifacts are cosign-signed keyless via Sigstore + GitHub OIDC, carry SLSA Build L3 provenance, and ship an SBOM in SPDX JSON — all independently verifiable.

Report a vuln

Disclose responsibly per SECURITY.md.

Get started

See it in action

What a review looks like

merge request · inline finding
config/settings.example+ api_token = "••••••••••••••••"
LR
LLM Reviewer · botissue · blocking · security

Hard-coded credential committed

Impact anyone with repo access can use the token until it is revoked.

Fix remove it, rotate, and inject via a CI secret.

confidence 0.98
A blocking finding, posted inline — structured impact / evidence / fix with a confidence score.
recall · learning
LR
LLM Reviewer · botstyle · dismissed

Naming nit — skipped, not re-posted

Why this category was dismissed here before; suppression is on.

Recall & learning — a class your team keeps dismissing stops getting posted.

Real production metrics

Measured RoI

Speed is a given. Bubo's edge is signal density: multi-agent orchestration and deep codebase context surface only real structural and security flaws — in minutes — saving hundreds of senior-engineer hours.

259.5k
Changed LoC reviewed
across 2,809 files in 5 projects
0
False positives · 0 disputes
high signal density
43
Findings accepted
31 blocking · 65 resolved
~$77K
Reviewer time returned
for ~$200 of run cost — est. (see note)

Return on investment

Loaded reviewer rate
~$90/hr
Reviewer time returned
~$77K
Return on spend
~385×
Peer AI reviewers
$24–30/dev-mo

Reviewer time freed

Human first pass @300 LoC/hr
865 hrs
Bubo review wall time
4.67 hrs
Reviewer hours freed (est.)
~861
Reviewer-days freed (est.)
~108
Cost / reviewer-hour
~$0.23

Outcomes & precision

Findings tracked
91
Developer replied
70
Findings accepted
43
— of which blocking
31
Resolved
65
Resolution rate
71.4%
Disputed
0
False positives
0

Code reviewed

Projects
5
Files
2,809
Added LoC
147,316
Removed LoC
112,233
Changed LoC
259,549
Attempted LoC
271,034

Cost & efficiency

Total cost
~$200
Total tokens
13,125,521
Cost / 1k LoC
~$0.77
Tokens / LoC
50.6
Changed LoC / $
~1,300

Aggregates

Period
Jun 1–29, 2026
Total review runs
124
Completed
118
Completion rate
95.2%
Findings returned
74
Posted
66

Reviewer-hours and dollar figures are estimates. Careful peer review runs ~200–400 LoC/hr (300 midpoint); review effectiveness drops sharply above ~200 LoC/hr.[1][2] Reviewer time is valued at a fully-loaded ~$90/hr — the BLS May 2024 median for software developers ($133,080, ~$64/hr) at a conservative 1.4× benefits/overhead load.[3] Peer AI reviewers list at ~$24–30/developer-month (CodeRabbit, Greptile, Qodo, Graphite).[4] Bubo performs technical review — correctness, structure, and security — not subject-matter-expert or domain-specific review, and reads diff LoC at scale where a human would sample and skim mechanical changes; treat the figures as directional.

  • [1] Kemerer & Paulk, “The Impact of Design and Code Reviews on Software Quality,” IEEE Trans. Software Eng., 2009. sites.pitt.edu
  • [2] SmartBear, “Best Practices for Peer Code Review” (SmartBear/Cisco study). smartbear.com
  • [3] U.S. Bureau of Labor Statistics, “Software Developers,” Occupational Outlook Handbook, May 2024. bls.gov
  • [4] Vendor list pricing, accessed 2026: CodeRabbit, Greptile, Qodo, Graphite.
MountainOwlMountainOwl
Bubo · MIT licensed · © 2026