{
 "sym": "Cq",
 "updated": "2026-08-06",
 "verdict": "CodeRabbit, for most teams \u2014 the category it effectively created still belongs to it: $40M ARR by April 2026 (up 700% YoY), 15,000+ customers, and the most-installed AI app on both GitHub and GitLab. The context that makes this element non-optional: AI now writes roughly half of committed code and its security pass rate has stalled at 56% (Veracode, Jul 2026). Copilot code review wins when you already pay for Copilot \u2014 60M reviews and 1 in 5 of all GitHub reviews is distribution nobody matches; Graphite when the review process itself (stacks, merge queue) is the bottleneck; Greptile when you want the deepest full-codebase context with the least noise; Bugbot when your team lives in Cursor and wants a pure bug-hunter on the diff.",
 "top5": [
  {
   "rank": 1,
   "name": "CodeRabbit",
   "maker": "CodeRabbit Inc.",
   "url": "https://www.coderabbit.ai",
   "docs": "https://docs.coderabbit.ai",
   "pricing": "Free tier (PR summaries, IDE/CLI reviews) \u00b7 Pro $24/user/mo \u00b7 Pro Plus $48 \u00b7 Enterprise custom (self-host)",
   "best_for": "Teams shipping AI-speed code who want line-by-line PR review with linters, security checks, and chat \u2014 installed in minutes on GitHub/GitLab/Azure/Bitbucket.",
   "why": "The standalone-category leader by every measure: ~$40M ARR in April 2026, up 700% from ~$5M a year earlier (Sacra est.); 15,000+ customers, 6M repositories, 75M defects found; most-installed AI app on GitHub and GitLab. The $60M Series B (Sep 2025, $550M valuation) was pitched explicitly on vibe-coding cleanup demand \u2014 the same 2.7x-vulnerability wave this element exists to tax.",
   "watch": "Comment volume is the perennial complaint \u2014 tuning is required before it feels like a colleague rather than a lint firehose. ARR figures are Sacra estimates, not audited. Bundled reviewers (Copilot, Bugbot, Claude Code Review) are commoditizing baseline review from above.",
   "evidence": [
    {
     "stat": "$40M ARR Apr 2026, +700% YoY from ~$5M (Sacra estimate)",
     "src": "https://sacra.com/c/coderabbit/"
    },
    {
     "stat": "$60M Series B at $550M valuation, Sep 16, 2025 (Scale Venture Partners)",
     "src": "https://markets.financialcontent.com/observerreporter/article/bizwire-2025-9-16-coderabbit-raises-60m-series-b-following-unprecedented-growth-as-vibe-coding-triggers-a-need-for-new-code-quality-standards"
    },
    {
     "stat": "15,000+ customers \u00b7 6M repos \u00b7 75M defects found \u00b7 most-installed AI app on GitHub and GitLab (vendor, Aug 2026)",
     "src": "https://www.coderabbit.ai"
    }
   ],
   "tile_note": "the category leader"
  },
  {
   "rank": 2,
   "name": "Copilot code review",
   "maker": "Microsoft / GitHub",
   "url": "https://github.com/features/copilot",
   "docs": "https://docs.github.com/en/copilot/concepts/agents/code-review",
   "pricing": "Included in all paid Copilot plans (Pro $10/mo \u2192 Enterprise $39/user) \u00b7 consumes AI credits per review \u00b7 not on Copilot Free",
   "best_for": "Teams already paying for Copilot who want a reliable first-pass review on every PR with zero new vendors, contracts, or apps.",
   "why": "Distribution nobody can answer: 60M reviews since the April 2025 launch, 10x usage growth, and more than 1 in 5 of all code reviews on GitHub by March 2026, with 12,000+ orgs auto-reviewing every PR. Quality is climbing \u2014 71% of reviews surface actionable feedback, and agent skills + MCP context went GA July 29, 2026.",
   "watch": "Depth trails the specialists in most independent roundups \u2014 it reviews the diff well but reads the codebase less deeply than Greptile or CodeRabbit. GitHub-only. The 2026 shift to AI-credit billing makes per-review cost opaque, and reviews are blocked when credit budgets run out.",
   "evidence": [
    {
     "stat": "60M reviews since Apr 2025; >1 in 5 of all GitHub code reviews (GitHub blog, Mar 5, 2026)",
     "src": "https://github.blog/ai-and-ml/github-copilot/60-million-copilot-code-reviews-and-counting/"
    },
    {
     "stat": "12,000+ orgs auto-review every PR; 71% of reviews surface actionable feedback (Mar 2026)",
     "src": "https://github.blog/ai-and-ml/github-copilot/60-million-copilot-code-reviews-and-counting/"
    },
    {
     "stat": "Agent skills + MCP servers GA for code review, Jul 29, 2026",
     "src": "https://github.blog/changelog/2026-07-29-copilot-code-review-agent-skills-and-mcp-now-generally-available/"
    }
   ],
   "tile_note": "one in five reviews"
  },
  {
   "rank": 3,
   "name": "Graphite",
   "maker": "Graphite \u2192 Cursor/Anysphere (Dec 2025; \u2192 SpaceX pending)",
   "url": "https://graphite.com",
   "docs": "https://graphite.com/docs",
   "pricing": "Hobby free \u00b7 Starter $20/user/mo \u00b7 Team $40 (unlimited AI reviews, merge queue) \u00b7 Enterprise custom",
   "best_for": "Teams who want to fix the review process, not just add a bot \u2014 stacked PRs, merge queue, and the Diamond AI reviewer in one flow.",
   "why": "The only top-5 pick that re-architects review itself: stacked PRs plus merge queue plus AI review (Diamond, launched with the $52M Accel-led Series B in March 2025 \u2014 Anthropic's Anthology Fund participated). Used by hundreds of thousands of engineers, and now the code-review arm of the Cursor empire after the December 19, 2025 acquisition \u2014 the strongest possible signal that review and generation are converging.",
   "watch": "Ownership churn squared: acquired by Cursor, which is itself being acquired by SpaceX ($60B, close expected Q3 2026). Stacked-PR workflow has a real adoption cost for teams happy with plain PRs, and unlimited AI review requires the $40 Team tier.",
   "evidence": [
    {
     "stat": "$52M Series B (Accel) + Diamond AI reviewer launch, Mar 19, 2025",
     "src": "https://thesaasnews.com/news/graphite-raises-52-million-in-series-b"
    },
    {
     "stat": "Acquired by Cursor Dec 19, 2025; continues to operate independently",
     "src": "https://cursor.com/blog/graphite"
    },
    {
     "stat": "Team $40/user/mo: unlimited AI reviews, merge queue, automations (Aug 2026)",
     "src": "https://graphite.com/pricing"
    }
   ],
   "tile_note": "stacked review flow"
  },
  {
   "rank": 4,
   "name": "Greptile",
   "maker": "Greptile (YC W24)",
   "url": "https://www.greptile.com",
   "docs": "https://docs.greptile.com",
   "pricing": "Free 50 credits/mo \u00b7 Pro $30/seat incl. 50 reviews, $1/extra review \u00b7 Enterprise custom (self-host, SSO)",
   "best_for": "Complex codebases and monorepos \u2014 it indexes the whole repository graph so reviews catch cross-file breakage a diff-reader can't see.",
   "why": "The context-depth play: full-codebase indexing rather than diff-only review, a v3 rewrite the company says catches 3x more critical bugs than v2, and a learning system that absorbs your engineers' review comments. Benchmark led the $25M Series A (Sep 23, 2025); customers include Brex, Substack, and PostHog, with 500M+ lines reviewed and 180k+ bugs prevented at announcement.",
   "watch": "Per-credit pricing stacks up fast on high-throughput repos ($1/review beyond the included 50). Headline bug-catch numbers are self-published, not independently benchmarked. Smallest vendor in the top 5 \u2014 procurement-sensitive orgs will notice.",
   "evidence": [
    {
     "stat": "$25M Series A led by Benchmark, Sep 23, 2025; v3 claims 3x more critical bugs vs v2",
     "src": "https://www.greptile.com/blog/series-a"
    },
    {
     "stat": "500M+ lines of code reviewed, 180,000+ bugs prevented (Sep 2025)",
     "src": "https://www.greptile.com/blog/series-a"
    },
    {
     "stat": "Pro $30/seat with 50 reviews included; extra reviews $1 (Aug 2026)",
     "src": "https://www.greptile.com/pricing"
    }
   ],
   "tile_note": "full-codebase context"
  },
  {
   "rank": 5,
   "name": "Bugbot",
   "maker": "Cursor/Anysphere (\u2192 SpaceX pending)",
   "url": "https://cursor.com/bugbot",
   "docs": "https://cursor.com/docs/bugbot",
   "pricing": "Usage-based $1.00\u20131.50/review since Jun 8, 2026 (was $40/seat/mo) \u00b7 individuals draw from Cursor plan usage",
   "best_for": "Cursor-native teams who want a pure bug-hunter on every PR \u2014 logic errors and edge cases, not style commentary \u2014 with one-click fixes back in the editor.",
   "why": "Rides the largest AI-coding install base on earth (Cursor: 1M+ paying users, $3B ARR by May 2026) and stays deliberately narrow: hard bugs only, with a claimed 80% resolution rate on flagged issues and a high-effort mode that finds 35% more bugs at the same precision (May 2026). The June 2026 move to $1\u20131.50 per review made it the cheapest credible entry point in the category.",
   "watch": "Not a full reviewer \u2014 no summaries, style, or architectural feedback; you still need review process elsewhere. Pricing model changed twice inside a year, and the SpaceX acquisition adds the same ownership uncertainty as Graphite. GitHub-focused.",
   "evidence": [
    {
     "stat": "Moved from $40/seat to usage-based $1.00\u20131.50/review, effective Jun 8, 2026",
     "src": "https://cursor.com/blog/may-2026-bugbot-changes"
    },
    {
     "stat": "80% resolution rate on flagged bugs; high-effort mode +35% bugs found (Cursor, May 2026)",
     "src": "https://cursor.com/blog/may-2026-bugbot-changes"
    },
    {
     "stat": "Distribution base: Cursor $3B ARR, 1M+ paying users (May 2026)",
     "src": "https://en.wikipedia.org/wiki/Cursor_(company)"
    }
   ],
   "tile_note": "cursor-native bug hunter"
  }
 ],
 "matrix": {
  "cols": [
   "Pricing model",
   "Free tier",
   "Context depth",
   "Learns your rules",
   "Platforms",
   "Autofix",
   "Self-host"
  ],
  "rows": [
   [
    "CodeRabbit",
    "Seat $24\u201348",
    "Yes (+ OSS free)",
    "Repo + linked repos + 40 linters",
    "Yes (chat, learnings)",
    "GitHub \u00b7 GitLab \u00b7 Azure \u00b7 Bitbucket",
    "1-click fixes",
    "Enterprise"
   ],
   [
    "Copilot code review",
    "AI credits on paid plans",
    "No (paid Copilot only)",
    "Diff + agentic context",
    "Instructions + skills + MCP",
    "GitHub only",
    "Suggested edits",
    "No"
   ],
   [
    "Graphite",
    "Seat $20\u201340",
    "Hobby free",
    "PR + stack context",
    "Customizations, automations",
    "GitHub (GHES on Ent.)",
    "Limited",
    "No (GHES support)"
   ],
   [
    "Greptile",
    "Seat $30 + $1/review",
    "50 reviews/mo",
    "Full codebase graph",
    "Yes (learns from comments)",
    "GitHub \u00b7 GitLab",
    "Agent-ready fix prompts",
    "Enterprise"
   ],
   [
    "Bugbot",
    "$1\u20131.50/review",
    "Via Cursor plans",
    "Diff-focused, bug-only",
    "Rules + effort levels",
    "GitHub",
    "Fix in Cursor",
    "No"
   ],
   [
    "Qodo",
    "Credits $0.012 ea",
    "14-day trial + OSS free",
    "Repo-aware",
    "Rules; self-learning (Ent.)",
    "GitHub \u00b7 GitLab \u00b7 Bitbucket \u00b7 Azure",
    "Yes",
    "On-prem / single-tenant"
   ],
   [
    "Claude Code Review",
    "$15\u201325/review (usage credits)",
    "No (Team/Ent preview)",
    "Full codebase, multi-agent + verification",
    "CLAUDE.md + REVIEW.md",
    "GitHub (GitLab via CI)",
    "Via Claude Code /code-review --fix",
    "Run in own CI"
   ],
   [
    "PR-Agent (community)",
    "Free + your tokens",
    "Yes (Apache-2.0)",
    "Diff-focused",
    "Config files",
    "GitHub \u00b7 GitLab \u00b7 Bitbucket \u00b7 Gitea",
    "Suggestions",
    "Yes"
   ]
  ]
 },
 "rules": [
  {
   "if": "Coding agents are writing most of your code and PRs pile up faster than humans can read them",
   "then": "CodeRabbit \u2014 the fastest install-to-value in the category, then spend a week tuning its noise down. Review is the tax on AI velocity; this automates the tax."
  },
  {
   "if": "You already pay for Copilot and procurement hates new vendors",
   "then": "Turn on Copilot code review org-wide \u2014 a 71%-actionable first pass for AI credits you already budget, with the honest caveat that it reads the diff, not your architecture."
  },
  {
   "if": "Review latency is the bottleneck \u2014 big PRs rotting for days",
   "then": "Graphite \u2014 stacked PRs plus merge queue attacks the process, and Diamond handles the first pass. Accept the Cursor\u2192SpaceX ownership uncertainty."
  },
  {
   "if": "You run a monorepo or a gnarly legacy codebase where diff-only review misses cross-file breakage",
   "then": "Greptile \u2014 full-codebase indexing is the whole product; budget ~$1/review beyond the included 50."
  },
  {
   "if": "You expect AI review to catch security holes",
   "then": "Don't \u2014 AI code stalls at a 56% security pass rate (Veracode, Jul 2026) and general reviewers are not SAST. Pair any pick with a real scanner (Snyk/Semgrep class) and, if on Claude, the free claude-code-security-review action."
  }
 ],
 "field": [
  {
   "name": "Qodo (Qodo Merge)",
   "maker": "Qodo (ex-CodiumAI)",
   "note": "Enterprise agentic review platform (credits at $0.012, BYOK, on-prem); expanded to Azure DevOps Feb 2026; handed its open-source PR-Agent to the community Apr 2026 \u2014 the strongest enterprise near-miss for the top 5",
   "url": "https://www.qodo.ai",
   "oss": false,
   "entry": "credits $0.012 \u00b7 Ent. 30+ seats",
   "status": "active"
  },
  {
   "name": "Claude Code Review",
   "maker": "Anthropic",
   "note": "Multi-agent review with a false-positive verification pass, on Anthropic infra; research preview for Team/Enterprise at $15\u201325/review; /code-review runs free-of-setup locally on any plan; deepest verification story, narrowest availability",
   "url": "https://code.claude.com/docs/en/code-review",
   "oss": false,
   "entry": "$15\u201325/review (usage credits)",
   "status": "active"
  },
  {
   "name": "PR-Agent",
   "maker": "community (Apache-2.0, ex-Qodo)",
   "note": "The original open-source PR reviewer \u2014 re-licensed AGPL\u2192Apache-2.0 and moved to community governance Apr 23, 2026; the default free self-hosted answer",
   "url": "https://github.com/The-PR-Agent/pr-agent",
   "oss": true,
   "entry": "free + tokens",
   "status": "active"
  },
  {
   "name": "claude-code-security-review",
   "maker": "Anthropic (open source)",
   "note": "Free GitHub Action doing security-focused diff review with Claude; a June 2026 prompt-injection flaw in the broader claude-code-action was patched \u2014 audit your workflow permissions",
   "url": "https://github.com/anthropics/claude-code-security-review",
   "oss": true,
   "entry": "free + API tokens",
   "status": "active"
  },
  {
   "name": "Gemini Code Assist on GitHub",
   "maker": "Google",
   "note": "The free consumer review agent was shut down Jul 17, 2026 (deprecated Jun 18) \u2014 enterprise version via Google Cloud continues; same retreat pattern as Gemini CLI",
   "url": "https://developers.google.com/gemini-code-assist/docs/deprecations/consumer-code-review",
   "oss": false,
   "entry": "enterprise only",
   "status": "sunsetting"
  },
  {
   "name": "Ellipsis",
   "maker": "Ellipsis (YC W24)",
   "note": "Early AI reviewer that expanded upward \u2014 launched 'Agent Cloud' (managed coding agents) Jul 28, 2026; review remains but is no longer the whole company; 400+ teams",
   "url": "https://www.ellipsis.dev",
   "oss": false,
   "entry": "~$20/dev/mo",
   "status": "active"
  },
  {
   "name": "Sourcery",
   "maker": "Sourcery AI",
   "note": "Veteran review + refactoring bot for GitHub/GitLab, Python roots; steady but out-momentumed by the funded pack",
   "url": "https://sourcery.ai",
   "oss": false,
   "entry": "free OSS \u00b7 ~$12/mo",
   "status": "active"
  },
  {
   "name": "Bito AI Code Review Agent",
   "maker": "Bito",
   "note": "Repo-aware review agent with static-analysis/security tool fusion; free plan plus ~$15/user teams tier",
   "url": "https://bito.ai",
   "oss": false,
   "entry": "free \u00b7 ~$15/user/mo",
   "status": "active"
  },
  {
   "name": "Baz",
   "maker": "Baz (Guy Eisenkot)",
   "note": "AI-native review platform pitching governance/specs for AI-generated code; seed-stage, enterprise-leaning",
   "url": "https://baz.co",
   "oss": false,
   "entry": "unverified",
   "status": "active"
  },
  {
   "name": "cubic",
   "maker": "cubic (YC X25)",
   "note": "'Cursor for code review' \u2014 review UI + AI reviewer aimed at AI-generated-code failure modes",
   "url": "https://www.cubic.dev",
   "oss": false,
   "entry": "free tier",
   "status": "active"
  },
  {
   "name": "Macroscope",
   "maker": "Macroscope",
   "note": "Code review + codebase-understanding layer; markets itself against Bugbot",
   "url": "https://macroscope.com",
   "oss": false,
   "entry": "unverified",
   "status": "active"
  },
  {
   "name": "Entelligence",
   "maker": "Entelligence AI",
   "note": "Review bot + engineering-intelligence dashboards (aggregator-sourced; verify before buying)",
   "url": "https://www.entelligence.ai",
   "oss": false,
   "entry": "free tier",
   "status": "active"
  },
  {
   "name": "CodeAnt AI",
   "maker": "CodeAnt (YC W24)",
   "note": "Review + SAST hybrid \u2014 one of the few pitching security and review in one bot",
   "url": "https://www.codeant.ai",
   "oss": false,
   "entry": "~$10/dev/mo",
   "status": "active"
  },
  {
   "name": "Panto AI",
   "maker": "Panto",
   "note": "Context-aware PR review agent, India-based, undercuts on price (aggregator-sourced)",
   "url": "https://www.getpanto.ai",
   "oss": false,
   "entry": "free tier",
   "status": "active"
  },
  {
   "name": "Korbit AI",
   "maker": "Korbit",
   "note": "Mentor-style PR reviews with quality scoring; quiet through 2026 roundups",
   "url": "https://www.korbit.ai",
   "oss": false,
   "entry": "~$9/dev/mo",
   "status": "fading"
  },
  {
   "name": "DeepSource",
   "maker": "DeepSource (YC W20)",
   "note": "Static analysis platform with AI Autofix \u2014 code-quality adjacent rather than conversational review",
   "url": "https://deepsource.com",
   "oss": false,
   "entry": "free \u00b7 ~$24/seat",
   "status": "active"
  },
  {
   "name": "Codacy",
   "maker": "Codacy",
   "note": "Classic code-quality platform bolting on AI guardrails for AI-generated code",
   "url": "https://www.codacy.com",
   "oss": false,
   "entry": "free \u00b7 ~$15/seat",
   "status": "active"
  },
  {
   "name": "SonarQube AI Code Assurance",
   "maker": "Sonar",
   "note": "The 400k-org static-analysis incumbent's answer: detect/assure AI-written code; complements rather than replaces agentic reviewers",
   "url": "https://www.sonarsource.com",
   "oss": true,
   "entry": "free community \u00b7 paid tiers",
   "status": "active"
  },
  {
   "name": "CodeScene",
   "maker": "CodeScene",
   "note": "Behavioral code analysis + ACE auto-refactoring; technical-debt lens on review",
   "url": "https://codescene.com",
   "oss": false,
   "entry": "free trial \u00b7 per-seat",
   "status": "active"
  },
  {
   "name": "Sweep",
   "maker": "Sweep AI (YC S23)",
   "note": "Left the review/PR-bot business \u2014 pivoted to a JetBrains autocomplete/coding assistant",
   "url": "https://sweep.dev",
   "oss": false,
   "entry": "\u2014",
   "status": "fading"
  },
  {
   "name": "What The Diff",
   "maker": "Beyond Code",
   "note": "Early AI PR-summary tool (2022 wave); superseded by full review agents",
   "url": "https://whatthediff.ai",
   "oss": false,
   "entry": "free tier",
   "status": "fading"
  },
  {
   "name": "Codeball",
   "maker": "Sturdy (YC)",
   "note": "2022 deep-learning PR reviewer; repo dormant for years \u2014 the category's first graveyard entry",
   "url": "https://github.com/sturdy-dev/codeball-action",
   "oss": true,
   "entry": "\u2014",
   "status": "dead"
  },
  {
   "name": "PullRequest",
   "maker": "\u2192 HackerOne",
   "note": "Human code-review-as-a-service marketplace, acquired by HackerOne (2022) and absorbed into its security offering",
   "url": "https://www.pullrequest.com",
   "oss": false,
   "entry": "\u2014",
   "status": "acquired"
  }
 ],
 "signals": [
  {
   "fact": "AI now authors ~half of committed code, but its security pass rate stalled at 56% (55% in 2025) \u2014 ~44% of AI code-generation tasks introduce vulnerabilities; top model (GPT-5.5) only 68% (Veracode 2026 GenAI Code Security Report, Jul 28, 2026, 100+ models)",
   "src": "https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/"
  },
  {
   "fact": "Copilot code review passed 60M reviews and >1 in 5 of all code reviews on GitHub (Mar 2026) \u2014 bundled review is now the category's biggest player by volume",
   "src": "https://github.blog/ai-and-ml/github-copilot/60-million-copilot-code-reviews-and-counting/"
  },
  {
   "fact": "CodeRabbit: ~$5M \u2192 ~$40M ARR Apr 2025 \u2192 Apr 2026 (+700%, Sacra est.); $60M Series B at $550M (Sep 2025) raised explicitly on vibe-coding cleanup demand",
   "src": "https://sacra.com/c/coderabbit/"
  },
  {
   "fact": "Consolidation into codegen platforms: Cursor acquired Graphite Dec 19, 2025, then agreed to be acquired by SpaceX for $60B (Jun 2026) \u2014 putting two of the top five reviewers (Graphite, Bugbot) under one pending owner",
   "src": "https://techcrunch.com/2025/12/19/cursor-continues-acquisition-spree-with-graphite-deal"
  },
  {
   "fact": "Pricing is shifting seat \u2192 usage across the category in 2026: Bugbot $40/seat \u2192 $1\u20131.50/review (Jun 8), Qodo credits at $0.012, Claude Code Review $15\u201325/review, Copilot per-review AI credits",
   "src": "https://cursor.com/blog/may-2026-bugbot-changes"
  },
  {
   "fact": "Free/community tiers in flux: Google shut its consumer Gemini Code Assist review agent Jul 17, 2026 (enterprise-only now); Qodo handed PR-Agent to community governance under Apache-2.0 (Apr 23, 2026)",
   "src": "https://developers.google.com/gemini-code-assist/docs/deprecations/consumer-code-review"
  }
 ],
 "notes": "Ranking criteria: verified adoption/revenue, review depth (codebase context, false-positive control), platform breadth, and momentum \u2014 no affiliate consideration. On the tile's '2.7x vulnerability rate': we could not trace 2.7x to a primary study (it circulates via SEO aggregators like SQ Magazine without citation); the defensible anchor is Veracode's Jul 2026 finding that ~44% of AI code-generation tasks introduce vulnerabilities and the pass rate has stalled at 56% \u2014 treat 2.7x as directionally right, not citable. Conflicts resolved: CodeRabbit and Qodo ARR figures are Sacra/aggregator estimates, not audited \u2014 we cite them as estimates; ideaplan.io's '$420M category ARR / 140k paid users' market-share numbers are aggregator-only and excluded from signals; Greptile's '3x more bugs' and Bugbot's '80% resolution' are vendor-published. Claude Code Review sits in the field, not the top 5, because it is a research preview restricted to Team/Enterprise plans at $15\u201325/review \u2014 technically the most rigorous verification pipeline in the category, but not yet broadly buyable; revisit next quarter. Adjacent elements: coding agents that also review (Claude Code, Cursor, Copilot as assistants) \u2192 Ca; SAST/security scanners proper (Snyk, Semgrep, Veracode, Checkmarx) are security tooling, not this element \u2014 only review/SAST hybrids (CodeAnt, Sonar) get field entries; LLM-app evals \u2192 Ev. Graphite ownership stated as Cursor/Anysphere with SpaceX close pending Q3 2026.",
 "sources": [
  "https://sacra.com/c/coderabbit/",
  "https://www.coderabbit.ai/pricing",
  "https://markets.financialcontent.com/observerreporter/article/bizwire-2025-9-16-coderabbit-raises-60m-series-b-following-unprecedented-growth-as-vibe-coding-triggers-a-need-for-new-code-quality-standards",
  "https://github.blog/ai-and-ml/github-copilot/60-million-copilot-code-reviews-and-counting/",
  "https://github.blog/changelog/2026-07-29-copilot-code-review-agent-skills-and-mcp-now-generally-available/",
  "https://docs.github.com/en/copilot/concepts/agents/code-review",
  "https://cursor.com/blog/graphite",
  "https://techcrunch.com/2025/12/19/cursor-continues-acquisition-spree-with-graphite-deal",
  "https://graphite.com/pricing",
  "https://thesaasnews.com/news/graphite-raises-52-million-in-series-b",
  "https://cursor.com/blog/may-2026-bugbot-changes",
  "https://www.greptile.com/blog/series-a",
  "https://www.greptile.com/pricing",
  "https://www.qodo.ai/pricing/",
  "https://www.qodo.ai/blog/qodo-is-handing-pr-agent-over-to-the-community/",
  "https://code.claude.com/docs/en/code-review",
  "https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/",
  "https://www.businesswire.com/news/home/20260728207685/en/LLMs-Are-Getting-Smarter-But-Not-Safer-Veracode-2026-GenAI-Code-Security-Report-Finds-AI-Generated-Code-Security-Has-Stalled-at-56-Pass-Rate",
  "https://developers.google.com/gemini-code-assist/docs/deprecations/consumer-code-review",
  "https://github.com/The-PR-Agent/pr-agent",
  "https://en.wikipedia.org/wiki/Cursor_(company)"
 ],
 "element": {
  "number": 7,
  "name": "Code Review",
  "group": "Build",
  "essential": false,
  "edition": "v2026.Q3",
  "revision": "r7",
  "license": "CC BY 4.0 \u2014 cite elems.ai",
  "url": "https://elems.ai/e/cq.html"
 }
}