Back to articles
Technology Insight

Automating Code Quality: Building a Local LLM-Powered AI Code Reviewer for Forgejo Actions

June 1, 2026

Introduction

In the fast-paced world of software development, code reviews are essential for maintaining code quality, ensuring security, and sharing knowledge across teams. However, manual code reviews can often become a bottleneck, delaying deployments and draining valuable engineering resources. With the rise of Large Language Models (LLMs), automating initial code assessments has become a viable reality.

While cloud-based AI tools offer powerful capabilities, they often raise critical concerns regarding data privacy, intellectual property protection, and recurring subscription costs. For enterprises and privacy-conscious development teams utilizing Forgejo—the self-hosted, community-driven software development platform—the ideal solution lies in self-hosting. This comprehensive guide will walk you through building an automated AI Code Reviewer using a Local LLM integrated directly into Forgejo Actions.

Why Choose a Local LLM with Forgejo Actions?

Integrating a local AI reviewer into your Forgejo workflow provides a perfect balance of automation and security. Here is why this architecture is highly advantageous for modern engineering teams:

  • Absolute Data Privacy: Your source code never leaves your infrastructure. By running LLMs locally, you eliminate the risk of third-party data leaks or compliance violations (such as GDPR or HIPAA).
  • Zero Operational API Costs: Unlike OpenAI or Anthropic APIs that charge per token, a local LLM runs on your own hardware (GPUs/CPUs), making the marginal cost of running thousands of code reviews effectively zero.
  • Deep Integration with Forgejo: Forgejo Actions (compatible with GitHub Actions syntax) allows you to seamlessly trigger code reviews on every pull request, commit, or branch update automatically.
  • Customized Code Standards: Local models can be prompted, fine-tuned, or given specific system instructions to align precisely with your team's internal coding conventions and architectural patterns.

Architectural Overview

Before diving into the implementation, let us understand how the components interact. The automated workflow follows a structured lifecycle whenever a developer submits a pull request:

  1. Event Trigger: A developer opens or updates a Pull Request (PR) in Forgejo.
  2. Workflow Execution: Forgejo Actions triggers a runner to execute a designated YAML workflow.
  3. Code Diff Extraction: The runner fetches the code changes (git diff) between the source and target branches.
  4. LLM Processing: The runner sends the diff along with a structured system prompt to a locally hosted LLM engine (e.g., Ollama or vLLM).
  5. Feedback Generation: The local LLM analyzes the code for bugs, security vulnerabilities, and code smells, then formats its critique.
  6. Comment Injection: The workflow uses Forgejo's API to post the AI's review directly as a comment or inline review on the PR.

Step-by-Step Implementation Guide

Step 1: Setting Up the Local LLM Server

To serve our language model efficiently, we will use Ollama, an open-source tool designed for running LLMs locally with minimal configuration. For code review tasks, models like DeepSeek-Coder, CodeLlama, or Qwen2.5-Coder yield exceptional results.

Install Ollama on your dedicated AI server or GPU-enabled runner node:

curl -fsSL [https://ollama.com/install.sh](https://ollama.com/install.sh) | sh

Once installed, pull a high-performing coding model. For a balance of speed and accuracy, the 7-billion or 14-billion parameter versions are highly recommended:

ollama run qwen2.5-coder:7b

Ensure that the Ollama API is accessible over your internal network by configuring the OLLAMA_HOST=0.0.0.0 environment variable so that Forgejo Actions runners can reach it.

Step 2: Creating the Review Script

We need a lightweight script to act as the intermediary between Forgejo and our Local LLM. Below is a conceptual Python script (ai_reviewer.py) that extracts the git diff, formats the prompt, and sends it to Ollama:

import os
import requests

# Configuration from environment variables
OLLAMA_URL = os.getenv("OLLAMA_HOST", "http://localhost:11434") + "/api/generate"
MODEL_NAME = os.getenv("LLM_MODEL", "qwen2.5-coder:7b")
DIFF_FILE = "changes.diff"

with open(DIFF_FILE, "r") as f:
    code_diff = f.read()

system_prompt = (
    "You are an expert senior software engineer and security auditor. "
    "Review the following git diff. Identify potential bugs, security flaws, performance bottlenecks, "
    "and violations of clean code principles. Provide constructive feedback with code examples where applicable. "
    "Keep your response concise and structured using Markdown."
)

payload = {
    "model": MODEL_NAME,
    "prompt": f"{system_prompt}\n\nHere is the code diff:\n{code_diff}",
    "stream": False
}

response = requests.post(OLLAMA_URL, json=payload)
review_text = response.json().get("response", "Failed to generate review.")

with open("review.md", "w") as f:
    f.write(review_text)

Step 3: Configuring the Forgejo Actions Workflow

Now, create a workflow file inside your repository at .forgejo/workflows/ai-codegen-review.yml. This YAML file defines when the review executes and how it interacts with your local environment.

name: Automated AI Code Review

on:
  pull_request:
    types: [opened, synchronize]

jobs:
  review:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout Code
        uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - name: Generate Git Diff
        run: |
          git diff origin/${{ gitea.base_ref }}...origin/${{ gitea.head_ref }} > changes.diff

      - name: Set up Python
        uses: actions/setup-python@v5
        with:
          python-version: '3.x'

      - name: Install Dependencies
        run: pip install requests

      - name: Run AI Reviewer
        env:
          OLLAMA_HOST: "http://your-local-ai-server-ip:11434"
          LLM_MODEL: "qwen2.5-coder:7b"
        run: python ai_reviewer.py

      - name: Post Comment to Pull Request
        uses: mshick/fast-gitea-comment@v1
        with:
          token: ${{ secrets.FORGEJO_TOKEN }}
          file: review.md
          comment-number: ${{ gitea.event.pull_request.number }}

Note: Ensure you create a Custom Token in Forgejo with read/write access to Pull Requests and add it to your repository's secrets as FORGEJO_TOKEN.

Best Practices for Refining Your AI Reviewer

To maximize the utility of your automated reviewer and prevent "alert fatigue" among developers, consider implementing the following optimizations:

  • Prompt Engineering: Explicitly instruct the LLM to skip minor formatting issues (like trailing whitespaces or minor indentation) if you already have a linter running in an earlier pipeline stage. Focus the prompt strictly on logic, security, and architecture.
  • Incremental Context: If a PR is large, sending the entire diff might overwhelm the LLM's context window. Break down the diff file-by-file or function-by-function to get precise inline comments.
  • Model Quantization: Use quantized models (e.g., Q4_K_M formats) to reduce VRAM consumption on your local servers without experiencing noticeable degradation in review quality.

Conclusion

By leveraging Forgejo Actions and local LLMs, you build an autonomous, completely private, and highly cost-efficient AI Code Reviewer. This setup does not replace human ingenuity; instead, it empowers your senior engineers by filtering out apparent errors, logical gaps, and basic security oversights before a human ever opens the PR. Embracing this local AI DevOps paradigm ensures your development lifecycle remains incredibly agile, secure, and prepared for future innovations.

Automating Code Quality: Building a Local LLM-Powered AI Code Reviewer for Forgejo Actions | DPTCloud