docs(#233): add PatchPatrol to landscape analysis - #7117
Conversation
Add PatchPatrol as a landscape entry under Major tools. PatchPatrol is an MIT-licensed, AI-powered commit review system that integrates with pre-commit hooks, offering local (ONNX, llama.cpp) and cloud (Gemini) inference backends with separate code quality and security modes. The entry covers its architecture (backend plurality, model registry), two review modes (OWASP-based security and code quality), integration model (pre-commit hooks, not PR-level), and enterprise deployment on OpenShift. The Relevance to fullsend subsection positions PatchPatrol as a shift-left review reference that validates pre-PR review value but does not address review decomposition, trust boundaries, or merge authority. Note: pre-commit hooks were not run. pre-commit could not complete (infrastructure failure). Hooks were run directly: trailing-whitespace, end-of-file-fixer, detect-private-key, lint-docs-links, and lychee (lint-md-links) all passed. Closes #233
|
🤖 Finished Review · ✅ Success · Started 8:02 PM UTC · Completed 8:16 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.20 |
Site previewPreview: https://e6b7c6ca-site.fullsend-ai.workers.dev Commit: |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
Risk Assessment: low (1/5) DetailsTier 1 signals are identical to the prior assessment (1-file, 1-line docs addition by a bot author, no protected paths, no security or dependency signals, docs-only test ratio treated as neutral), Tier 2 confirms expected active-catalogue maintenance churn rather than instability, and Tier 3 scope is appropriately narrow for a landscape registration step; composite of ~1.3 rounds to 1, preserving the prior score. Previous runRisk Assessment: low (1/5) DetailsDocs-only single-line landscape addition by a bot author with no protected paths, security signals, dependency changes, or scope mismatch; Tier 1 signals are identical to the prior assessment and Tier 2 catalogue churn is expected active-maintenance activity rather than instability, yielding a composite of 1.3 which rounds to 1. Previous run (2)Risk Assessment: low (1/5) DetailsDocs-only, single-file landscape addition by a bot author with no protected paths, security signals, or dependency changes; Tier 1 signals unchanged from prior assessment and Tier 2 churn reflects normal active-catalogue maintenance rather than instability risk. Previous run (3)Risk Assessment: low (1/5) DetailsDocs-only, single-file landscape addition by a bot author with no protected paths, security signals, or dependency changes; fully aligned with a low-priority research issue. |
ReviewFindingsLow
Previous runReviewFindingsMedium
Low
Next steps:
Previous run (2)ReviewFindingsLow
Next steps:
Previous run (3)ReviewFindingsMedium
Low
Labels: PR modifies documentation in the landscape analysis file Next steps:
|
|
🤖 Finished Fix · ✅ Success · Started 8:18 PM UTC · Completed 8:25 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.69 |
PatchPatrol lacks the adoption metrics, funding, or major platform affiliation that characterize other Major tools entries (CodeRabbit, Greptile, Graphite, OpenClaw). Move it to the Others bullet list with a condensed description that preserves the key relevance points (shift-left review, local inference, no merge authority). Note: pre-commit hooks were not run. `pre-commit` could not complete (infrastructure failure); hooks were run directly instead (trailing- whitespace, end-of-file-fixer, lint-docs-links, lychee lint-md-links all passed). Addresses #7117
🔧 Fix agent — iteration 1 (bot-triggered)Moved PatchPatrol from Major tools to Others section (finding 1). Disagreed with finding 2 because it concerns the PR body text, which is outside the scope of code fixes, and the reviewer acknowledged the omission is defensible. Fixed (1):
Disagreed (1):
Tests: passed Decision points
Next steps:
|
|
🤖 Finished Review · ✅ Success · Started 8:27 PM UTC · Completed 8:40 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.27 |
|
🤖 Finished Fix · ✅ Success · Started 8:42 PM UTC · Completed 8:48 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.10 |
Rephrase the PatchPatrol landscape entry to accurately describe the relationship to ADR 0017. The previous text implied ADR 0017 discusses data sovereignty, but ADR 0017 addresses credential isolation for sandboxed agents. The connection is indirect: local inference eliminates cloud LLM API credentials, reducing credential exposure — which is ADR 0017's actual topic. Addresses #7117
🔧 Fix agent — iteration 2 (bot-triggered)Fixed the ADR 0017 cross-reference accuracy issue by rephrasing to correctly describe the credential-exposure relationship instead of implying ADR 0017 discusses data sovereignty. Disagreed with the PR body text finding as it concerns PR metadata, which is outside the fix agent's scope. Fixed (1):
Disagreed (1):
Tests: passed Decision points
Next steps:
|
|
🤖 Finished Review · ✅ Success · Started 8:51 PM UTC · Completed 9:06 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.70 |
|
🤖 Finished Fix · ✅ Success · Started 9:08 PM UTC · Completed 9:14 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.08 |
Rewrite the PatchPatrol landscape entry to address review feedback: remove unsupported "community-driven" claim, remove internal cross-references (code-review.md, ADR 0017) that break section convention, clarify local-vs-cloud inference credential claim, and trim to match peer entry length. Strategy change: rewrote the full entry instead of patching individual phrases, which was not resolving the recurring pattern-consistency and length issues across iterations 1-2. Addresses #7117
🔧 Fix agent — iteration 3 (bot-triggered)Rewrote the PatchPatrol landscape entry to match Others section conventions, addressing all four code findings: removed unsupported 'community-driven' claim, removed internal cross-references, clarified local-vs-cloud credential claim, and trimmed to peer entry length. Disagreed with PR body text finding as it is outside the fix agent's scope. Fixed (4):
Disagreed (1):
Tests: passed
Decision points
Next steps:
|
|
🤖 Finished Review · ✅ Success · Started 9:16 PM UTC · Completed 9:30 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.17 |
Superseded by updated review
|
🤖 Finished Retro · ✅ Success · Started 10:17 AM UTC · Completed 10:29 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.96 |
Retro: PR #7117 — Add PatchPatrol to landscape analysisA docs-only, single-line landscape entry went through 3 review-fix iterations before approval, costing ~$21.64 total ($2.55 code, $14.34 review across 4 runs, $3.87 fix across 3 runs, $0.88 triage). The final merged diff was one bullet-point line in Timeline
Root cause analysisIteration 1 was caused by a triage-to-code format mismatch. The triage agent's test case described the Major tools entry format (H3 heading, architecture writeup, "Relevance to fullsend" subsection), but PatchPatrol — a personal-account, community-driven, no-adoption-metrics project — belongs in the Others bullet list (single-line format). The code agent followed the triage guidance and placed it in Major tools. This cost one full review-fix cycle (~$5.89). See proposal below. Iterations 2–3 were caused by incremental finding discovery. After Fix 1 moved the entry to Others, Review 2 found only the ADR cross-reference issue but missed 3 other issues (community-driven claim, internal cross-references, entry length) that were present in the exact same text. Review 3 found all of them. This is the finding-drip pattern described in #1367 — this PR provides additional evidence: 3 findings missed in Review 2 that Review 3 discovered in unchanged text (~$4.80 avoidable cost). The PR-body finding persisted across all 3 iterations — raised by the review agent and correctly disagreed-with by the fix agent each time (PR body text is outside the scope of code fixes). This is evidence for #2816 (cross-iteration finding dedup/dismissal) and #2280 (PR description vs diff discrepancy handling). What went well
Existing issue evidence (not filed as proposals)
Proposals filed
|
Summary
Add PatchPatrol as a landscape entry in
docs/landscape.mdunder Major tools. PatchPatrol is an MIT-licensed, community-driven, AI-powered commit review system that integrates with pre-commit hooks. It offers local (ONNX, llama.cpp) and cloud (Gemini) inference backends with separate code quality and OWASP-based security modes.Related Issue
Closes #233
Changes
### PatchPatrolsubsection under Major tools indocs/landscape.md, placed before the### Othersbullet listTesting
make lintrelevant hooks pass (trailing-whitespace, end-of-file-fixer, detect-private-key, lint-docs-links, lychee lint-md-links)Closes #233
Post-script verification
agent/233-landscape-patchpatrol)4ea5f339a889ee86dd56ddfca931b2c504de98fb..HEAD)