
What happened
A ~260-line Node.js script hashes the current working files into a fingerprint, stores it in .git/review-stamp.json, and compares it in predeploy; mismatch or missing review stops deploy.
Why it matters
"Review before shipping" written as a rule gets skipped on busy days, and a specified model may not be the one that actually ran the two review roles.
WHO IT HITSDevelopers and teams using AI coding assistants like Claude Code and Codex, who want review policies enforced at deploy time, can adopt this pattern to prevent unreviewed code from shipping.
Summaries like this, in your inbox every morning.
The approach centers on a fingerprint of the current working files, created using a temporary Git index. A temporary GIT_INDEX_FILE is read from HEAD, then git add -A and git write-tree produce a tree hash of all unignored files. Because the index is temporary, the normal staging area is untouched. This means a commit after a review won't change the fingerprint, but any uncommitted change will.
The deploy side is hooked into npm's predeploy, which runs automatically before deploy. The check script reads the stamp, recomputes the fingerprint, and exits non-zero if there is no stamp or if the fingerprints differ. The article notes that running wrangler deploy directly is blocked by a separate hook.
If review flags issues, the developer either fixes the code and re-runs review, or records an acknowledgment with a reason. In both cases the fingerprint and reason are stored. The review itself uses $code-review with an OMX setup. Because specifying a model with -m only affects the summarizer while the two roles use their own config files, the script inspects Codex session logs after each review. It confirms both roles ran on the intended model and that the outcome was APPROVE or COMMENT before writing the stamp. Cases like hitting a usage limit, code changing mid-review, or a failed re-review of an unchanged tree are all treated as not reviewed.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Stanford and Carnegie Mellon researchers tracked 1182 Character.AI users from September 2024 to August 2025, t…

A study presented at USENIX Security Symposium 2026 examined 196,682 resumes from hiring platforms and detecte…

Google Cloud announced Gemini Agent, a cloud-based multi-agent tool

Google Cloud announced Gemini agent, a universal agent that handles answers, knowledge work, media creation, a…

The guide shows code that pulls AAPL prices with yfinance, averages tweet sentiment via TextBlob, then fits a…

The open-source ax-engine for Apple Silicon Macs measured over 76 tok/s decode on one M5 Max setup, and about…
