David
ProPro · Backend engineer
Caught a race condition before merge
It flagged a subtle async bug on a PR I was about to approve—the kind of thing we used to find in staging. Happy we have it on every pull request now.
NewContainer scan is live — CVEs in Docker images on Dockerfile PRs
Learn moreAI review + security · one platform
Parallel agents review your diff, scan dependencies, and hunt secrets—then post one native PR/MR review on GitHub or GitLab. Risk scores, inline threads, and @mergeguards fix. No extra CI YAML or second AI subscription.
564
Files reviewed
,2,226
Bugs reported
96
Bugs fixed
How container scan works
Image builds are slow—your team shouldn't wait. Main review posts immediately; container CVEs arrive when the scan finishes.
Comment 2 · when ready
Container scan follow-up
Image CVEs grouped Critical → Info when a Dockerfile changed.
Sample review
Real review shape: risk score, severities, and inline findings—before you install anything.

MergeGuard summary
Risk score 35 / 100
Medium merge risk. Auth middleware change touches request path—verify session handling on edge cases.
Reply @mergeguards fix on an inline thread to push a patch commit.
One roof · parallel agents
Many teams bolt on different models and vendors for review, security, and dependencies—each with its own bill. MergeGuard runs specialized agents in parallel, merges the signal, and posts one native review with the strongest scans on every pull request.
Parallel agents
Merge risk
48
/ 100 · ~2 min review
mergeguard
bot · just now
Potential issue — missing null check before decode() on the authorization header.
Reply @mergeguards fix for an auto-commit
3 signals · 1 comment
lodash@4.17.20 · CVE-2021-23337
AWS key pattern in .env.example
Missing null guard before decode()
Also available natively onGitHub&
GitLab
Why teams use MergeGuard
We do the heavy lifting on the diff—you do the final 10%.
Reply @mergeguards fix on inline findings—MergeGuard generates the patch and commits to your branch.
Security scanning · now built in
Open-source security scanners are built into your AI code review—no separate tool to install. OSV dependency CVEs, Trivy filesystem scans, and async container image scanning on Dockerfile PRs are live on Pro+.
Scanning 6 targets in the diff
Findings
0
CVEs
0
Secrets
0
Misconfig
0
Code
Merge risk
merging findings…
Dependency CVEs from your npm lockfiles, on every pull request.
Filesystem vulns, leaked secrets, and IaC misconfig in the same review.
Docker image CVE scans when a PR changes a Dockerfile—queued in the background so reviews never wait on image build.
How it works
One pipeline from push to protected merge—AI review, security scans, and PR commands inline on your diff. Install once; no separate dashboard.
Sign in required
Leave GitHub to view findings in an external dashboard.
Context lost · extra clicks · slower merges
PR commands
After the review lands, reply with commands—no context switch to another tool.
@mergeguards fixAll plansReply on an inline finding to generate a patch and commit it to the PR.
@mergeguard-followupPaidRe-run AI review on the current PR after new commits or discussion.
@mergeguards deep-scanPaidDeeper pass for security and architectural risk—ideal before merging large changes.
Powered by
Customer stories
David
ProPro · Backend engineer
Caught a race condition before merge
It flagged a subtle async bug on a PR I was about to approve—the kind of thing we used to find in staging. Happy we have it on every pull request now.
Self-serve setup
No scheduled demo—we walk you through install with short videos and docs. Most teams are live on their first pull request the same day.
Connect GitHub or GitLab
Sign in with the provider that owns your repos—no MergeGuard password.
Connect account →Prefer GitLab? GitLab walkthrough
Free tier · 20 reviews/month
Install the GitHub App or connect GitLab—review and scans on every PR or MR.
See pricing · Product demos · FAQ · Security
Comment 1 · right away
Main PR review
Risk score, AI findings, dependency CVEs, and filesystem security.