AI Code Reviewer CodeAnt founds Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)CVE-2026-29000

simple-git npm package has a CVSS 9.8 RCE. 5M+ weekly downloads. check your lockfiles.

How risky is prompt injection once AI agents touch real systems?

Is AI Code Reviews something you use?

grep searched my node_modules for 6 minutes before i killed it

my code review bot was scanning files one by one. 90 seconds per PR.

chalk + debug just got owned on npm… and honestly, this is the nightmare I’ve been expecting

I need a second opinion on this folks... who else isusing AI-based code review tools for GitHub PRs?

How are you integrating AI into your code review process?