An AI agent validates them. Agentic validation reviews PRs with as little noise as possible, analyzes CI failures and catches flaky tests, autofixes until the PR is green, then auto-approves and merges based on rules the team sets — with trust built step by step toward fully automated PRs, and agents combined with program analysis beating either alone.
Gitar is Sonar's AI-powered code-change verification agent for reviewing pull requests and automating validation. It produces high-signal code review findings, diagnoses CI failures by separating real breakage from flaky tests and infrastructure noise, de-duplicates failures, and identifies root causes. Under rules defined in plain language and versioned in the repository, Gitar can generate fixes, commit them to the branch, and iterate until CI passes. Teams can specify what it may fix, what it must escalate, what blocks a merge, and whether it can approve and merge changes. It integrates with GitHub, GitLab, Bitbucket, Azure DevOps, and CircleCI. Its analytics dashboards report metrics such as time to merge, review cycles, CI failure patterns, flake rates, and fix rates. Sonar states that Gitar does not retain source code, use customer code to train models, or retain data through its LLM providers.
Sonar is a software code-quality and code-security company whose products provide automated code review and verification from the IDE through CI/CD pipelines. Its platform uses a Guide–Verify–Solve model: teams set coding context and constraints, review code for reliability, security, quality, and compliance through algorithmic and agentic verification, and generate fixes for detected issues and technical debt. It also provides agentic CI verification and background code-maintenance loops intended to validate AI-generated code and improve the operating practices, tooling, and roles used by engineering teams adopting AI agents.
SonarQube is a named software product. The supplied page does not describe SonarQube; it describes Gitar, an AI-powered code review and pull-request automation tool from Sonar.
Searchable transcript of AI Writes More PRs. Who Validates Them? — Ali-Reza Adl-Tabatabai, Sonar — AI Engineer (11:34). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by AI Engineer. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:13 Let's get started. Um, good afternoon everyone. I'm Ali and um, I'm one of the founders of guitar.ai AI and previously the CEO up until about a month ago where we were acquired by Sonar and now we are part of Sonar and you've heard a lot in the past few days about the importance of verification in the age of AI and so today I'm going to focus my talk on code and verifying code.
00:44 So in in almost all software teams there is this centralized validation phase that is basically CI plus code review and as you scale your engineering this plays this phase plays a very critical part especially in an AI world. Uh first it enforces all your quality gates centrally. So these are security compliance code quality gates. It's on the critical path of getting your changes into production.
01:12 So the faster is always the better. But as you scale engineering, this becomes kind of a challenge. As as you have longer running builds and tasks, you have asynchronous team review flows across sides and geographies and things just get slower naturally as you grow. Um, this is also a phase where you end up spending a lot of developer infrastructure dollars.
01:36 So there's a lot of expensive tools here that need to be integrated and scaled up as you um scale your organization and it all runs on very expensive infrastructure. Uh for these reasons it's often times the main focus of your platform organization team or your platform team. Um but any kind of failure in this phase is very expensive. It introduces failures introduce an outer loop that are typically measured in hours and days.
02:09 So failures are expensive. They costly. They really slow down your velocity. Uh you lose developer time and that's compounded by disruptions to your flow state. It's also very expensive to optimize. So you've got a lot of fragmented systems that have been integrated together with bespoke configuration and scripting. and you have a usually headcount restricted, constrained platform organization trying to keep it all up and running for you.
02:39 And trying to address that all with AI is also kind of complex because it requires complex workflow orchestration involving various inter asynchronous interaction, team workflows, integrations across tools and so on. In fact, AI kind of makes the problem even worse. uh you've got a lot of PRs now being generated, more PRs than before uh thanks to AI and bigger PRs uh all of which can have defects and so your costs in your development life cycle are kind of shifting to the right.
03:14 You have a lot more code to review. You can have potential for a lot more failures in production and and so your choices are kind of tough here. either you slow down and ask developers to review every PR very carefully or you rubber stamp PRs and you risk incidents in production. Either way, you've got less happy developers, lower sentiment, and much less productivity than than you'd expect.
03:40 So, what's the answer here? Of course, it's more AI. It's uh an agentic approach to validation which is essentially what we built at guitar um that we're now also shipping uh as part of sonar. And basically what we've got here is an agent that fully automates all the validation steps and as outcomes it delivers for you green PRs that are ready to merge or merge automatically.
04:08 Now how does this work? Well first when you create your PR it reviews your PR and posts issues and inline comments. No surprise there. But our goal has been to really make this experience as noisefree as possible, both in the way we handle the UX as well as posting issues that are real and really matter. You can customize your review with your own rules and you can add your own custom checks and you can trigger your own custom workflow automations.
04:37 And then you can also configure the system to block merging if there are any unresolved code review findings. It also analyzes CI failures and posts a summary of the root causes of those failures. And in particular, it's really good at catching flaky tests. And you can even set up rules that automatically retry flaky tests if you want. That's a very popular feature.
05:01 You can also automatically fix any code review issues or any CI failures. Any kind of uh failures that happen in CI, it can fix it for you as well as address any of the issues that it raises. You can either ask it to specifically fix an issue or more interestingly you can set it up to automatically loop until all the fish issues have been fixed in your PR and you have a green PR ready to merge.
05:26 And finally, you can automatically approve and merge PRs that are green. you can define rules and conditions that control when uh PRs get automatically approved by the agent and merged automatically. So we're seeing actually a very interesting trend in our users. There's a clear trajectory towards fully automated PRs. uh as users use the system and as they build trust in the accuracy of the AI what we see is they work towards full automation first they get reviews and they're happy with they build trust in the accuracy
06:06 of the reviews they see that these reviews are not only accurate but they're raising really important issues so then they give teeth to the agent by allowing it to start blocking the PRs and then they start using the autofix capabilities to automatically turn PRs green and fix all the issues that were raised by code review or any CI failures that come up.
06:29 And then where the real interesting leap is beginning to happen now is users setting up rules that define when the agent automatically approves and merges PRs. So over time as they build trust in the system they unlock more levels of automation and with the additional levels of automation and with the trust they're getting more value out of the system.
06:54 Now because the system processes every single PR using AI it's also able to uncover new types of insights. For example, uh one of the insights that are is very useful to platform teams is a categorization of the top CI failures. Where are you seeing failures in your CI system where your developer is running into failures? Are these flakiness issues that you can that you need to address by improving the reliability of the tests or are there infrastructure issues that you need to address or are there other kinds of
07:28 failures that they're running into? Very very useful for platform teams. We also have another example of what what else we have in terms of AI enabled insights are categorization of PRs. What exactly is happening across your engineering team in terms of the PRs that are being landed? This is extremely useful for leadership teams. For example, what amount of PRs are going to feature development versus fixing issues, chores, refactors, and so on.
07:59 Now under the hood, if you look at the system, there's a number of components that constitute guitar. There are three interesting pieces here. One is the control plane that acts as this orchestration layer for handling PR workflows. And then there's an agent runtime or or harness. We built our own harness here that handles multi- aent execution, context management, memory management, um tool calling, all the integrations, etc.
08:25 And having this having our own agent harness has really allowed us to optimize specifically for the validation use case and it's allowed us to optimize for token cost, precision and coverage of the agent itself. So that allows us to essentially guarantee outcomes at a fixed PR price while giving really good quality results. We also have an NLM proxy that handles the routing across different models as well as things like failover.
09:00 Now that we're part of Sonar, we've been integrating guitar with sonar cube. There's a ton of opportunity here in combining an agentic approach to validation with program analysis. So combining agents with things like u taint analysis, control flow analysis, data flow analysis, software composition analysis. So all the traditional approaches combined with agents.
09:25 We think there's a ton of opportunity here and that together you can get much better precision, much better coverage at a really great price point. So the overall results uh the value that we're seeing in in all of this is much better quality, much better security, especially with AI generated code, faster delivery times through all the automation going from PRs straight to approved and merged PRs, much higher productivity and sentiment by developers.
09:57 So less time spent on actually reviewing code and worrying about what's happening in production with more confidence as well as sentiment because now you much better sentiment now because you have a lot of automation in place and less grunt work. And finally the to the features that we've built for platform teams gives them a lot more leverage to be able to fix issues and to add customizations and see insights in this critical part of the software development life cycle.
10:26 To wrap up, PR validation is really critical, even more so in AI, but AI turns validation into a friction point. And guitar, what we've built, allows you to automate this step, fully automate PR validation, go from created PRs all the way to merge, completely eliminating this friction and helps you keep up with the rate at which you're generating code from AI.
10:51 And finally, the combination of using agents uh doing a gentic validation plus an algorithmic program analysis will give you something that that I think is going to be much better than either alone. If you want to talk more and you want to see more, if you'd like to see a demo, come on and visit us at booth number P7 right down right down the hall there. Thank you.