Gemma DevPulseA local-first, self-hostable VS Code extension and Git pre-commit guard. Welcome and syncOverview shows your branch status and a short summary of commits since the last visit, including authors and changed files. The first visit establishes a baseline. Only bounded, redacted commit metadata goes to Gemma; commit counts remain available when the server is unavailable. Reload the same Development Host to test revisits. Git Pull & Sync uses fast-forward only and refreshes the summary and reminders.
Save your edited files and commit or stash local changes first. Diverged branches
need manual reconciliation. Check the configured server and model with
Saved context and pull remindersDevPulse saves editing context after about two seconds of inactivity. Reopening the workspace shows a brief Where You Left Off banner; Resume editing opens the saved file and line. Gemma can summarize the context, with a file/line fallback when unavailable. To test in a Development Host, use Developer: Reload Window: each new F5 launch uses a fresh profile with separate saved state. If the branch is behind its upstream, Attention and the status bar explain that a pull is needed. Checks run every minute, on window focus and after Git ref changes. The reminder clears after catching up; diverged branches and failed fetches receive distinct messages. Pulling remains an explicit user action. Attention also reports requested PR reviews, a missing DevPulse hook, and work
that has remained uncommitted for a day. Change the threshold with
Editor highlights and suggestionsRun DevPulse: Analyze File on a saved file. Yellow, red and blue gutters mark logic, security and context findings. Hover for the explanation, or open the Code tab. Apply Suggestion appears when Gemma provides a precise code replacement; the command palette also lets you choose one. Review the redacted diff and confirm before applying. The edit supports Undo and stays unsaved and unstaged. Changing the file clears its findings; changed files and branches are checked again after confirmation. Save and re-analyze to get current suggestions. Instruction-only suggestions and selection reviews remain read-only. Use the Security view's Fix action for hardcoded credentials. Gemma requests have a 30-second timeout. A reachable server can still be too busy to finish analysis; Git status and regex secret verification keep working. AI connection diagnosticsUse DevPulse: Check AI Connection or the Check Connection button in the panel's Overview tab to test server reachability, response latency, and installed model catalog. Diagnostics report whether your configured review/chat and inline autocomplete models are present on the endpoint without sending code, exposing passwords, or revealing full private URLs. Pre-commit secret verificationOpen your Git repository in the Extension Development Host (F5), then open DevPulse in the Activity Bar. Choose Install pre-commit hook once. You can also run DevPulse: Install Pre-Commit Hook from the Command Palette. Stage your changes and commit normally. The guard scans only added staged lines for possible API credentials, AWS keys, JWT secrets, password-bearing database URLs, private-key headers and pasted environment values. A finding blocks the commit and appears in the Security view and editor diagnostics. Existing hooks are backed up and chained. Reinstalling the guard is safe. Click Fix for supported standalone JavaScript/TypeScript literal assignments.
Review the redacted preview and choose Apply fix. DevPulse replaces the literal
with Partially staged or unsaved files, tracked For optional AI checks, run DevPulse: Install Pre-Commit Hook with AI Review,
or install with Use DevPulse: Disable AI Pre-Commit Review to return to regex-only checks.
Standalone use, after building:
Run these commands from the repository to protect. CLI fixes require confirmation
through DevelopmentGenerated using the official
Open this folder in VS Code and press F5. In the Extension Development Host,
open DevPulse in the Activity Bar for code review and security verification.
The watch task includes its own esbuild problem matcher. Extension security
tests use a disposable repository in Run Extension builds and opens a fresh Development Host window without an
attached debugger. This avoids the Windows Extension Host crash in VS Code's
injected debug launcher. Installed extensions are disabled in that development
window. The launch task finishes while the window stays open; close the window
when finished. Each launch uses a separate profile under F5, Ctrl+Shift+B and Open the inner Run
Code reviewUse the ⚙ Settings button in the panel header or DevPulse: Open Settings to edit the host address, review/chat model, autocomplete model and enablement, JSON mode, Focus threshold, Flow Shield and reminder timing in VS Code's native settings editor. Choose User or Workspace scope where the setting supports it. New to local models? Run DevPulse: Set Up Ollama & Models, or use the guide links in the host/model settings. The setup guide covers installing Ollama, downloading Gemma E2B/E4B or another model, and enabling autocomplete with a separate model. Environment and Reviewed lines also appear directly in the editor: red security gutters, yellow warnings and blue architectural context, with matching line highlights. Hover a finding for its explanation and, when the model supplies validated flow data, a Markdown diagram of variable flow, calls or execution branches. Click Inspect step to jump to its line. Recent file commits show real Git authors and commit metadata; history is cached for one minute and requires no AI call. Edits clear stale highlights and disable old step links. The Code tab retains the complete review descriptions. In DevPulse settings, toggle Analysis: Highlights, Code Lens, Hovers, Diagrams, and History independently. Diagrams use native Markdown; no Mermaid extension is required. Flow diagrams are AI analysis, not execution traces, and are omitted when the review has no flow data. Copy Use Press F5, open the Git repository you want to review in the Development Host, and choose DevPulse: Review My Changes. The DevPulse activity-bar view shows upstream ahead/behind counts and per-file review summaries. Its Code tab lists findings; click a finding to navigate, or hover the colored editor gutters. DevPulse: Analyze File and DevPulse: Review Selection review editor text, including unsaved edits. Suggestions are displayed for manual use. Each review fetches the current branch's remote before comparing with its upstream. Fetch failure falls back to clearly marked last-fetched counts. Detached branches and branches without an upstream can still be reviewed. Review does not pull, push, or edit files automatically. Local-change review covers the net saved working-tree changes against HEAD (including staged edits) and untracked files. Staged edits subsequently undone in the working tree are therefore not reviewed separately. Unsaved files are skipped until saved. Private environment/key files, binary files, generated lockfiles, and deleted files are skipped and reported. Limits: 20 files, 1 MB per source file, 24,000 characters per request and 32 parts per file. Large inputs are redacted first, then split into numbered parts with a little boundary context. Progress shows the current part. There is no aggregate 80,000-character cutoff; results are merged and duplicate findings removed. Only changed lines or deletion anchors receive diff findings. Detected secrets are redacted before requests. Calls are serialized, cached for five minutes, and time out after 30 seconds each. Review can be cancelled. If Gemma is unavailable, branch information remains visible. Results are cleared when an open document changes. Review suggestions are for manual use; the Security view separately offers confirmed fixes for supported credentials. Run
These checks use isolated profiles and temporary repositories. They do not modify your installed extensions. Live GitHub/Gemma acceptance still needs a signed-in account, an open PR requesting review, and your configured model server. Pull request reviewsOpen a repository with a github.com HTTPS or SSH remote. In DevPulse's Overview tab, choose Connect GitHub and use VS Code's GitHub sign-in. Refresh PRs lists open PRs requesting your review in that repository (including team review requests). Choose Review with Gemma on a PR to see per-file summaries, severity-based risk and findings. Configure Gemma as described under Code review. You can also run DevPulse: Connect GitHub or DevPulse: Refresh Requested PRs. Requested PRs refresh automatically every five minutes and on window focus using an existing login. Focus checks are throttled and failed requests back off for up to thirty minutes. Background refresh preserves the current review where possible and never opens a sign-in prompt. PR review uses the remote diff without checking out the branch or changing local files. Finding links open the reviewed head revision on GitHub, so they do not point at unrelated local code. No comments or reviews are posted to GitHub. Reviews are cancellable; local code review and security remain available when GitHub or Gemma is unavailable. Results are cached in memory for up to 20 PR revisions, keyed by repository, PR number, head/base SHAs and model configuration. Changed revisions are reviewed again. Private/generated files, binaries, deletions and oversized files are reported as skipped; partial reviews never imply the entire PR is safe. Limits are 20 reviewable files, 24,000 characters per file, 80,000 total and 4 MB for the GitHub response. PRs changing during analysis require another review. GitHub Enterprise and remotes containing embedded credentials are not supported. Use an ordinary github.com remote and VS Code authentication. The review list is limited to GitHub Search's first 1,000 results and reports incomplete results. Run npm run test:pr for an Extension Development Host fixture test of sign-in states, requested PR loading, review results, cancellation and safe panel rendering. It uses injected GitHub/model fixtures; live GitHub/Gemma verification requires your account and a PR requesting your review. Inline autocompleteConnection diagnosticsOpen Overview → AI Connection → Check connection, or run DevPulse: Check AI Connection. It checks whether your configured review/chat and autocomplete models appear in the server's catalog and reports a fresh request's response time. No source code is sent, and the panel never displays the endpoint or token. Checks can be cancelled; settings changes invalidate the result. Model availability does not guarantee successful or fast generation. Reload the Development Host, then run DevPulse: Toggle Inline Autocomplete to opt in. Suggestions appear as ghost text; press Tab to accept or Escape to dismiss. Only workspace files are eligible; environment/key files are excluded. DevPulse sends up to 1,500 characters before and 500 after the cursor, with secrets redacted before slicing. Edits, cancellation and superseding requests discard stale suggestions. Requests share the LLM queue and stop after eight seconds. Slow requests report a brief status-bar timeout and a sanitized message in the DevPulse Output channel; cancelled requests remain quiet. Set To pick models without editing JSON, reload the Development Host and open the Command Palette (Ctrl+Shift+P):
Selecting a model does not enable autocomplete: run DevPulse: Toggle Inline Autocomplete to opt in, then type a function signature in a saved workspace file. Commit description and analysisStage the intended change, then run DevPulse: Generate Commit Description & Analysis from the Command Palette. Gemma drafts a conventional commit title, description and analysis in an editable, unsaved text document. Copy the message into Source Control after reviewing it. The command does not stage files, commit, or run tests; its analysis is a suggestion, not verification. Only staged text diffs are sent, with secrets redacted and private/generated and binary files excluded. Exclusions are listed in the draft. Diffs over 24,000 characters require a smaller staged change. If staging changes during generation, the draft is discarded so it cannot describe an old index. It uses your selected review/chat model and remains cancellable. AI response cacheSuccessful structured responses (including commit drafts) and autocomplete results are reused for five minutes in memory. Hits bypass the inference queue; queued duplicates check again before contacting Gemma. The model catalog is cached for one minute. Prompt/context, model, server/authentication configuration and output options distinguish requests, so changed input or configuration triggers fresh work. The shared cache holds at most 64 responses and 2 MiB, evicting the least recently used entries. Nothing is written to disk; restarting clears it. Use DevPulse: Clear AI Response Cache to clear stored responses and the model catalog. Failed requests are not cached, and structured results are validated again on reuse. Live Git status and staged diffs are read again to keep repository state current; streaming chat and the separate PR revision cache retain their existing behavior. |