DevDoctor automatically scans every pull request for infrastructure issues โ and writes the fix for you. No setup. No configuration. No missed mistakes.
Code reviewers focus on logic. DevOps issues slip through. DevDoctor fills that gap automatically.
Install once, forget about it. DevDoctor runs silently in the background on every relevant PR.
One-click install from the GitHub Marketplace. Select which repos to monitor. Takes under 30 seconds. No YAML config, no token setup.
Any PR that modifies a Dockerfile, docker-compose.yml, or Kubernetes manifest automatically triggers a DevDoctor scan.
DevDoctor posts a structured comment with a health score, issue table, severity levels, and AI-generated fix for every problem found.
DevDoctor doesn't just detect problems. It understands context and writes the fix โ like pairing with a senior engineer on every PR.
9 rules covering security, performance, and reliability. Catches hardcoded secrets, root execution, unpinned images, layer bloat, and missing runtime safety nets.
Powered by Gemini 2.5 Flash. Every issue includes a specific, copy-pasteable fix โ not generic advice. Context-aware suggestions that understand your actual file.
Analyzes Dockerfiles and docker-compose together. Catches cross-service issues like unpinned service images, open port bindings, and missing healthchecks.
No YAML files, no tokens, no CLI setup required for teams. Install the GitHub App once and every eligible PR gets scanned automatically. It just works.
No dashboards to check. No tools to run. DevDoctor posts directly to GitHub โ exactly where your team already works.
| Severity | Rule | Issue |
|---|---|---|
| โ Error | HARDCODED_SECRET | API key found in ENV instruction (line 3) |
| โ Warning | NO_USER | Container executes as root |
| โ Warning | NO_DOCKERIGNORE | Sensitive files included in build context |
| โน Info | NO_HEALTHCHECK | Docker cannot detect unhealthy container |
DevDoctor ships weekly. Here's what's live and what's coming next.
9 rules โ secrets, pinned images, USER, HEALTHCHECK, layer optimization, .dockerignore.
Automatic PR scanning with inline comment reports and commit status checks.
Context-aware fix suggestions for every issue. Specific, not generic.
Resource limits, liveness probes, security contexts, namespace enforcement.
Pinned action versions, secret exposure, missing job timeouts, runner security.
Exit with code 1 below score threshold. Shareable HTML report export with --report flag.
Install the GitHub App in 30 seconds. Your next PR gets a full infrastructure health report โ automatically.
Backend engineer building developer tools and AI-powered products.
Currently working at TCS. Previously at DailyPe (YC W23). I build things that solve real developer problems โ DevDoctor is one of them.