Built Diff Sentry to add an automated safety layer — it scans every PR diff and posts a risk report comment flagging HIGH/MEDIUM/LOW risk files before anyone merges.
Categories it catches: auth & session logic, secrets/env vars, DB migrations, infra configs, API changes.
Setup is two lines in your GitHub Actions workflow. One-time $19, no subscription.
Happy to answer questions about how the risk analysis works.