GitLab-backed analysis

Adservio Code Review Analysis

A read-only analysis of recent merge request review behavior in GitLab, focused on visible review discussion, reviewer distribution, queue health, MR size, and traceability gaps.

Period: 2026-08-15 07:00 to 2026-08-22 07:00
Primary source: GitLab merge request metadata, notes, labels, commits, and approvals endpoints.

Bottom line: review throughput is not the main risk here; traceability and queue hygiene are. The team is still merging code, but most merges leave no durable visible review trail and the open queue is overwhelmingly stale.

What Matters

  • Traceability is the clearest control gap: 36 of 40 merged MRs (90.0%) showed no visible non-author review comment in GitLab.
  • Queue health is poor: 84.5% of active open MRs are already older than 48 working hours. The oldest example is adservio/web!2091 at 292.6d open.
  • Visible review capacity is thin and concentrated: only 6 visible review touches were detected in the whole window, and the top 3 reviewers handled 50.0% of them.
  • adservio/helm2 is the highest-volume review surface with 14 merged MRs and only 0.0% visible review coverage. adservio/web is the next meaningful flow at 7 merges and 14.3% visible review coverage.
  • MR size is not the main story: median changed files were 4.0, and only 15.0% of merged MRs were above 20 files. Even the slowest merged example, adservio/frontend!2041, took 16.0d with 115 changed files, so the dominant problem still looks like review discipline and queue ownership rather than consistently oversized MRs.

Leadership Analysis

  • The operating rhythm is serviceable at the median (24.8h created-to-merged), which means the biggest leverage is improving process fidelity rather than pushing for even more raw throughput.
  • With 84.5% of active MRs already stale, the open list is functioning more like inventory than prioritization support. adservio/web!2091 being open for 292.6d is a strong sign that ownership and review handoffs are not being actively reset.
  • The spread between a 4.0-file median MR and a 16.0d longest merged cycle (adservio/frontend!2041, 115 changed files) suggests a few ownership-heavy exceptions are dragging on outside normal flow. Those should be managed as explicit escalations, not left to age inside the common queue.

Recommended Actions

  • Make one durable review artifact mandatory before merge: a substantive non-author GitLab review comment, a recorded approval, or both. A label alone should no longer count as sufficient evidence. The approval API coverage is also low, so the fix should include tooling or policy that leaves an auditable trace by default.
  • Run a stale-MR reset on anything older than 48 working hours: close abandoned work, re-confirm owner and reviewer on the rest, and turn the open list back into a real queue instead of a parking lot. Start with adservio/web!2091 and the rest of the oldest backlog because their age now obscures whether they are still real priorities.
  • Put adservio/helm2 under explicit review guardrails for the next cycle. It combines enough volume with weak visible review coverage, which makes it the best place to tighten the process and see impact quickly.
  • Broaden the reviewer bench beyond Dragoș Ivan and the current small reviewer set. The present concentration is a continuity risk and will keep queue health fragile when one person is away.

Improvement Ideas

  • Set explicit operating standards for the next quarter: require one auditable peer-review artifact before merge, target first review inside one working day for active MRs, and keep the stale active backlog below 15%. What gets measured this clearly is far more likely to improve.
  • Run a four-week process experiment on adservio/helm2: dedicated reviewer-of-the-week coverage, explicit reviewer assignment at MR creation, and a lightweight weekly audit of silent merges. It is the highest-yield place to test whether better ownership changes the data.

Supporting Evidence

  • 36 of 40 merged MRs (90.0%) had no visible non-author review comment in GitLab.
  • 11 of 40 merged MRs (27.5%) carried the `CR - Approved` label.
  • 7 merged MRs (17.5%) were labeled `CR - Approved` without any visible non-author review comment.
  • 15.0% of merged MRs changed more than 20 files, while 7.5% changed more than 50 files.
  • Among MRs with visible review discussion, the median last-author-commit to first-review time was 25.0h.
  • The median last-author-commit to `CR - Approved` time was 46.2h.
  • The top 3 reviewers accounted for 50.0% of visible review touches.
  • 49 of 58 active open MRs (84.5%) were older than 48 working hours.
Merged MRs
Merged MRs inside the analysis window.
40
Open MRs
All currently open group MRs.
73
Active open MRs
Open MRs excluding drafts.
58
Draft open MRs
Open MRs marked draft/WIP.
15
Visible review rate
Merged MRs with at least one visible non-author GitLab comment.
10.0%
Merged without visible review comment
Merged MRs with zero visible non-author comments.
90.0%
CR - Approved label coverage
Merged MRs carrying the CR-approved label.
27.5%
Approval API coverage
Merged MRs with at least one approver in the GitLab approvals API.
20.0%
CR - Approved without visible review comment
CR-approved MRs with no visible non-author comment.
17.5%
Median MR created -> first review
Working time from MR creation to first visible non-author comment.
4.1d
Median last author commit -> first review
Working time from last author commit before review to first visible non-author comment.
25.0h
Median first review -> CR - Approved
Working time from first visible comment to CR-approved label after review start, else merge.
21.1h
Median MR created -> CR - Approved
Working time from MR creation to CR-approved label after review start, else merge.
8.1d
Median last author commit -> CR - Approved
Working time from last author commit before review to CR-approved label after review start, else merge.
46.2h
Median MR created -> merged
Working time from MR creation to merge.
24.8h
Median changed files
Median GitLab `changes_count` value.
4.0
MRs > 5 files
Merged MRs where `changes_count` is above 5.
37.5%
MRs > 10 files
Merged MRs where `changes_count` is above 10.
22.5%
MRs > 20 files
Merged MRs where `changes_count` is above 20.
15.0%
MRs > 50 files
Merged MRs where `changes_count` is above 50.
7.5%
Top 3 reviewer touch share
Share of visible review touches handled by the top 3 reviewers.
50.0%
Active open backlog rate
Non-draft open MRs older than 48 working hours.
84.5%

These headline timing medians bring back the anchor-to-anchor numbers directly, using working time with weekends excluded.

Median MR created -> first review4.1d
Median last author commit -> first review25.0h
Median MR created -> CR - Approved8.1d
Median first review -> CR - Approved21.1h
Median last author commit -> CR - Approved46.2h
Median MR created -> merged24.8h
Dragoș Ivan1116.7%
Alex Murarescu1216.7%
Marian Andrei1216.7%
Andrei Alexandru1116.7%
Valentin Pal1116.7%
Achim Stefan1216.7%
adservio/helm2140.0%0.0%3.5
adservio/web714.3%57.1%4
adservio/frontend540.0%80.0%8
adservio/devops/iac40.0%0.0%4.5
adservio/ai/backend30.0%0.0%5
adservio/billing/backend250.0%100.0%5.5
adservio/uni/backend20.0%50.0%8.0
adservio/services/mcp10.0%0.0%59
adservio/services/websocket10.0%0.0%1
adservio/social10.0%0.0%1

Visible Review Discussion MRs

Compact by default: key CR metrics stay visible, and each row expands inline for the full audit trail. The table starts sorted by Last Commit -> First Review.

Details
adservio/web!2662[S: ADS-6142][ADS-8250] [Registre Matricole] [BE-PHP] - Creare volume si asociere studenti incadrati5/5 Deep2.0d3.1h11.1d
adservio/frontend!2074[ADS-8428 ] - penalties management bugfixes3/5 Solid5.0d17.5h5.1d
adservio/frontend!2041[ADS-6142][Registre Matricole] - US1.1 Creare volume si asociere studenti incadrati4/5 Strong14.3d32.6h15.9d
adservio/billing/backend!269[fix-penalties-test] Stabilize penalty fixtures2/5 Light3.3d3.3d20.8h

No Visible Review Comment Audit

These merged MRs had no visible non-author GitLab comment under the current heuristic. Use this section to audit whether the gap is a real review-process issue or a GitLab traceability issue.

Total MRs36
With CR Label7
With Approval API7
  • Open the MR link and check the Overview tab for CR - Approved and any approval widget signal.
  • Check Activity / Discussions for real human reviewer comments.
  • If you only see system notes, merge notes, mentions, or bot activity, it stays in this audit set.
  • If you find a genuine reviewer comment from someone other than the author, treat that MR as a false positive of this heuristic.
full audit table (36 MRs). Click again to collapse.
adservio/helm2!346adservio/helm2ads-8504 add APP_KEY sealed secret for laravel encryptionRojan Shrestha2026-08-17
adservio/web!2698adservio/web[HOTFIX] sync new studentIonut Ciolan2026-08-17
adservio/helm2!341adservio/helm2ADS-8480 Use DNS-safe MR environment slugsValentin Pal2026-08-17
adservio/helm2!335adservio/helm2ads-8434 raise prod tempo max_bytes_per_trace 5MiB to 25MiB to stop dropping large tracesRojan Shrestha2026-08-17Yes
adservio/helm2!332adservio/helm2ads-8287 web prod rollout surge-only (maxUnavailable 0, maxSurge 25%) to eliminate capacity dipRojan Shrestha2026-08-17
adservio/frontend!2079adservio/frontend[ADS-8515] Preferinte notificari dividerPetronel Pavel2026-08-17Yes
adservio/helm2!347adservio/helm2Ads 8515Daniel Onisoru2026-08-17
adservio/web!2671adservio/web[ADS-6142] Add Academic Registry PHPUnit gateValentin Pal2026-08-17
adservio/uni/backend!235adservio/uni/backend[S: ADS-6142][ADS-8221] Registru MatricolAndrei Alexandru2026-08-17YesYes
adservio/services/websocket!10adservio/services/websocket[ADS-8480] Authenticate Groups chat socket via session cookieDaniel Onisoru2026-08-17
adservio/frontend!2082adservio/frontend[ADS-8480] Authenticate Groups chat socket via session cookieDaniel Onisoru2026-08-17
adservio/helm2!348adservio/helm2ads-8484 add certificate expiry alerting for prod and tuiasiRojan Shrestha2026-08-18
adservio/helm2!340adservio/helm2helm-core: overrides-apps for the eks-apps clusterDaniel Onisoru2026-08-18
adservio/helm2!351adservio/helm2fix: render oauth-tuiasi as a managed sealed secretDaniel Onisoru2026-08-18
adservio/helm2!352adservio/helm2refactor: split google-credentials, move oauth-tuiasi to the umbrella chartDaniel Onisoru2026-08-18
adservio/helm2!353adservio/helm2Upgrade the deployer: node 24, oclif 4, kubectl 1.33, helm 3.21 — with a test suiteDaniel Onisoru2026-08-18
adservio/devops/iac!71adservio/devops/iacADS-8526: manage gabriel.ichim SSO user in terraformRojan Shrestha2026-08-19Yes
adservio/helm2!355adservio/helm2ci: pilot cypress failure screenshots + video on test_frontend shard 4/4Rojan Shrestha2026-08-19
adservio/devops/iac!66adservio/devops/iacbootstrap apps account backend and scaffold eks environmentRojan Shrestha2026-08-20
adservio/devops/iac!70adservio/devops/iacBootstrap romatsa ec2Daniel Onisoru2026-08-20
adservio/web!2701adservio/web[ADS-8511] ordinea claselor la adaugarePetronel Pavel2026-08-20Yes
adservio/services/mcp!3adservio/services/mcpS:[ADS-8339] [ADS-8492][BE] Add support for warnings and observationsAlex Murarescu2026-08-20
adservio/helm2!359adservio/helm2staging billing migrationsAlex Murarescu2026-08-20
adservio/social!39adservio/socialallow hidden organizationsAlex Murarescu2026-08-20
adservio/ai/backend!73adservio/ai/backend[ADS-8497] [BE] - Integrate the AI service with the MCP serverAlex Murarescu2026-08-20
adservio/web!2704adservio/web[S: ADS-6142][ADS-8250] [Registre Matricole] [BE-PHP] - Creare volume si...Catalin Cojan2026-08-20YesYes
adservio/helm2!356adservio/helm2[ADS-8497][BE] Integrate the AI service with the MCP serverAlex Murarescu2026-08-20
adservio/frontend!2086adservio/frontend[S: ADS-6142][ADS-8250] [Registre Matricole] - Creare volume si asociere studenti incadratiAchim Stefan2026-08-20YesYes
adservio/billing/backend!270adservio/billing/backend[ADS-8428 ] - penalties management bugfixesGeorge Murgoci2026-08-20YesYes
adservio/web!2700adservio/web[S: ADS-8499] Sync coduri SirutaCatalin Cojan2026-08-20Yes
adservio/helm2!360adservio/helm2[ADS-8482] [BE] Replace audit interceptor for the AI projectAlex Murarescu2026-08-20
adservio/ai/backend!74adservio/ai/backend[ADS-8482] [BE] Replace audit interceptor for the AI projectAlex Murarescu2026-08-20
adservio/web!2705adservio/web[ADS-8511] fix ads-7907 revert regressionsPetronel Pavel2026-08-20
adservio/ai/backend!75adservio/ai/backendFix migrationsAlex Murarescu2026-08-20
adservio/devops/iac!73adservio/devops/iacstaging: upgrade both mysql instances to 8.4.11Rojan Shrestha2026-08-20
adservio/uni/backend!246adservio/uni/backend[ADS-8495] Import Note discipline DOP, DFAndrei Alexandru2026-08-21Yes

Oldest Active Open MRs (> 48 Working Hours)

adservio/web!2091adservio/webAndrei Dragan292.6d5
adservio/helm2!137adservio/helm2Raul Popovici268.7d0
adservio/services/websocket!8adservio/services/websocketRaul Popovici265.7d0
adservio/services/videothumb!5adservio/services/videothumbRaul Popovici265.6d0
adservio/services/fet-generator!9adservio/services/fet-generatorRaul Popovici265.6d0
adservio/frontend!1556adservio/frontendGeorge Murgoci157.4d0
adservio/web!2344adservio/webGeorge Murgoci156.5d0
adservio/library/backend!26adservio/library/backendRaul Popovici136.5d0
adservio/subscriptions/backend!103adservio/subscriptions/backendEdgar Alexa134.6d4
adservio/admission/backend!104adservio/admission/backendEdgar Alexa134.4d0
adservio/frontend!2041adservio/frontendAchim Stefan16.0d1153
adservio/uni/backend!235adservio/uni/backendAndrei Alexandru15.1d140
adservio/web!2662adservio/webCatalin Cojan14.0d603
adservio/helm2!332adservio/helm2Rojan Shrestha14.0d10
adservio/web!2671adservio/webValentin Pal11.2d30
adservio/devops/iac!66adservio/devops/iacRojan Shrestha9.8d340
adservio/helm2!335adservio/helm2Rojan Shrestha7.2d10
adservio/billing/backend!269adservio/billing/backendEdgar Alexa5.9d11
adservio/frontend!2074adservio/frontendGeorge Murgoci5.2d112
adservio/billing/backend!270adservio/billing/backendGeorge Murgoci5.2d100

Methodology And Limits

  • This report uses visible non-author GitLab comments as the strongest review-start proxy.
  • GitLab approval API coverage is shown separately; missing approval API data should be read as traceability gap, not proof that no approval happened.
  • Review completion uses the first `CR - Approved` label-add event after review starts when GitLab label history provides one; otherwise it falls back to merge time.
  • Last-author-commit metrics use the latest non-merge MR commit authored by the MR author strictly before review starts.
  • Timing metrics in this report exclude Saturday and Sunday hours using the Europe/Bucharest calendar.
  • Review-quality scoring is heuristic: it rewards visible substantive comments, multiple reviewers, and post-review pushes, and it penalizes large MRs with shallow visible discussion.
  • `Active open backlog rate` excludes draft MRs and uses a > 48 working-hour age threshold.
  • Open MR backlog age is a queue-health signal, not proof that every old open MR is actively waiting for review right now.