Local-first. BYOK. Privacy-hardened. Developer-approved.
โก Quick Start โข โ๏ธ Why GitWhisper โข ๐ฅ๏ธ VS Code SCM โข ๐น๏ธ CLI Experience โข ๐๏ธ Architecture
Most AI commit tools dump raw diffs onto cloud servers, leaking API keys and generating inaccurate hallucinations. GitWhisper gives you deterministic git analysis, zero telemetry, and native VS Code integration:
| Feature | ๐ฎ GitWhisper | opencommit | aicommits | Generic Copilot / Chat |
|---|---|---|---|---|
| Local-First AI (Ollama, LM Studio, Llama) | โ Native (100% Offline, $0 cost) | โ OpenAI only | โ Cloud only | |
| Zero Secret Leaks (AST Redaction) | ๐ก๏ธ Automatic key & token sanitization | โ Sends raw diff | โ Sends raw diff | |
| Native VS Code 1-Click SCM Button | โ Direct SCM commit box integration | โ CLI only | โ CLI only | |
| Conventional Commit Determinism | โ Git plumbing parser + AST verification | โ LLM guesswork | โ LLM guesswork | โ Inconsistent |
| Atomic Multi-Hunk Splitting | โ Splits multi-concern staged changes | โ Single commit | โ Single commit | โ Manual staging |
| Instant Style Switching | โ Concise / Descriptive / Detailed (1-key) | โ Single style | โ Single style | |
| Open Source License | โ MIT License (Free Forever) | โ MIT | โ MIT | โ Paid Subscription |
Most AI commit tools do something reckless: they dump your raw Git diffs onto remote servers, leaking .env secrets, private tokens, and unreviewed code. Then they hallucinate non-standard commit messages that make your Git history messy.
GitWhisper is built differently:
- Deterministic Truth First: Inspects real index plumbing (
git diff --cached), file trees, and repository history to determine the conventionaltypeandscopebefore AI is ever called. - Ironclad Privacy Boundary: Built-in AST secret scanner automatically redacts API keys, JWTs, private keys, and passwords before any remote prompt is sent.
- Multiple Intent Variants: Generates Concise, Descriptive, and Detailed variants with 1 click or keypress.
- Atomic Hunk Splitting: Detects multiple distinct concerns in your staged changes and splits them into clean, independent atomic commits.
- Developer Remains in Control: GitWhisper never silently commits without your explicit approval.
# Stage your changes
git add .
# Run GitWhisper
npx gitwhispernpm install -g gitwhisper
# or with pnpm
pnpm add -g gitwhisperThen simply type:
gitwhisperGitWhisper embeds directly into your native VS Code Source Control (SCM) panel!
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ SOURCE CONTROL โจ ๐ โ โ <-- 1-Click Generation & Provenance
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โจโ โ <-- SCM Input Box Action Icon
โ โ feat(auth): refresh session tokens before timeout โ โ <-- Auto-filled Conventional Commit!
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ [ โ Commit ] โ <-- Normal native VS Code commit
โ โ
โ CHANGES โ
โ โ Staged Changes (2) โ
โ M src/auth/session.ts โ
โ M src/auth/token.ts โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Status Bar: $(shield) GitWhisper: Local-Only <-- Live Privacy Indicator
- Inline Sparkle Action: Click the
$(sparkle)button inside the commit message box to generate messages instantly. - Interactive QuickPick: Choose between Concise, Descriptive, or Detailed styles.
- Explain Commit: Inspect classification evidence, confidence levels, and privacy badges without leaving your editor.
- Keyboard Shortcut: Press
Alt+G C(Cmd+Alt+G Con macOS) to generate a commit proposal anywhere.
To test the extension locally:
pnpm run build:vscode
# Press F5 in VS Code to launch the Extension Development Host! GitWhisper v0.9.0 [Local-Only] ollama (qwen2.5-coder:7b) (140ms)
Repo: ritual-api (feature/DEV-142-session-timeout) Staged: 2 files (+48, -12)
Issue: DEV-142 โ Refresh sessions before expiration
Privacy: [LOCAL-ONLY] Zero external data transmission
Variants: [1] Concise [2] Descriptive โ [3] Detailed
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ feat(auth): refresh session tokens before timeout (DEV-142)โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Proactively requests a refreshed access token 5 minutes โ
โ prior to session expiry to prevent sudden user disconnects.โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
[Enter] Commit [1-3] Variant [e] Edit [t] Type [s] Scope
[b] Breaking [r] Regenerate [d] Details [p] Hunk Plan [q] Cancel
- Evaluates configured AI providers before sending any context.
- High-entropy heuristic, known format (AWS, GitHub, Stripe, Slack, OpenAI, PEM private keys), and authorization header scanning.
- Redacted values are substituted with deterministic tokens (
[REDACTED:API_KEY_0]). - Untracked files,
.envfiles, and unstaged modifications are strictly isolated.
- Parses branch names (
feature/DEV-142-refresh-tokens,fix/issue-89) to extract issue keys. - Enriches commit proposals with Jira, GitHub, or Linear work-item context.
- Configurable reference formats:
(DEV-142),[DEV-142], or footerFixes: #142.
- Detects when a developer staged multiple distinct concerns in a single session.
- Automatically groups hunks into coherent sub-plans (
gitwhisper hunks). - Safely applies atomic commits sequentially, preserving unstaged working tree changes.
- CLI Checker: Run
gitwhisper check "feat(auth): refresh tokens"to validate subject length, casing, specificity, and conventional syntax. - Git Hook Integration: Run
gitwhisper hooks install --mode warn(or--mode strict) to guard your repository via.git/hooks/commit-msg. - Non-Destructive Chaining: Never overwrites existing user hooks (e.g. Husky) โ chains cleanly into them.
- Run
gitwhisper timelineto view recent commits automatically clustered into coherent feature workstreams. - Detects revert commits and visually links them to their original target commits.
- Read-only: Never rewrites or rebases Git history.
GitWhisper is built from the ground up to support local-first privacy as well as Bring Your Own Key (BYOK) cloud providers.
By default, GitWhisper communicates with a local Ollama instance running on http://localhost:11434.
- Default Model:
qwen2.5-coder:7b - 100% Offline: No source code, diffs, or secrets leave your machine.
- Zero API Costs: Run unlimited generations for free.
To use Ollama, install Ollama and pull any coding model:
# Pull the recommended default model
ollama pull qwen2.5-coder:7b
# Or pull any other model
ollama pull llama3.2
ollama pull deepseek-coder:6.7bTo tell GitWhisper which local model to use:
gitwhisper --provider ollama --model deepseek-coder:6.7bPrefer cloud intelligence? Use any OpenAI-compatible endpoint. GitWhisper's Phase 7 Fail-Closed Redaction automatically scans and strips secrets, passwords, and tokens before the prompt leaves your machine.
# Pass via CLI
gitwhisper --provider openai-compatible --model gpt-4o-mini --api-key sk-...
# Or set environment variable
export OPENAI_API_KEY="sk-..."
gitwhisper --provider openai-compatible --model gpt-4o-minigitwhisper --provider openai-compatible \
--base-url https://api.groq.com/openai/v1 \
--model llama-3.3-70b-versatile \
--api-key gsk_...gitwhisper --provider openai-compatible \
--base-url https://openrouter.ai/api/v1 \
--model meta-llama/llama-3.3-70b-instruct \
--api-key sk-or-...gitwhisper --provider openai-compatible \
--base-url http://localhost:1234/v1 \
--model local-modelYou can lock in your preferred settings for an entire team or repository by adding a .gitwhisper.json file in your repository root:
{
"provider": "ollama",
"model": "qwen2.5-coder:7b",
"commit": {
"maxSubjectLength": 72,
"requireScope": false,
"allowedTypes": ["feat", "fix", "docs", "style", "refactor", "perf", "test", "build", "ci", "chore"]
},
"hooks": {
"commitMsg": "warn"
}
}Or for an OpenAI-powered repository:
{
"provider": "openai-compatible",
"model": "gpt-4o-mini",
"providers": {
"openai-compatible": {
"baseUrl": "https://api.openai.com/v1"
}
}
}What if Ollama is closed or your internet is down?
GitWhisper never leaves you stranded. Its deterministic engine analyzes Git tree plumbing, file paths, and monorepo structure to derive the exact Conventional Commit type (feat, fix, docs, chore, etc.) and scope (auth, cli, vscode). The LLM is strictly used for descriptive phrasingโit never controls commit syntax or data safety.
- Build the extension package:
This outputs
pnpm run build:vscode cd apps/vscode npx @vscode/vsce packagegitwhisper-vscode-0.1.0.vsix. - Install via command line:
OR via VS Code UI:
code --install-extension apps/vscode/gitwhisper-vscode-0.1.0.vsix
- Open VS Code
$\rightarrow$ click the Extensions icon (Ctrl+Shift+X). - Click the
...(Views and More Actions) menu in the top right corner of the Extensions panel. - Select Install from VSIX...
- Choose
apps/vscode/gitwhisper-vscode-0.1.0.vsix. Done!
- Open VS Code
You do not need to use the command line to publish:
- Create a publisher account at marketplace.visualstudio.com/manage.
- Click New Extension
$\rightarrow$ Visual Studio Code. - Drag and drop
gitwhisper-vscode-0.1.0.vsix. - Microsoft automatically validates and publishes your extension within 5 minutes!
| Command | Description |
|---|---|
gitwhisper |
Interactive commit composer with variant selection and overrides. |
gitwhisper generate --dry-run |
Generates conventional proposals without committing. |
gitwhisper check [msg] |
Evaluates commit message quality against team policy. |
gitwhisper hooks [install|status|uninstall] |
Manages the .git/hooks/commit-msg quality gate. |
gitwhisper style |
Learns and inspects repository-specific commit conventions. |
gitwhisper timeline |
Clustered commit history and workstream intelligence. |
gitwhisper hunks |
Inspects and plans atomic hunk-level commit splitting. |
gitwhisper/
โโโ packages/
โ โโโ core/ # Core engine, type/scope detection, history style, timeline
โ โโโ git/ # Index plumbing, diff parsing, hooks manager, patch ops
โ โโโ ai/ # Ollama, OpenAI-compatible BYOK adapters, prompt guards
โ โโโ config/ # Multi-layer configuration (.gitwhisper.json) and team policy
โ โโโ editor/ # Reusable MyIDEAdapter and IDE command bridges
โโโ apps/
โ โโโ cli/ # Interactive terminal application
โ โโโ vscode/ # Native VS Code Extension with SCM UI integration
โโโ scripts/
โ โโโ qs-test.ts # Automated 10-step Quality Suite runner
โโโ .github/workflows/
โโโ ci.yml # Multi-OS matrix CI (Ubuntu, macOS, Windows on Node 20 & 22)
โโโ pr-title.yml # Conventional Commit PR title validation
GitWhisper is rigorously tested with zero-mock Git plumbing tests:
# Run complete test suite (304 tests across 66 files)
pnpm test
# Run tests with coverage gates
pnpm run test:coverage
# Run the 10-step Quality Suite
pnpm run test:qs
# Run code linter & format check
pnpm run lint
pnpm run format:check
# Build all packages and the VS Code extension
pnpm run buildMIT ยฉ RitualDev