Figures attributed to Google engineer Roman Gushchin’s presentation at Linux Plumbers Conference, held October 5–7, 2026, put Sashiko above 191,000 Linux kernel patch reviews across 99 mailing lists in less than a year. The count describes reviews performed. A separate project benchmark measures how often Sashiko detected bugs in a defined set of past kernel commits.

Sashiko’s reported review activity

The March–October 2026 activity figures also list 19.3 million autonomous Git-tool lookups. The reported update includes more than 7,600 responses from over 1,100 kernel developers, along with 1,277 commits in linus/master and 1,567 in linux-next/master that cited Sashiko.

The same tally lists 463 kernel CVE records citing Sashiko. Those figures count references and activity; they do not describe how many patches were accepted or how many vulnerabilities the tool found.

The project’s benchmark, in context

The Sashiko project reports that the system detected 53.6% of bugs that had passed human review and been merged into the Linux mainline kernel. The benchmark used Gemini 3.1 Pro against the last 1,000 unfiltered upstream commits carrying Fixes: tags. It is a retrospective result tied to that model and sample.

The project separately reports a false-positive estimate below 20% from manual sampling, with most flagged concerns described as gray-area issues. Sashiko’s output is probabilistic and can vary between runs, so findings still call for human review.

Local review and human judgment

Sashiko can review a local Linux kernel checkout as well as handle automated review from mailing lists and Git forges. For local work, its sashiko review command can inspect a commit or a range of commits. The project documents a multi-stage process that analyzes areas such as implementation, execution flow, resources, locking, security and hardware, then verifies candidate findings.

The quick start lists Rust 1.90 or newer, Git and an LLM-provider API key as requirements. The project says patch data and relevant repository context are sent to the configured provider, and warns that multi-stage reviews can incur significant API costs.