mirror of
https://github.com/alibaba/open-code-review.git
synced 2026-08-22 07:04:17 +00:00
Some checks are pending
CI / cross-compile (arm64, darwin) (push) Waiting to run
CI / cross-compile (arm64, linux) (push) Waiting to run
CI / cross-compile (arm64, windows) (push) Waiting to run
CI / test (push) Waiting to run
CI / cross-compile (amd64, darwin) (push) Waiting to run
CI / cross-compile (amd64, windows) (push) Waiting to run
CodeQL Advanced / Analyze (go) (push) Waiting to run
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
Deploy Pages / build (push) Waiting to run
Deploy Pages / deploy (push) Blocked by required conditions
* chore: add SPDX license headers to all source files
Add Apache-2.0 SPDX license identifiers and copyright notices to all
tracked .go, .sh, .js, .mjs, .ts, and .tsx source files.
Introduce scripts/verify-license.sh and scripts/add-license.sh for
automated verification and bulk addition of license headers. Integrate
the check into CI (ci.yml) and the Makefile (license-check target as
a prerequisite of the existing check target).
This satisfies the OpenSSF Best Practices Badge requirements for
copyright_per_file and license_per_file.
* fix: restore execute permissions on scripts
* docs: add license header instructions to CONTRIBUTING guides
* docs: add license header instructions to pages contributing guides
* fix(pages): strip unclosed HTML comment markers to satisfy CodeQL
* fix: apply code review suggestions for license scripts
- Fix portability: detect macOS vs Linux stat for permission copy
- Fix has_header: check both SPDX and copyright (match verify logic)
- Fix is_ignored: match on path boundaries to avoid false positives
- Fix year extraction: use consistent pipeline across both scripts
- Fix Bash 3.2 compat: quote array length expansion for set -u
* fix(pages): use loop-until-clean for HTML comment stripping (CodeQL)
* fix(pages): use split/join instead of replace to avoid CodeQL false positive
CodeQL's js/incomplete-multi-character-sanitization rule flags any
.replace() that removes multi-character sequences like '<!--...-->',
regardless of context. The data here comes from readFileSync on the
project's own index.html (no untrusted input), making this a false
positive. Using split(regex).join('') achieves the same result without
triggering the taint-tracking rule.
63 lines
1.8 KiB
JavaScript
Executable file
63 lines
1.8 KiB
JavaScript
Executable file
#!/usr/bin/env node
|
|
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
// Copyright 2026 alibaba/open-code-review Contributors
|
|
|
|
"use strict";
|
|
|
|
const { spawnSync, spawn } = require("child_process");
|
|
const path = require("path");
|
|
const fs = require("fs");
|
|
const os = require("os");
|
|
|
|
const { resolveNativeBinary } = require("../scripts/platform");
|
|
|
|
const resolved = resolveNativeBinary();
|
|
if (!resolved) {
|
|
console.error(
|
|
"[ERROR] OpenCodeReview binary not found. Run: npm install -g @alibaba-group/open-code-review"
|
|
);
|
|
process.exit(1);
|
|
}
|
|
const binaryPath = resolved.path;
|
|
|
|
const hintFile = path.join(os.homedir(), ".opencodereview", "update-available");
|
|
try {
|
|
const hint = JSON.parse(fs.readFileSync(hintFile, "utf8"));
|
|
if (hint.version && hint.pkg) {
|
|
console.error(
|
|
`\x1b[33m[ocr] A new version (v${hint.version}) is available. Run to update:\x1b[0m\n` +
|
|
`\x1b[33m npm i -g ${hint.pkg}@${hint.version}\x1b[0m\n`
|
|
);
|
|
}
|
|
} catch (_) {}
|
|
|
|
if (!process.env.OCR_NO_UPDATE) {
|
|
const stateDir = path.join(os.homedir(), ".opencodereview");
|
|
const tsFile = path.join(stateDir, "last-update-check");
|
|
const cooldownMs =
|
|
(parseInt(process.env.OCR_UPDATE_INTERVAL, 10) || 18) * 60 * 1000;
|
|
|
|
let shouldCheck = true;
|
|
try {
|
|
const mt = fs.statSync(tsFile).mtimeMs;
|
|
if (Date.now() - mt < cooldownMs) shouldCheck = false;
|
|
} catch (_) {}
|
|
|
|
if (shouldCheck) {
|
|
const updateScript = path.join(__dirname, "..", "scripts", "update.js");
|
|
const child = spawn(process.execPath, [updateScript], {
|
|
detached: true,
|
|
stdio: "ignore",
|
|
env: Object.assign({}, process.env, { OCR_NO_UPDATE: "1" }),
|
|
});
|
|
child.unref();
|
|
}
|
|
}
|
|
|
|
const result = spawnSync(binaryPath, process.argv.slice(2), {
|
|
stdio: "inherit",
|
|
env: process.env,
|
|
});
|
|
|
|
process.exit(result.status ?? (result.error ? 1 : 0));
|