mirror of
https://github.com/alibaba/open-code-review.git
synced 2026-08-08 08:14:26 +00:00
Some checks are pending
CI / cross-compile (arm64, darwin) (push) Waiting to run
CI / cross-compile (arm64, linux) (push) Waiting to run
CI / cross-compile (arm64, windows) (push) Waiting to run
CI / test (push) Waiting to run
CI / cross-compile (amd64, darwin) (push) Waiting to run
CI / cross-compile (amd64, windows) (push) Waiting to run
CodeQL Advanced / Analyze (go) (push) Waiting to run
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
Deploy Pages / build (push) Waiting to run
Deploy Pages / deploy (push) Blocked by required conditions
* chore: add SPDX license headers to all source files
Add Apache-2.0 SPDX license identifiers and copyright notices to all
tracked .go, .sh, .js, .mjs, .ts, and .tsx source files.
Introduce scripts/verify-license.sh and scripts/add-license.sh for
automated verification and bulk addition of license headers. Integrate
the check into CI (ci.yml) and the Makefile (license-check target as
a prerequisite of the existing check target).
This satisfies the OpenSSF Best Practices Badge requirements for
copyright_per_file and license_per_file.
* fix: restore execute permissions on scripts
* docs: add license header instructions to CONTRIBUTING guides
* docs: add license header instructions to pages contributing guides
* fix(pages): strip unclosed HTML comment markers to satisfy CodeQL
* fix: apply code review suggestions for license scripts
- Fix portability: detect macOS vs Linux stat for permission copy
- Fix has_header: check both SPDX and copyright (match verify logic)
- Fix is_ignored: match on path boundaries to avoid false positives
- Fix year extraction: use consistent pipeline across both scripts
- Fix Bash 3.2 compat: quote array length expansion for set -u
* fix(pages): use loop-until-clean for HTML comment stripping (CodeQL)
* fix(pages): use split/join instead of replace to avoid CodeQL false positive
CodeQL's js/incomplete-multi-character-sanitization rule flags any
.replace() that removes multi-character sequences like '<!--...-->',
regardless of context. The data here comes from readFileSync on the
project's own index.html (no untrusted input), making this a false
positive. Using split(regex).join('') achieves the same result without
triggering the taint-tracking rule.
69 lines
1.9 KiB
JavaScript
69 lines
1.9 KiB
JavaScript
// SPDX-License-Identifier: Apache-2.0
|
|
// Copyright 2026 alibaba/open-code-review Contributors
|
|
|
|
"use strict";
|
|
|
|
const path = require("path");
|
|
const fs = require("fs");
|
|
|
|
const IS_WINDOWS = process.platform === "win32";
|
|
const BINARY_FILENAME = IS_WINDOWS ? "opencodereview.exe" : "opencodereview";
|
|
|
|
const PLATFORM_PKG = {
|
|
"darwin-arm64": "@alibaba-group/ocr-darwin-arm64",
|
|
"darwin-x64": "@alibaba-group/ocr-darwin-x64",
|
|
"linux-arm64": "@alibaba-group/ocr-linux-arm64",
|
|
"linux-x64": "@alibaba-group/ocr-linux-x64",
|
|
"win32-arm64": "@alibaba-group/ocr-win32-arm64",
|
|
"win32-x64": "@alibaba-group/ocr-win32-x64",
|
|
};
|
|
|
|
function getPlatformPackageName() {
|
|
const key = `${process.platform}-${process.arch}`;
|
|
|
|
try {
|
|
const parentPkg = JSON.parse(
|
|
fs.readFileSync(path.join(__dirname, "..", "package.json"), "utf8")
|
|
);
|
|
const optDeps = parentPkg.optionalDependencies || {};
|
|
for (const name of Object.keys(optDeps)) {
|
|
if (name.endsWith(`-${key}`)) {
|
|
return name;
|
|
}
|
|
}
|
|
} catch (_) {}
|
|
|
|
return PLATFORM_PKG[key] || null;
|
|
}
|
|
|
|
function resolveNativeBinary() {
|
|
const pkgName = getPlatformPackageName();
|
|
if (pkgName) {
|
|
try {
|
|
const pkgDir = path.dirname(require.resolve(`${pkgName}/package.json`));
|
|
const binPath = path.join(pkgDir, "bin", BINARY_FILENAME);
|
|
if (fs.existsSync(binPath)) {
|
|
return { path: binPath, fromPlatformPkg: true };
|
|
}
|
|
} catch (err) {
|
|
if (err.code !== "MODULE_NOT_FOUND") {
|
|
console.warn(`[WARN] Unexpected error resolving ${pkgName}: ${err.message}`);
|
|
}
|
|
}
|
|
}
|
|
|
|
const legacyPath = path.join(__dirname, "..", "bin", BINARY_FILENAME);
|
|
if (fs.existsSync(legacyPath)) {
|
|
return { path: legacyPath, fromPlatformPkg: false };
|
|
}
|
|
|
|
return null;
|
|
}
|
|
|
|
module.exports = {
|
|
IS_WINDOWS,
|
|
BINARY_FILENAME,
|
|
PLATFORM_PKG,
|
|
getPlatformPackageName,
|
|
resolveNativeBinary,
|
|
};
|