mirror of
https://github.com/alibaba/open-code-review.git
synced 2026-08-21 06:34:29 +00:00
Some checks are pending
CI / cross-compile (arm64, darwin) (push) Waiting to run
CI / cross-compile (arm64, linux) (push) Waiting to run
CI / cross-compile (arm64, windows) (push) Waiting to run
CI / test (push) Waiting to run
CI / cross-compile (amd64, darwin) (push) Waiting to run
CI / cross-compile (amd64, windows) (push) Waiting to run
CodeQL Advanced / Analyze (go) (push) Waiting to run
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
Deploy Pages / build (push) Waiting to run
Deploy Pages / deploy (push) Blocked by required conditions
* chore: add SPDX license headers to all source files
Add Apache-2.0 SPDX license identifiers and copyright notices to all
tracked .go, .sh, .js, .mjs, .ts, and .tsx source files.
Introduce scripts/verify-license.sh and scripts/add-license.sh for
automated verification and bulk addition of license headers. Integrate
the check into CI (ci.yml) and the Makefile (license-check target as
a prerequisite of the existing check target).
This satisfies the OpenSSF Best Practices Badge requirements for
copyright_per_file and license_per_file.
* fix: restore execute permissions on scripts
* docs: add license header instructions to CONTRIBUTING guides
* docs: add license header instructions to pages contributing guides
* fix(pages): strip unclosed HTML comment markers to satisfy CodeQL
* fix: apply code review suggestions for license scripts
- Fix portability: detect macOS vs Linux stat for permission copy
- Fix has_header: check both SPDX and copyright (match verify logic)
- Fix is_ignored: match on path boundaries to avoid false positives
- Fix year extraction: use consistent pipeline across both scripts
- Fix Bash 3.2 compat: quote array length expansion for set -u
* fix(pages): use loop-until-clean for HTML comment stripping (CodeQL)
* fix(pages): use split/join instead of replace to avoid CodeQL false positive
CodeQL's js/incomplete-multi-character-sanitization rule flags any
.replace() that removes multi-character sequences like '<!--...-->',
regardless of context. The data here comes from readFileSync on the
project's own index.html (no untrusted input), making this a false
positive. Using split(regex).join('') achieves the same result without
triggering the taint-tracking rule.
59 lines
1.4 KiB
Go
59 lines
1.4 KiB
Go
// SPDX-License-Identifier: Apache-2.0
|
|
// Copyright 2026 alibaba/open-code-review Contributors
|
|
|
|
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"runtime"
|
|
|
|
"github.com/spf13/cobra"
|
|
)
|
|
|
|
var rootCmd = &cobra.Command{
|
|
Use: "ocr",
|
|
Short: "OpenCodeReview - AI-Powered Code Review CLI",
|
|
Long: `OpenCodeReview - AI-Powered Code Review CLI
|
|
|
|
An AI-powered code review tool that reads git diffs, sends them to a
|
|
configurable LLM service, and generates review comments.`,
|
|
SilenceUsage: true,
|
|
SilenceErrors: true,
|
|
RunE: func(cmd *cobra.Command, args []string) error {
|
|
v, _ := cmd.Flags().GetBool("version")
|
|
if v {
|
|
printVersion()
|
|
return nil
|
|
}
|
|
return cmd.Help()
|
|
},
|
|
}
|
|
|
|
func init() {
|
|
rootCmd.SetFlagErrorFunc(flagErrorWithSuggestion)
|
|
rootCmd.Flags().BoolP("version", "V", false, "version for ocr")
|
|
|
|
rootCmd.AddCommand(versionCmd)
|
|
rootCmd.AddCommand(reviewCmd)
|
|
rootCmd.AddCommand(scanCmd)
|
|
rootCmd.AddCommand(delegateCmd)
|
|
rootCmd.AddCommand(sessionCmd)
|
|
rootCmd.AddCommand(configCmd)
|
|
rootCmd.AddCommand(llmCmd)
|
|
rootCmd.AddCommand(rulesCmd)
|
|
rootCmd.AddCommand(viewerCmd)
|
|
rootCmd.AddCommand(completionCmd)
|
|
}
|
|
|
|
func versionString() string {
|
|
s := fmt.Sprintf("open-code-review %s", Version)
|
|
if GitCommit != "" {
|
|
s += fmt.Sprintf(" (%s)", GitCommit)
|
|
}
|
|
s += fmt.Sprintf(" %s/%s\n", runtime.GOOS, runtime.GOARCH)
|
|
if BuildDate != "" {
|
|
s += fmt.Sprintf("built at: %s\n", BuildDate)
|
|
}
|
|
s += "https://github.com/alibaba/open-code-review\n"
|
|
return s
|
|
}
|