Unofficial GitLab CI integration layer for Open Code Review
Project description
Open Code Review Toolkit
Open Code Review Toolkit is an unofficial GitLab CI integration layer for Alibaba Open Code Review. It provides bounded repository context generation, environment-driven OCR configuration, preflight validation, and safe GitLab merge-request posting. It does not bundle or download the ocr binary.
[!NOTE] The project is under active development. It currently targets Python 3.10-3.14 on Linux and macOS; the public API, CLI, environment contract, and generated schemas may evolve before 1.0.
Install
Install the Python package from PyPI and install a supported OCR binary separately:
python -m pip install open-code-review-toolkit
ocr --version
ocr-ci --help
The current compatibility target is OCR 1.7.13. CI should pin the release and verify its published checksum before execution.
Review output defaults to English. Set OCR_REVIEW_LANGUAGE=Russian to use Russian consistently in both OCR configuration and generated review context.
Stable distributions are published to PyPI and mirrored as checksum-listed, provenance-attested assets in the corresponding GitHub Release. Development snapshots are published only to TestPyPI.
GitLab CI quick start
- Configure protected/masked
GITLAB_API_TOKENand LLM variables in GitLab. - Pin and checksum the OCR binary.
- Install this package.
- Run the five helper stages around
ocr review:
ocr-ci preflight
ocr-ci configure
ocr-ci mcp-config
ocr-ci context --output .review-context/dependencies.md
# run: ocr review ... --format json
ocr-ci post --result /tmp/ocr-result.json --stderr /tmp/ocr-stderr.log
See the fully synthetic examples/gitlab/ocr-review.gitlab-ci.yml and the GitLab guide.
Configuration and safety
Configuration is environment-only in v0.1. The configuration reference documents supported OCR_*, CI_*, GITLAB_*, and MCP inputs. Posting requires GITLAB_API_TOKEN; job tokens and legacy aliases are deliberately unsupported.
Repository content, OCR output, and provider responses are untrusted inputs. The toolkit applies bounded reads and writes, secret redaction, Unicode normalization, Markdown/quick-action neutralization, fingerprinted comments, ownership boundaries for human replies, and rollback controls. Review the security and trust model before enabling write access.
Development and release
Licensed under Apache-2.0.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file open_code_review_toolkit-0.1.0.tar.gz.
File metadata
- Download URL: open_code_review_toolkit-0.1.0.tar.gz
- Upload date:
- Size: 122.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
34400866886ba253f933315332c439679da30a9612b0deb4e1bb73de44438ce9
|
|
| MD5 |
6da99c3ae73c53773e32aadb438c8aea
|
|
| BLAKE2b-256 |
cb35b7e5c14aa744433a04381ba6d156aac279b2ea42f8a14ca92ab4d46c13b8
|
Provenance
The following attestation bundles were made for open_code_review_toolkit-0.1.0.tar.gz:
Publisher:
release.yml on xeonvs/open-code-review-toolkit
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
open_code_review_toolkit-0.1.0.tar.gz -
Subject digest:
34400866886ba253f933315332c439679da30a9612b0deb4e1bb73de44438ce9 - Sigstore transparency entry: 2205672934
- Sigstore integration time:
-
Permalink:
xeonvs/open-code-review-toolkit@96d6d33d2faa1d664b41f4b19d3498a7bb148d72 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/xeonvs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@96d6d33d2faa1d664b41f4b19d3498a7bb148d72 -
Trigger Event:
pull_request
-
Statement type:
File details
Details for the file open_code_review_toolkit-0.1.0-py3-none-any.whl.
File metadata
- Download URL: open_code_review_toolkit-0.1.0-py3-none-any.whl
- Upload date:
- Size: 96.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ad2ddac2fe39bc204a1ea5f80340a126faee96797de97e8505c18b2acb7d6016
|
|
| MD5 |
908067996730c6b5ba24124f8a6c8357
|
|
| BLAKE2b-256 |
243c93f185bb871a25e72b8b3564d2309b7d0a61cef4f352bd086a30ac84a4d4
|
Provenance
The following attestation bundles were made for open_code_review_toolkit-0.1.0-py3-none-any.whl:
Publisher:
release.yml on xeonvs/open-code-review-toolkit
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
open_code_review_toolkit-0.1.0-py3-none-any.whl -
Subject digest:
ad2ddac2fe39bc204a1ea5f80340a126faee96797de97e8505c18b2acb7d6016 - Sigstore transparency entry: 2205673008
- Sigstore integration time:
-
Permalink:
xeonvs/open-code-review-toolkit@96d6d33d2faa1d664b41f4b19d3498a7bb148d72 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/xeonvs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@96d6d33d2faa1d664b41f4b19d3498a7bb148d72 -
Trigger Event:
pull_request
-
Statement type: