Skip to main content

Open Code Review Toolkit

OpenSSF Best Practices OpenSSF Scorecard CodeQL

Open Code Review Toolkit is an unofficial GitLab CI integration layer for Alibaba Open Code Review. It provides bounded repository evidence, a compact review bootstrap, a built-in read-only MCP server, environment-driven OCR configuration, preflight validation, and safe GitLab merge-request posting. It does not bundle or download the ocr binary.

[!NOTE] The project is under active development; the public API, CLI, environment contract, and generated schemas may evolve before 1.0.

Install

Install the Python package from PyPI and install a supported OCR binary separately:

python -m pip install open-code-review-toolkit
ocr --version
ocr-ci --help

The exact recommended OCR release and its verified asset checksums live in the versioned compatibility manifest. CI should pin that release and checksum before execution. The versioned compatibility policy records tested assets and evidence and describes the conservative Dependabot-like qualification workflow for later upstream releases. Review output defaults to English. OCR_REVIEW_LANGUAGE accepts another explicit language name when a project needs localized review output; for example, OCR_REVIEW_LANGUAGE=Russian.

Stable distributions are published to PyPI and mirrored as checksum-listed, provenance-attested assets in the corresponding GitHub Release. Development snapshots are published only to TestPyPI.

How reviews evolve

On a successful rerun, the toolkit replaces untouched OCR-only notes instead of accumulating stale reviews. A human reply transfers that discussion to the team: the conversation is preserved and a matching finding is suppressed. Reply with /ocr suppress or @<live-bot-username> suppress to keep a discussion open without future repeats; use the corresponding resolve command to resolve it after the next successful posting transaction. For example, a bot named mr.bot accepts the exact reply @mr.bot resolve.

Suppression uses both the GitLab diff position and a stable finding fingerprint, so ordinary line shifts do not normally bring the same bug back. A materially changed finding can still receive a new discussion. See GitLab review operations for the complete lifecycle, posting modes, permissions, failure behavior, and Mermaid state diagram.

After every current review note publishes, the GitLab adapter can add a conservative approval bound to receipt v5's exact reviewed source SHA and merge-request author. This write is enabled by default; set OCR_AUTO_APPROVE=false when the bot must remain comment-only. DLP-clean metadata, generic discussions, and adapter records do not independently block approval, while degraded metadata, DLP rejection, required context degradation, admitted remediation history, legacy receipts, publication filtering, any direct external MCP, author movement, or bot self-authorship prevents an approval write. GitLab approval rules and protected-branch policy remain authoritative. The toolkit only adds an eligible approval; it never removes an existing approval when a later review is ineligible or disabled.

Accepted tradeoffs can be recorded in .opencodereview/accepted-decisions.md; the evidence collector supplies only applicable target-ref decisions and never lets a source change self-authorize its review. Root and nested target AGENTS.md/CLAUDE.md guidance is similarly exposed through the existing evidence MCP with deterministic scope and precedence, while any guidance touched by the merge request is excluded. See Accepted project decisions and Target project guidance for formats and trust boundaries.

Project architecture

The shipped Repository Evidence Engine reads immutable base/head Git objects, stores bounded typed facts and deltas, creates the compact bootstrap used by OCR, and exposes detailed facts, scoped completeness, and base/head changes through the mandatory built-in read-only MCP server. Protected-policy enriched reviews can acquire stable GitLab discussions, verified remediation history, and authorized external issue/document records before OCR. Forge-specific acquisition and posting stay at provider edges; the broker, DLP, store, MCP, receipts, and tests use common contracts so a future GitHub adapter can reuse them without inheriting GitLab API semantics. The same built-in MCP exposes only opaque committed context_list/context_get handles; it has no provider network or arbitrary identifier path. Direct external MCP remains a separate privileged, comment-only operator boundary.

  • Toolkit strategy - durable product boundaries, architecture, invariants, and non-goals.
  • Bounded review context - protected policy, adapter protocol, GitLab discussions, opaque handles, DLP, receipt, and cleanup contracts.
  • Roadmap - milestone status, dependencies, outcomes, and completion signals.
  • Backlog - inactive implementation-ready work; active execution remains in PLANS.md.

GitLab CI quick start

  1. Configure protected/masked GITLAB_API_TOKEN and LLM variables in GitLab.
  2. Pin and checksum the OCR binary.
  3. Install this package.
  4. Run the four public helper stages around ocr review:
ocr-ci preflight
ocr-ci configure
ocr-ci review --result /tmp/ocr-result.json --stderr /tmp/ocr-stderr.log -- ... --format json
ocr-ci post --result /tmp/ocr-result.json --stderr /tmp/ocr-stderr.log

See the GitLab mode matrix, the complete ocr-review.gitlab-ci.yml pipeline, the GitLab setup guide, and GitLab review operations.

Configuration and safety

Configuration is environment-driven. The configuration reference documents supported OCR_*, CI_*, GITLAB_*, and MCP inputs. Posting requires GITLAB_API_TOKEN; job tokens and legacy aliases are deliberately unsupported.

Repository content, OCR output, and provider responses are untrusted inputs. The toolkit applies bounded reads and writes, secret redaction, Unicode normalization, Markdown/quick-action neutralization, fingerprinted comments, ownership boundaries for human replies, and rollback controls. Review the security and trust model before enabling write access.

Development and release

Licensed under Apache-2.0.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

open_code_review_toolkit-0.8.1.tar.gz (226.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

open_code_review_toolkit-0.8.1-py3-none-any.whl (287.7 kB view details)

Uploaded Python 3

File details

Details for the file open_code_review_toolkit-0.8.1.tar.gz.

File metadata

  • Download URL: open_code_review_toolkit-0.8.1.tar.gz
  • Upload date:
  • Size: 226.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for open_code_review_toolkit-0.8.1.tar.gz
Algorithm Hash digest
SHA256 14be57f3b0a94d37bb749b10f2494d7fb6d757f688f6e0b727fb750f2fafae8e
MD5 0394840e2477bbd80c4a3cd33bc99b75
BLAKE2b-256 e6d0fd17fc3c0cd16550c448e0dd76d9e92cdb0b649d687ce2fbf38060b42210

See more details on using hashes here.

Provenance

The following attestation bundles were made for open_code_review_toolkit-0.8.1.tar.gz:

Publisher: release.yml on xeonvs/open-code-review-toolkit

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file open_code_review_toolkit-0.8.1-py3-none-any.whl.

File metadata

File hashes

Hashes for open_code_review_toolkit-0.8.1-py3-none-any.whl
Algorithm Hash digest
SHA256 05c3f7425bf69c494da9b5b689ac712daf8d1c3587a7fa564dea67e7c2eb47bc
MD5 2e24453ec832bdd45d3566d2c6ee76e6
BLAKE2b-256 178dd66fa226bba55706e6eca2a7718622e45c368ceb2b58ee685ac8f228993b

See more details on using hashes here.

Provenance

The following attestation bundles were made for open_code_review_toolkit-0.8.1-py3-none-any.whl:

Publisher: release.yml on xeonvs/open-code-review-toolkit

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.9.0

2 files

0.8.7

2 files

0.8.6

2 files

0.8.5

2 files

0.8.4

2 files

0.8.3

2 files

0.8.2

2 files

This release

0.8.1 This release

2 files

0.8.0

2 files

0.7.1

2 files

0.7.0

2 files

0.6.3

2 files

0.6.2

2 files

0.6.1

2 files

0.6.0

2 files

0.5.0

2 files

0.4.7

2 files

0.4.6

2 files

0.4.5

2 files

0.4.4

2 files

0.4.3

2 files

0.4.2

2 files

0.4.1

2 files

0.4.0

2 files

0.3.1

2 files

0.3.0

2 files

0.2.1

2 files

0.2.0

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page