OPEN SOURCE DEEP DIVE
Alibaba open-sources Open Code Review: battle-tested hybrid code review CLI
Originating from Alibaba's internal official AI review assistant (tens of thousands of devs, millions of defects over two years): hybrid deterministic pipelines + LLM Agent, line-level comments, built-in NPE/thread-safety/XSS/SQL-injection rulesets, plugins for Claude Code/Codex/Cursor and more, CI/CD integration, and a public benchmark of 200 real PRs with 1,505 annotated issues. OpenAI/Anthropic compatible.
From Alibaba's internal AI review assistant to an open-source project
Open Code Review (ocr) is not "yet another LLM review toy" — it started as Alibaba Group's official internal AI code review assistant, serving tens of thousands of developers and identifying millions of code defects over two years before being open-sourced after validation at massive scale. Configure a model endpoint and you are ready to go.
Hybrid architecture: deterministic pipelines + LLM Agent
The project bills itself as a secure, fast, efficient review tool battle-tested at Alibaba's scale: deterministic pipelines read Git diffs and partition changed files, while an LLM Agent with tool-use does deep analysis. The agent can read full file contents, search the codebase, and cross-check other changed files for context — producing deep reviews rather than surface-level diff feedback. Comments carry line-level precision, and a built-in multi-language ruleset covers NPE, thread-safety, XSS, and SQL injection. OpenAI- and Anthropic-compatible.
Two review modes
- Diff review (
ocr review): Git-diff based, supporting ranges (--from main --to feature-branch), single commits, and resume after interruption (session list+--resume). - Full-file scan (
ocr scan): no git history needed — audit entire repositories or specific directories/files, ideal for unfamiliar codebases.
Results can be saved with --format json --output result.json for consumption by host agents.
Coding-agent integrations and CI/CD
Official plugins/skills exist for Claude Code, Codex, Cursor, Kimi Code, and OpenCode (review slash commands or callable skills). A Delegation Mode lets your own coding agent run reviews with its own LLM — no OCR API key required. CI/CD support covers GitHub Actions, GitLab CI, GitFlic CI, and Gerrit.
A real-world PR benchmark
The bundled benchmark is built from 50 popular open-source repositories, 200 real pull requests, and 10 programming languages, cross-validated by 80+ senior engineers into 1,505 annotated ground-truth issues — a rare public benchmark for quantitatively comparing review capability.
Quick start
npm install -g @alibaba-group/open-code-review
ocr review --from main --to feature-branch
ocr scan --path internal/agent
See open-codereview.ai and the GitHub repo for details.