100 Commits
Author SHA1 Message Date
kite 86482ade24 chore(gitignore): ignore local claude command files 2026-07-31 11:27:35 +08:00
kite 74f5cde8b4 fix(vscode): upgrade js-yaml resolution to >=5.2.2 for GHSA DoS (#511) 2026-07-26 18:12:21 +08:00
kite 6ae397b894 fix(ci): use npm install instead of npm ci in Pages CI
package-lock.json is gitignored for the pages directory, so npm ci
always fails in CI (no lockfile present after checkout). Switch to
npm install to match deploy-pages.yml behavior.
2026-07-24 23:29:09 +08:00
kite c9f6e86e45 fix(ci): pin Pages CI container to node:24.18.0 (#492)
The rolling `node:24` tag recently picked up a newer npm version whose
`npm ci` rejects the existing lockfileVersion-3 lockfile. Pin to
24.18.0 (same version used by translation-sync.yml) to restore
deterministic builds.
2026-07-24 23:11:18 +08:00
kite 69e68a9317 docs(readme): add overall Trendshift badge alongside weekly badge
Add the overall Trendshift repository badge next to the existing weekly
trending badge, and resize both to 280x60 for balanced side-by-side display.
2026-07-24 09:12:26 +08:00
kite fc9cc769e1 fix(vscode): bound brace-expansion resolution to avoid poisoned 5.x (#467)
The resolutions entry "brace-expansion": ">=2.1.2" had no upper bound,
so yarn resolved it to the poisoned 5.0.7 release whose changed export
shape breaks minimatch's default import, crashing `yarn lint` with
"brace_expansion_1.default is not a function".

Bound the range to ">=2.1.2 <3" (keeping the CVE-safe lower bound from
#445) and regenerate yarn.lock. brace-expansion now resolves to 2.1.2
and its transitive balanced-match back to 1.0.2. Lint, compile and the
92 unit tests all pass.
2026-07-23 21:18:24 +08:00
kite aeea6342fc fix(deps): upgrade grpc-go to v1.82.1 for GHSA-hrxh-6v49-42gf (#456)
Fixes Dependabot alert #26 (High severity). Addresses xDS RBAC
authorization bypass, HTTP/2 Rapid Reset DoS bypass, and xDS RBAC
engine panic vulnerabilities.
2026-07-23 10:02:12 +08:00
kite 484b513aee fix(vscode): resolve 5 high-severity npm dependency vulnerabilities (#445)
Add yarn resolutions to pin minimum safe versions for brace-expansion
(>=2.1.2), fast-uri (>=3.1.4), js-yaml (>=4.3.0), and linkify-it
(>=5.0.2), fixing DoS and host-confusion vulnerabilities reported by
Dependabot alerts #21-#25.
2026-07-22 13:17:23 +08:00
kite c62c4ae79b ci(pages): add Pages CI workflow for typecheck and build (#442)
Add a Pages CI GitHub Actions workflow that runs on pull requests
touching pages/**, performing npm ci, typecheck, and build. This
provides quality gating for the frontend, which previously had no
PR-level checks (deploy-pages.yml only ran on push to main).
2026-07-22 13:03:23 +08:00
kite 5ebc4d9975 ci: unify gofmt -s across Makefile and CI, reduce cross-compile timeout (#439)
- Change Makefile fmt/check targets from `go fmt` to `gofmt -s -w .`
  to match the CI gate introduced in #433, preventing drift where
  local `make fmt` passes but CI fails on simplification opportunities.

- Reduce cross-compile job timeout from 20 to 10 minutes, since each
  leg completes in ~16 seconds on self-hosted runners.
2026-07-22 11:23:39 +08:00
kite 90306cafb4 docs(readme): slim README by removing sections duplicated on docs site (#426) 2026-07-21 18:09:02 +08:00
kite 817ddf9403 docs(readme): link to docs site and collapse duplicated sections (#424)
Reduce the large content overlap between the README files and the docs
site (pages/src/content/docs). Add a Documentation section linking to
open-codereview.ai/docs, and collapse the Commands, Review Rules, and
Configuration Reference sections into one-line summaries plus links.
This makes the docs site the single source of truth for reference
content and cuts the multi-language maintenance burden.

Applied consistently across all five localized READMEs (en/zh/ja/ko/ru).
2026-07-21 17:12:31 +08:00
kite d0caa8af66 feat(pages): add social preview meta tags and og-image (#414)
Add description, Open Graph, and Twitter Card meta tags to the site's index.html, plus an og-image.png asset. Fixes link previews in messaging apps (iMessage, WeChat, Slack, etc.) showing no description or thumbnail when the site URL is unfurled into a card.
2026-07-21 14:33:27 +08:00
kite 3493658a87 docs(readme): update official website URL to open-codereview.ai (#410)
Point the logo link and official website link to the new custom
domain https://open-codereview.ai across all localized READMEs.
2026-07-20 19:47:14 +08:00
kite 750304d63a feat(pages): serve landing site at custom-domain root with clean URLs (#407)
Migrate the landing site from the GitHub Pages subpath
/open-code-review/ to the root of the open-codereview.ai custom domain
and drop the /#/ from URLs:

- webpack publicPath -> '/' so assets load at the domain root
- switch HashRouter -> BrowserRouter for clean paths (e.g. /docs)
- fix HeroSection '#/docs' anchor to a router Link
- add public/CNAME (open-codereview.ai) for the GitHub Pages custom domain
- emit 404.html (copy of index.html) as SPA deep-link fallback
2026-07-20 16:12:26 +08:00
kite 8e628f9e1c docs(pages): simplify page title to "Open Code Review" 2026-07-20 14:50:14 +08:00
kite c4de7ac32d docs(pages): note that LLM API key is optional in delegation mode (#392)
Add a parenthetical to the quickstart prerequisites and a tip before
Step 2 so delegation-mode users know they can skip LLM configuration.
2026-07-17 16:36:19 +08:00
kite 86724c3d1a docs(pages): simplify claude-code prerequisites, recommend delegation mode (#391)
Remove redundant auto-install hints (the command handles this
transparently) and replace the LLM prerequisite note with a tip
pointing users to Delegation Mode as a zero-config alternative.
2026-07-17 16:29:52 +08:00
kite 17049fb1e3 docs(pages): remove integrations parent page, keep as sidebar group (#387)
The integrations overview page added little value beyond navigation.
Remove its content and make the sidebar entry a non-navigable group
node that only expands/collapses its children.
2026-07-17 11:37:32 +08:00
kite 2967f2a9cb docs(pages): add Delegation Mode documentation to website (#386)
Add a new Delegation Mode page under Integrations in the docs site,
covering the ocr delegate subcommand workflow for subscription-based
AI coding agents (Claude Code, Codex, Cursor, Open Code, Qoder).

- New docs in en/zh/ja under integrations/delegate.md
- Register 'delegate' slug in docs index.ts
- Add sidebar entry in DocsPage.tsx
- Add i18n labels for all three languages
- Fix list-style-type reset caused by Tailwind Preflight in docs
2026-07-17 11:03:58 +08:00
kite 4ee453fd79 feat(delegate): add delegation mode for host-agent driven code review (#383)
* feat(delegate): add delegation mode for host-agent driven code review

Add `ocr delegate` subcommand that provides deterministic file selection
and rule resolution without calling any LLM. This enables AI coding agents
to perform reviews themselves using OCR only for engineering scaffolding
(preview which files to review, resolve grouped rules by path).

Includes:
- `ocr delegate preview` — outputs reviewable file list with mode/ref metadata
- `ocr delegate rule <path...>` — outputs review rules grouped by content
- Claude Code plugin command (delegate-review.md)
- Skill definitions for Claude Code, Codex, and Cursor
- Unit tests for internal/delegate package
- README documentation synced across all 5 locales

* fix(delegate): group rules by source, pattern and text

GroupRules keyed groups on rule text alone, so files sharing identical
rule text but resolved from different sources or matched by different
patterns were merged into one group that kept only the first file's
Source/Pattern metadata. Use a composite (source, pattern, text) key so
each group's provenance is accurate for every file it contains.
2026-07-16 13:10:54 +08:00
kite c3da878850 fix(pages): widen blog detail content area with percentage-based max-width (#356) 2026-07-11 10:46:47 +08:00
kite 4cc2fe8568 feat(pages): add blog section with i18n support (#355)
Add a blog feature to the pages site including:
- BlogPage component with list/detail views, tag filtering, search, and TOC
- Blog content system with markdown posts and i18n (en/ja/zh)
- Navbar integration with blog tab and improved active state detection
- MarkdownRenderer image path handling for relative/absolute paths
- Webpack CopyPlugin for serving static blog assets
2026-07-10 22:55:53 +08:00
kite d191862b95 fix(llm): make OCR_LLM_EXTRA_HEADERS apply to all resolver strategies (#353)
Previously, OCR_LLM_EXTRA_HEADERS was only parsed inside the tryOCREnv
strategy, so extra headers set via the environment variable were ignored
when the endpoint was resolved through config-file providers or other
strategies. Move the parsing into the global resolution loop so the env
var acts as a universal override, merging into whatever headers the
winning strategy already provides (env values take precedence on
conflict).
2026-07-10 16:52:59 +08:00
kite 88faa5775e fix(vscode): add PNG icon for marketplace display and bump to v0.1.1
VS Code Marketplace requires PNG format icons — SVG icons are ignored,
causing the extension to show a default placeholder avatar.
2026-07-10 15:20:22 +08:00
kite 37ac8658dc chore(vscode): prepare extension for marketplace publishing (#349)
- Update repository URL to alibaba/open-code-review
- Add LICENSE file for marketplace compliance
- Exclude __mocks__ from VSIX package
- Add *.vsix to .gitignore and remove tracked VSIX binary
2026-07-10 11:36:39 +08:00
kite ed168d9882 chore(vscode): replace activity bar icon with new design (#348)
Remove the old icon-old.svg and replace icon.svg with a refined
shield-and-eye motif that better represents the code review concept.
2026-07-10 11:04:43 +08:00
kite fbc11045bd docs(pages): split install and version commands into separate code blocks (#345)
Separate `npm install` and `ocr version` into individual code blocks in
quickstart guides so each command can be copied independently.
2026-07-09 20:30:08 +08:00
kite 07b41bad79 docs(roadmap): mark MCP as shipped and add delegate mode
Move MCP server to the current-state list now that it is supported, and
replace the MCP roadmap entry with a delegate mode that lets ocr run on
the host coding agent's subscription without a standalone LLM endpoint.
2026-07-09 13:42:45 +08:00
kite 3d2886ea78 docs: remove broken Star History section from all READMEs (#329)
GitHub restricted the stargazers API (July 2026) to a repository's own
admins and collaborators, so the embedded star-history.com SVG can no
longer render for anonymous README viewers. Remove the Star History
section from README.md and all localized versions.
2026-07-09 11:14:44 +08:00
kite e6e5da0930 ci: bump Go image to 1.26.5 to fix GO-2026-5856 govulncheck failure (#330)
govulncheck flags GO-2026-5856 (Encrypted Client Hello privacy leak in
crypto/tls), present in the Go standard library through go1.26.4 and
fixed in go1.26.5. The CI and release workflows pin the golang:1.26.4
container image, so govulncheck fails with exit code 3 on every run.
Bump both workflow images to golang:1.26.5.
2026-07-09 11:00:45 +08:00
kite e2d75b732a test: fix golangci-lint errcheck/staticcheck issues in test code (#323) 2026-07-08 22:46:18 +08:00
kite ac1eff5bae docs: add contributors image to Contributing section (#326) 2026-07-08 22:41:49 +08:00
kite eb680d9645 docs: remove retired Go Report Card badge (#319)
Go Report Card has been sunset by its maintainers; the badge endpoint now
returns "go report: retired" and the report page redirects to a farewell
notice, so the badge can never render a grade. Remove it from README.md and
all localized versions (zh-CN, ja-JP, ko-KR, ru-RU).
2026-07-08 14:26:32 +08:00
kite a2e08b77a1 feat(review): add structured category and severity to findings (#311)
Add two structured fields, category and severity, to every review finding
so CI integrations can sort, group, filter, or gate builds without
re-parsing natural-language comment text.

- Tool schema (tools.json): add category/severity as enum-constrained,
  required properties of code_comment. severity is limited to
  critical/high/medium/low (info dropped, since LLMs struggle to
  distinguish low from info).
- System prompt (task_template.json) is intentionally left untouched to
  avoid the review-quality regression observed on the benchmark suite;
  the tool schema alone drives field population.
- JSON output: category/severity are flat siblings of content/start_line,
  omitted entirely when empty (backward compatible).
- CLI output: render an inline [category - severity] badge before the
  comment, colored by severity.
- Sync docs across all five README locales.
2026-07-07 13:08:41 +08:00
kite 9dfcffda07 fix(pages): address CodeQL XSS alerts in markdown rendering (#300)
* fix(pages): address CodeQL XSS alerts in markdown rendering

Alert #4 (headingId.ts): replace the unreliable single-pass regex used to
strip HTML tags (incomplete multi-character sanitization) with DOMPurify.
This also fixes a pre-existing mismatch where headings containing HTML
entities produced different anchor ids on the TOC vs renderer sides.

Alert #5 (MarkdownRenderer.tsx): mermaid runs with securityLevel:'strict'
and already sanitizes its own SVG output, so re-running DOMPurify over the
whole SVG broke rendering (namespaces, inline <style>, foreignObject
labels). Make securityLevel explicit and inject mermaid's trusted output
directly, annotated with a codeql suppression comment.

* docs(pages): clarify CodeQL XSS suppression justification in MarkdownRenderer

The suppression comment claimed the mermaid SVG is 'not raw user input',
which understates the trust boundary. The SVG is in fact derived from
user-controlled mermaid code; safety relies on mermaid's securityLevel:
'strict' sanitizing the output via DOMPurify. Update the comment to state
this accurately and flag that the boundary depends on that setting.
2026-07-06 10:31:37 +08:00
kite 1587630604 feat(pages): add per-chapter routes for docs (#294)
Each docs chapter previously lived at the single /docs route driven by
component state, so chapters had no shareable URL and browser back/forward
did not work. Add a /docs/:slug route and derive activeSlug from the URL
param (falling back to quickstart), navigating via the router on switch.

Also add a dev-time invariant that throws when two sidebar entries share a
slug, since each slug now maps to exactly one URL.
2026-07-03 20:29:29 +08:00
kite 44e4867637 docs(pages): sync restructured MCP guide to en and ja (#293)
Sync the reorganized zh/mcp.md into the English and Japanese versions:
remove the MCP client-side paragraph and the How it works section,
split Configuration into Adding/Removing subsections, drop the manual
JSON edit example, move env to the end of the code block and table, and
align dash spacing. Also fix a double-space typo in the zh version.
2026-07-03 20:04:35 +08:00
kite 4596e2ce2e docs(pages): add MCP servers guide to the user guide (#292)
Add an MCP tutorial page (en/zh/ja) covering how OCR acts as an MCP
client that pulls tools from external MCP servers into a review:
configuration via mcp_servers, the config fields, CLI usage, tool
filtering, name conflicts, the setup command, and troubleshooting.

Wire the new page into the docs system (index.ts, DocsPage sidebar,
i18n en/zh/ja) and cross-link from the integrations page to clarify the
client vs server distinction.
2026-07-03 19:03:27 +08:00
kite 5e8099f9e3 docs(pages): remove overview page across all languages and clean up references
- Delete en/zh/ja overview.md
- Remove overview imports, DocSlug entry and doc maps in index.ts
- Drop overview sidebar item and switch default slug to quickstart in DocsPage
- Remove overview-related i18n keys from en/zh/ja
- Sync viewer.md heading emphasis removal to en/ja
2026-07-03 18:00:00 +08:00
kite c9acbcf91b docs(pages): update CLI docs for install, auto-update, config and quickstart (#290)
Refactor installation instructions, update auto-update mechanism
description, streamline configuration and quickstart docs, and adjust
FAQ across en/ja/zh translations.
2026-07-03 17:37:31 +08:00
kite d1ef549e93 docs(README): bump Git prerequisite to >= 2.41 and sync localized READMEs
Bump the Git prerequisite version hint from >= 2.38 to >= 2.41, and add
the Prerequisites section to the ja/ko/ru localized READMEs which were
missing it.
2026-07-03 17:37:00 +08:00
kite 6ded4f3624 docs(pages): remove pipeline and project layout sections from overview (#284) 2026-07-03 14:37:33 +08:00
kite db254dd9c8 docs(pages): add Japanese (ja) translation for docs content (#282)
Translate all 17 docs pages from zh to ja under content/docs/ja/,
translate frontmatter titles, and wire ja into content/docs/index.ts
(replacing the previous English fallback). Sidebar i18n keys already
existed in i18n/ja.ts, so navigation renders Japanese automatically.
2026-07-03 14:23:35 +08:00
kite d83a758a6d docs(pages): update page title to "AI Code Review" 2026-07-02 13:27:50 +08:00
kite 90a926e964 docs(pages): move MCP setup timeout info into field table
Move the 5-minute timeout note from the standalone mcpNote paragraph
into the setup field description in the MCP Server table, so users
see the timeout constraint directly alongside the field definition.
2026-07-02 13:23:17 +08:00
kite 44fabbaa68 docs(pages): update i18n docs for unified Provider system
Update documentation strings across en/ja/zh to reflect the new
provider-based configuration: add full scan review mode, list built-in
providers (Anthropic, OpenAI, DashScope, DeepSeek, Z.AI), and replace
legacy config keys with provider-scoped keys including extraHeaders.
2026-07-01 19:57:03 +08:00
kite 6adcb1ecd4 feat: add standard MCP tool support (#212)
* feat(mcp): add Model Context Protocol server support

Add MCP client and provider packages that allow integrating external
MCP tool servers into the review loop. Includes config commands for
managing MCP servers, stdio subprocess integration tests, and
comprehensive test coverage.

* refactor(mcp): rename loop variable in contentToText to avoid shadowing Client receiver

* fix(mcp): use platform-specific shell for setup command

The MCP server setup command was hardcoded to use `sh -c`, which
fails on Windows. Extract a `shellCommand` helper behind build tags
to use `cmd /c` on Windows and `sh -c` elsewhere.

* docs(mcp): add MCP server documentation to all README locales
2026-07-01 19:10:16 +08:00
kite 2a5c894635 docs(pages): deduplicate scan preview section and add review preview card (#255)
Merge the redundant scan --preview standalone section into its existing
card with richer copy, and add a matching Dry-Run Preview card to the
ocr review advanced usage section. Updates en/zh/ja i18n files.
2026-07-01 16:41:24 +08:00
kite 52a51f86f8 test(diff): add tests for gitignore pattern matching and mode getters 2026-07-01 14:27:07 +08:00
kite be470bb8ee fix(i18n): improve Chinese hero title wording
Remove redundant "经" prefix for a more concise and impactful title.
2026-07-01 13:22:01 +08:00
kite d84d76b6dc fix(session): isolate test sessions to test-sessions subdirectory
Prevent make test from polluting ~/.opencodereview/sessions/ with
thousands of var-folders-* directories by redirecting test session
writes to ~/.opencodereview/test-sessions/.

Introduce a package-level sessionSubDir variable (default "sessions")
and an exported UseTestSessions() function that switches it to
"test-sessions". Each test package that creates sessions calls
UseTestSessions() from init() in an init_test.go file.
2026-06-30 13:23:21 +08:00
kite e3813ceeda docs: add timeout_sec and OCR_LLM_TIMEOUT to configuration reference 2026-06-30 11:29:06 +08:00
kite c076b8e17f docs(llm): clarify timeout override semantics and resolution-path coverage 2026-06-30 11:25:21 +08:00
kite 62972cbcf8 refactor(pages): improve hero terminal display with semantic colors, reorder lines, and add cursor blink
- Reorder terminal lines: move Summary above the separator line
- Change command from range mode (--from/--to) to workspace mode (ocr review)
- Apply semantic color scheme: brand, command, path, success, action, dim
- Remove unused terminal prompt icon and hasIcon field
- Add blinking cursor animation for the last terminal line
- Reduce line number container width after icon removal
2026-06-29 22:52:29 +08:00
kite 403335ef5a docs: add official website link to READMEs and update screenshots
Add official website URL to the "What is Open Code Review?" section
across all localized READMEs. Update highlights and benchmark
screenshots for en/zh, add Japanese versions (highlights-ja.png,
benchmark-ja.png), and add id="highlights" to HighlightsSection
for screenshot tool targeting.
2026-06-29 17:20:39 +08:00
kite 86d474c5d7 feat(i18n): auto-detect browser language for default locale selection
Use navigator.languages to detect the user's preferred language and
automatically select the matching locale (zh/ja/en) on first visit,
falling back to English when no match is found.
2026-06-29 16:43:04 +08:00
kite dc30b81ad6 fix(i18n): correct ocr viewer description from "review results" to "session logs"
The ocr viewer command is a session history viewer, not a results browser.
Updated the description in all three locales (en, zh, ja) to accurately
reflect its purpose.
2026-06-29 16:19:46 +08:00
kite d22bd7fa3d fix(i18n): correct inaccurate translations in zh and ja locales
- zh: navbar.benchmark '排行榜' → '基准测试' to match benchmark section
- zh: footer.copyright fix year placement to follow convention
- zh: docs.configKeyExtraBody '供应商' → '提供商' for terminology consistency
- ja: highlights.stat4Caption add missing particle 'との'
- ja: benchmark.colPrecision '精度' → '適合率' (standard ML term for precision)
2026-06-29 15:15:51 +08:00
kite 0881ad87b8 fix(ci): use --replace-all for git safe.directory to prevent self-hosted runner failure
On self-hosted runners, _github_home/.gitconfig persists across jobs.
The ocr-review workflow used --add which accumulated multiple safe.directory
values over time. Once multiple values existed, other workflows using plain
git config (without --add/--replace-all) failed with "cannot overwrite
multiple values with a single value".

Unify all workflows to use --replace-all, which clears previous values and
writes exactly one entry regardless of prior state.
2026-06-29 11:37:23 +08:00
kite dde66f1dee docs: update OpenSSF badge to Silver level 2026-06-27 11:19:28 +08:00
kite f2a6f7c5c7 ci: add 80% statement coverage threshold check
Add coverage threshold enforcement in CI workflow and Makefile to satisfy
OpenSSF Best Practices Silver badge test_statement_coverage80 criterion.
2026-06-27 11:13:22 +08:00
kite 30c083c0de test: improve coverage for tool package from 79.5% to 93.6%
Add tests for response_message, stub providers, code_search Execute/Tool,
filereader commit mode with and without Runner, file_find git repo modes,
file_read error paths, and comment_collector ReplaceSince edge cases.
2026-06-27 11:00:23 +08:00
kite 793bbc6a61 test: improve coverage for telemetry package and exclude extensions from build targets
Add comprehensive tests for events, metrics, provider, shutdown, span,
and exporter in the telemetry package. Update Makefile to exclude the
extensions directory from test, fmt, vet, and check targets.
2026-06-27 10:43:45 +08:00
kite 9a11fc1302 test: improve coverage for cmd/opencodereview package from 42% to 70%
Add comprehensive unit tests covering config dispatch, emit run result,
git helpers, provider commands, provider TUI pure functions and View
rendering, shared utilities, flags parsing, scan command flags, and
small file entry points (version, viewer, llm, rules commands).
2026-06-27 01:47:48 +08:00
kite 38fc691498 fix: skip permission-based tests when running as root in CI 2026-06-27 00:42:41 +08:00
kite be4b0b0aa9 test: improve coverage for viewer package from 35% to 92%
Add comprehensive tests for handler, server, and store modules including
LoadSession full parsing, template rendering, and error/edge-case paths.
2026-06-27 00:34:12 +08:00
kite 9f71753f68 test: improve coverage for template and pathutil packages
template: 71.2% → 84.9% — add Validate error-branch tests for both
Template and ScanTemplate, ApplyLanguage coverage for optional scan
tasks (DedupTask, ProjectSummaryTask), nil-optional-task path, and
non-system message skip verification.

pathutil: add tests for non-existent path error, relative path
resolution, nested symlink traversal, and additional WithinBase
edge cases.
2026-06-27 00:22:30 +08:00
kite 453c4f9c76 test: add coverage tests for agent, llm, llmloop, and scan packages
Raise statement coverage to 80%+ across four core packages to meet
FLOSS best practice badge criteria. Key additions:

- internal/scan (67% → 90%): getters, lookupDiff, filterScanItems,
  whyExcluded all branches, extFromPath, maybeRunPlan/ProjectSummary/
  Dedup success paths, executeSubtask, Run pipeline, dispatchSubtasks.
- internal/agent (60% → 83%): getters, filterDiffs, findDiff,
  resolveSystemRule, injectDiffMap, executeReviewFilter, executePlanPhase,
  executeSubtask, dispatchSubtasks.
- internal/llmloop (59% → 80%): warnings, tool calls, usage recording,
  compression lifecycle (cancel/tryApply/run/trigger), partitionMessages.
- internal/llm (67% → 80%): parseBpeData, embedded BPE loader, message
  constructors, ExtractText, ChatResponse helpers, parseShellRC.
2026-06-27 00:15:28 +08:00
kite 110e5284fb fix: stabilize TestDiscoverRepos_FindsRepos with explicit mtime ordering
The test relied on filesystem ModTime for sorting repos, but files
created in rapid succession can share the same mtime on CI, making
the sort order non-deterministic. Use os.Chtimes to guarantee repo-b
has a strictly later mtime than repo-a.
2026-06-26 23:31:51 +08:00
kite b3eb4b3491 test: add unit tests for output_helpers, config, model, stdout, and telemetry packages 2026-06-26 23:26:49 +08:00
kite 5bd291739d chore: remove unused cmd/testdiff debug helper
The testdiff CLI was an early-stage tool for manually testing the
internal/diff package. It has no external references and its role is
fully covered by the existing unit tests in internal/diff/.
2026-06-26 23:19:22 +08:00
kite 904ecd3ae1 test: expand unit test coverage for agent, llm, llmloop, and tool packages
Add integration-style tests with fake LLM clients for agent dispatch and
llmloop runner, plus new unit test files for gitcmd, session/history,
tool/code_comment, tool/filereader_read, and viewer/store packages.
2026-06-26 23:09:11 +08:00
kite 98fe309f03 test: add unit tests for pure logic functions across 6 packages
Add table-driven tests for pure computation functions with no external
dependencies, improving overall coverage from 45.9% to 48.8%.

Covered functions:
- suggestdiff: ComputeLineDiff (LCS algorithm)
- tool: CommentCollector, DiffMap, FileReadDiff, Registry, ParseReviewMode, scanLines
- llmloop: CountMessagesTokens, groupIntoRounds, partitionMessages, StripMarkdownFences
- agent: buildFilterCommentsJSON, parseFilterResponse, extFromPath, formatToolDefs, BuildToolDefs
- viewer: truncateText, formatDuration, formatTime
2026-06-26 22:41:35 +08:00
kite e1a6a404ba feat(ci): add Sigstore attestation for release artifacts
Add build provenance attestation to the release workflow using
actions/attest-build-provenance with OIDC keyless signing.
Document release signature verification in SECURITY.md.
2026-06-26 22:18:03 +08:00
kite b3b4f238a3 docs: add security assurance case and use signed tags
Add ASSURANCE_CASE.md covering threat model, secure design principles
(Saltzer & Schroeder), OWASP/CWE countermeasures, and automated
verification. Switch tag command from annotated (-a) to signed (-s) to
match the assurance case's integrity claims.
2026-06-26 21:30:57 +08:00
kite 3f4155170e ci: add govulncheck, job timeout, dependabot and preserve debug symbols in dev builds
- Add govulncheck step to CI pipeline for vulnerability scanning
- Set 15-minute timeout on CI test job
- Add dependabot config for weekly Go module and GitHub Actions updates
- Split LD_FLAGS so dev builds retain debug symbols while release
  builds remain stripped with -s -w
2026-06-26 21:02:33 +08:00
kite 8a987d3d29 docs: add ROADMAP.md with project direction for the next year
Cover planned work (JetBrains plugin, standard MCP integration,
Ultra mode, domain-specific long-term memory) and explicit non-goals.
Satisfies the OpenSSF Best Practices silver badge documentation_roadmap
criterion.
2026-06-26 20:02:04 +08:00
kite 410cabf488 docs: add GOVERNANCE.md, CODE_OF_CONDUCT.md and clean up SECURITY.md
- Rewrite GOVERNANCE.md with expanded structure: goals, scope, project
  values, detailed roles, decision-making process, merge expectations,
  maintainer lifecycle, and continuity sections.
- Add CODE_OF_CONDUCT.md covering expected behavior, unacceptable
  behavior, scope, reporting, and enforcement.
- Remove fictitious email address from SECURITY.md, keeping only
  GitHub Private Vulnerability Reporting as the reporting channel.
2026-06-26 19:38:37 +08:00
kite c8ff673667 feat: add Cursor plugin support (#221)
Add .cursor-plugin/plugin.json manifest alongside existing Claude Code
and Codex plugin integrations, reusing the shared SKILL.md. Update all
README versions (EN, zh-CN, ja-JP, ko-KR, ru-RU) with Cursor badge and
installation instructions.
2026-06-26 10:35:02 +08:00
kite 779c4a8290 fix: enable code_search to find content in untracked files
git grep defaults to searching only tracked files, causing code_search
to miss untracked directories like internal/mcp/. Add --untracked flag
in workspace mode so both tracked and untracked files are searched.

Also fix non-git-directory detection to use exit code 128 instead of
hardcoded English error string, making it locale-independent.
2026-06-26 00:01:44 +08:00
kite d939b327cf docs: rewrite LLM config section to use provider-based setup
Replace the legacy manual `llm.*` configuration with the modern provider
system across all README localizations (en, zh-CN, ja-JP, ko-KR, ru-RU).
The new structure introduces interactive setup for humans and CLI-based
`ocr config set` commands for CI/CD, covering both built-in and custom
providers.
2026-06-25 21:32:58 +08:00
kite 034d512b15 fix: increase REVIEW_FILTER_TASK and RE_LOCATION_TASK timeout from 60s to 180s (#208) (#218)
Slow local models often cannot complete these sub-tasks within the
hardcoded 60-second limit, causing timeouts that the user-provided
--timeout flag cannot override. Raise both to 180s in task_template.json
and scan_template.json to give local models sufficient time.
2026-06-25 20:07:07 +08:00
kite 63b0f02d27 feat: add tool_calls field to JSON output (#216)
* feat: add tool_calls field to JSON output for tool usage statistics

Track per-tool invocation counts in llmloop.Runner and expose them
through the ResultProvider interface so both review and scan modes
report tool call statistics in --format json output.

* fix: correct tool_calls counting and ensure stable JSON schema

Move recordToolCall after lookupTool nil check so only actually-executed
tool calls are counted. Always emit tool_calls field in JSON output for
a consistent schema, initializing by_tool to empty map when nil.

* fix: remove omitempty from tool_calls to ensure stable JSON schema

Drop omitempty from the tool_calls struct tag and initialize ToolCalls
in outputJSONNoFiles so the field is always present in JSON output
regardless of execution path.
2026-06-25 13:53:06 +08:00
kite ce11f374fd docs: sync ocr scan documentation to localized READMEs
Commit 18797f8 added the ocr scan feature but only updated the English
README. This syncs all six categories of changes (intro paragraph, quick
start examples, commands table, --exclude flag, ocr scan flags section,
and scan usage examples) to zh-CN, ja-JP, ko-KR, and ru-RU.
2026-06-24 22:18:28 +08:00
kite 4a2370f9cd fix: make option-like ref test locale-independent
Replace English git error message matching with a locale-agnostic
"Error:" prefix check to fix test failures on non-English systems.
2026-06-24 21:19:06 +08:00
kite 71b3353153 fix: skip empty rule entries in resolver to restore fallback behavior
PR #161 refactored matchProjectRule into matchProjectRuleEntry but
removed the empty-rule guard, causing entries with rule:"" to match
and return an empty string instead of falling through to the next
layer or system rule. This restores the skip-on-empty semantics while
honoring merge_system_rule:true with empty rule as "lock system rule".
2026-06-24 18:59:18 +08:00
kite fa030d4a1a bench: add GLM-5.2 (Zhipu AI) benchmark results and update screenshots 2026-06-24 15:46:46 +08:00
kite 7715639bd8 docs: sync config unset command to localized READMEs
Commit 9d2800f added `ocr config unset custom_providers.<name>`
documentation to README.md but missed the four localized copies.
Add the command table row and usage example to zh-CN, ja-JP, ko-KR,
and ru-RU READMEs.
2026-06-23 21:27:09 +08:00
kite bb0cf901ed chore: reduce default update check interval from 30 to 18 minutes 2026-06-23 21:08:55 +08:00
kite bad29fc9b9 fix: normalize repository.url with git+ prefix to suppress npm publish warnings 2026-06-23 20:29:45 +08:00
kite 757b359673 fix(ci): use bash shell for release notes generation step
The ubuntu:24.04 container defaults to sh (dash) which does not support
process substitution (< <(...)). Add shell: bash to the step.
2026-06-23 20:09:43 +08:00
kite a86389c5e5 fix(ci): install git in release job container to fix workflow failure
The release job uses ubuntu:24.04 which lacks git. After adding
commit-based release notes generation, git commands (config/describe/log)
fail with "git: not found". Install git before checkout so the full
history is available for release notes.
2026-06-23 19:57:09 +08:00
kite c69108656b feat: switch auto-update to npm i -g and show update hints on failure
Replace GitHub releases download with `npm i -g` so platform package
installations also get auto-updates. On permission failure, write a hint
file that bin/ocr.js reads to prompt the user to update manually.
2026-06-23 19:09:44 +08:00
kite ca3b03dfc9 fix(vscode): upgrade minimatch to 9.0.9 to resolve CVE-2026-27903 ReDoS vulnerability 2026-06-23 16:30:19 +08:00
kite 82d3f7700a docs(README): add platform and agent support badges to all README variants 2026-06-23 16:08:02 +08:00
kiteandgithub-actions[bot] dc4bf69854 feat(vscode): add VSCode extension for AI code review with security fixes
Add VSCode extension providing sidebar-based AI code review integration,
including CLI/Git/Config services, webview UI with file diff viewer,
inline comment provider, and comprehensive test coverage.

Fix 9 Dependabot security vulnerabilities by adding yarn resolutions
for undici, form-data, js-yaml, and minimatch.

Co-authored-by: lizhengfeng <lizhengfeng.lzf@alibaba-inc.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-23 14:33:31 +08:00
kite 97de26e027 docs(README): add OpenSSF Best Practices badge to all README variants 2026-06-22 19:18:40 +08:00
kite bc225682f1 docs(README): replace % symbol with words in benchmark metric descriptions
Use "Proportion" (EN) and "Доля" (RU) instead of the bare "%" symbol
for consistency with the Chinese, Japanese, and Korean translations
which already use their respective words for "proportion".
2026-06-22 18:55:12 +08:00
kite dc93166205 feat(rules): add dedicated review rules for GitHub Actions and GitHub config YAML
The generic YAML rule only checked spelling in keys, which is insufficient
for CI/CD workflow files. Add layered rules with security, correctness,
reliability checks for .github/workflows/ and structure validation for
other .github/ config files (issue templates, release config).
2026-06-22 17:59:16 +08:00