Open Code Review
Audited from github.com/alibaba/open-code-review
Open Code Review is Alibaba's open-source AI code review CLI. It reads Git diffs, runs a deterministic pipeline plus a tool-using LLM agent, and produces line-level review comments for terminals, CI systems, IDEs and coding agents.
- Language
- Go
- License
- Apache-2.0
- Running for
- 4 months
- Team
- 20+ people
Why this architecture
A single static Go binary keeps the review engine fast and easy to distribute through npm, CI and IDE plugins. Putting deterministic diff/context analysis before a narrow LLM loop keeps reviews precise and cheap in tokens compared with general-purpose agents.
Tech stack by layer
12 technologies · audited Sep 25, 2026- ReactLanding and docs site in pages/ (React 18, webpack, three.js, mermaid)
- TypeScriptVS Code extension, Preact-based review webview (extensions/frontend) and OpenCode plugin
- KotlinJetBrains IDE plugin under extensions/idea
- GoThe ocr CLI and review engine (cmd/opencodereview, internal/*), built as static CGO-free binaries
- CobraCommand tree and flags for the ocr CLI (review, scan and related subcommands)
- Bubble TeaTerminal UI for interactive review sessions, with Bubbles and Lip Gloss components
- Node.jsnpm launcher (bin/ocr.js) that installs the matching per-platform Go binary on postinstall
- OpenTelemetryTraces and metrics exported over OTLP gRPC/HTTP from internal/telemetry
- GitHub ActionsCI, CodeQL, releases, IDE extension builds and a reusable review Action (action.yml)
- OpenAIopenai-go client for OpenAI-compatible model endpoints used by the review agent loop
- Anthropic SDKanthropic-sdk-go client for Claude models, with AWS SDK config for Bedrock-style credentials
- Model Context ProtocolMCP Go SDK in internal/mcp lets agents such as Claude Code or Cursor call the reviewer as a tool
- tiktoken-goToken counting to budget how much diff and file context is sent to the model
Open Code Review architecture diagram
Open SVGDiagram as text
- ocr CLI (Go · Bubble Tea TUI) → Review engine (deterministic pipeline): review · scan
- IDE plugins (VS Code · JetBrains) → Review engine (deterministic pipeline): reviews
- Coding agents (MCP · GitHub Action) → Review engine (deterministic pipeline): MCP tool
- Review engine (deterministic pipeline) → Review agent loop (tiktoken budget): findings
- Review agent loop (tiktoken budget) → LLM providers (OpenAI · Anthropic · Bedrock): prompts
- Review engine (deterministic pipeline) → OpenTelemetry (OTLP): traces
Key architectural decisions
5 decisions- 01
Deterministic pipeline first, LLM agent second
internal/diff, internal/gitcmd and internal/scan compute the change set and context deterministically before internal/agent and internal/llmloop run a tool-using review loop, which the README says trades some recall for higher precision and fewer tokens.
- 02
One Go binary distributed through npm optional dependencies
The root package.json lists @alibaba-group/ocr-<os>-<arch> packages under npm/ as optionalDependencies, and bin/ocr.js plus scripts/install.js pick the right CGO_ENABLED=0 binary built by the Makefile for six OS/arch targets.
- 03
Provider-agnostic LLM layer with official SDKs
internal/llm wraps both openai-go and anthropic-sdk-go, and the AWS SDK config is included for credential resolution, so teams point the reviewer at any OpenAI-compatible or Anthropic endpoint.
- 04
Same engine exposed to CI, IDEs and coding agents
action.yml and examples/ cover GitHub Actions, GitLab CI, Bitbucket, Gerrit and Codeup; extensions/ ships VS Code and JetBrains plugins; skills/, .claude-plugin and plugins/open-code-review package it for Claude Code, Kimi and OpenCode.
- 05
Docs site isolated as its own Go module
pages/go.mod exists only so go list ./... in the root module never walks into pages/node_modules, keeping go test, vet, govulncheck and the coverage gate clean without per-command filters.
How Open Code Review is built
How Open Code Review is structured
The root is one Go module (go.mod, Go 1.25) with a single entry point, cmd/opencodereview, and the engine under internal/:
| Package | Responsibility |
|---|---|
internal/gitcmd, internal/diff |
Read Git state and compute the reviewable diff |
internal/scan |
Whole-file review for ocr scan when no diff exists |
internal/agent, internal/llmloop |
Tool-using review agent loop |
internal/llm, internal/model |
Provider clients and model configuration |
internal/tool, internal/delegate |
Tools the agent can call and delegation to sub-reviews |
internal/suggestdiff |
Turns findings into suggested patches |
internal/mcp |
Model Context Protocol server |
internal/session, internal/viewer, internal/stdout |
Session state and output rendering |
internal/telemetry |
OpenTelemetry setup |
Everything else in the repository wraps that engine: the npm launcher (bin/ocr.js, npm/*), IDE extensions (extensions/vscode, extensions/idea, extensions/frontend), agent packaging (skills/, plugins/, .claude-plugin/, .kimi-plugin/), CI examples (examples/) and the docs site (pages/).
Backend & APIs
The CLI uses Cobra (opens in a new tab) and pflag for commands and Bubble Tea (opens in a new tab) v2 with Bubbles and Lip Gloss for its terminal UI. Model access goes through openai-go and anthropic-sdk-go. aws-sdk-go-v2/config is also a direct dependency, for AWS-style credential resolution. tiktoken-go counts tokens so the agent can budget its context, and doublestar handles glob-based include and exclude rules such as those in .opencodereview/rule.json.
The Model Context Protocol Go SDK in internal/mcp lets other agents call the reviewer as a tool rather than shelling out.
Frontend
The product is CLI-first, but the repository contains three UI surfaces:
extensions/vscode: a VS Code extension with an activity-bar webview and commands to start or cancel reviews and apply, discard or mark comments as false positives.extensions/frontend: the webview UI, written in Preact and bundled with webpack, tested with Jest.extensions/idea: a JetBrains plugin, which accounts for the Kotlin share in the language stats.
pages/ is a separate landing and docs site built with React 18, React Router, three, mermaid and marked/dompurify, bundled with webpack under a 150 kB size-limit budget.
Data & persistence
There is no database. Inputs are the local Git repository and a configuration file. Review sessions are handled in-process by internal/session. Telemetry leaves the process only through the configured OTLP exporters.
Build, test & deploy
- The
Makefilebuildsopencodereviewfor Linux, macOS and Windows on amd64 and arm64 withCGO_ENABLED=0and-s -wldflags, injecting the version, commit and build date. - Extra make targets check license headers (
scripts/verify-license.sh) and English-only sources (scripts/verify-english-only.go). - GitHub Actions workflows include
ci.yml,codeql.yml,release.yml,vscode-ext.yml,idea-ext.yml,frontend-ext.yml,deploy-pages.yml,plugin-contract.yml,action-contract.yml,translation-sync.yml, andocr-review.yml, in which the project reviews its own pull requests. scripts/verify-action-pins.shchecks that third-party Actions are pinned. The README shows an OpenSSF Best Practices badge.
Self-hosting notes
Install with npm i -g @alibaba-group/open-code-review, or with install.sh / install.ps1, then configure a model endpoint. The npm package contains only a launcher. postinstall fetches the platform binary through scripts/install.js, which verifies the release's sha256sum.txt.
What to copy (and what not to)
What to copy
- Shipping a Go binary through npm
optionalDependenciesper OS/arch. Users getnpm i -gconvenience with native performance. - A separate
go.modin a docs subfolder so Go tooling ignores that folder'snode_modules. - Having the tool review its own pull requests in CI (
ocr-review.yml), which exercises the tool on every change.
What not to copy
- Maintaining VS Code, JetBrains, Preact webview, OpenCode, Claude and Kimi integrations in one repository multiplies release workflows. Smaller tools can start with the CLI and an MCP server only.
- Two separate frontend toolchains (webpack + Babel for
pages/, webpack + ts-loader for the extension webview) could be consolidated.
Sources & repo audit
- Audited
- Sep 25, 2026
- Commit
- 486022d
- License
- Apache-2.0
- go.mod (Cobra, Bubble Tea, OpenAI/Anthropic SDKs, MCP, OpenTelemetry)
- Makefile (cross-platform static builds)
- package.json (npm launcher and platform binaries)
- action.yml (GitHub Action)
Independent analysis of repository at github.com/alibaba/open-code-review. Spotted an inaccuracy? Use the claim form to request a correction.
Maintainer? Add the architecture badge to your README
[](https://stackitfast.com/project/open-code-review) Scaffold it with your agent
Paste this prompt into Claude Code, Cursor, Windsurf or AGY to start a project with Open Code Review's architecture.
- 1Copy the promptThe full markdown spec, with every layer and decision.
- 2Open your AI toolClaude Code, Cursor, Windsurf or Copilot, in a new repo.
- 3Paste and scaffoldUse it as the first instruction; review before you ship.
# MISSION: Scaffold "Open Code Review" Production Architecture
You are an expert Senior Staff Software Architect and Full-Stack Engineer. Your mission is to scaffold and implement a production-grade, highly reliable, and modular codebase following the proven architecture of **Open Code Review**.
---
## 1. PROJECT SPECIFICATIONS & BENCHMARK
- **Reference Architecture**: Open Code Review
- **What It Does**: Open Code Review is Alibaba's open-source AI code review CLI. It reads Git diffs, runs a deterministic pipeline plus a tool-using LLM agent, and produces line-level review comments for terminals, CI systems, IDEs and coding agents.
- **Domain & Category**: Hybrid Deterministic + LLM Agent Code Review Tool
- **Production Scale**: 20+ people
- **Development Mode**: HYBRID
- **Architectural Rationale**: A single static Go binary keeps the review engine fast and easy to distribute through npm, CI and IDE plugins. Putting deterministic diff/context analysis before a narrow LLM loop keeps reviews precise and cheap in tokens compared with general-purpose agents.
- **Live Website Reference**: https://open-codereview.ai
- **Source Repository**: https://github.com/alibaba/open-code-review
---
## 2. PRODUCTION TECH STACK
- **Full Stack Array**: Go, Cobra, Bubble Tea, OpenAI, Anthropic, Model Context Protocol, OpenTelemetry, Node.js, TypeScript, React, Kotlin, GitHub Actions
- **Primary Language(s)**: Go, JavaScript, TypeScript, Kotlin, CSS
- **License of the reference repo**: Apache-2.0
- **Frontend**: React — Landing and docs site in pages/ (React 18, webpack, three.js, mermaid); TypeScript — VS Code extension, Preact-based review webview (extensions/frontend) and OpenCode plugin; Kotlin — JetBrains IDE plugin under extensions/idea
- **Backend & APIs**: Go — The ocr CLI and review engine (cmd/opencodereview, internal/*), built as static CGO-free binaries; Cobra — Command tree and flags for the ocr CLI (review, scan and related subcommands); Bubble Tea — Terminal UI for interactive review sessions, with Bubbles and Lip Gloss components
- **Infrastructure & deploy**: Node.js — npm launcher (bin/ocr.js) that installs the matching per-platform Go binary on postinstall; OpenTelemetry — Traces and metrics exported over OTLP gRPC/HTTP from internal/telemetry; GitHub Actions — CI, CodeQL, releases, IDE extension builds and a reusable review Action (action.yml)
- **Tooling, testing & ops**: OpenAI — openai-go client for OpenAI-compatible model endpoints used by the review agent loop; Anthropic SDK — anthropic-sdk-go client for Claude models, with AWS SDK config for Bedrock-style credentials; Model Context Protocol — MCP Go SDK in internal/mcp lets agents such as Claude Code or Cursor call the reviewer as a tool; tiktoken-go — Token counting to budget how much diff and file context is sent to the model
---
## 3. KEY ARCHITECTURAL DECISIONS (audited from https://github.com/alibaba/open-code-review @ 486022d)
1. **Deterministic pipeline first, LLM agent second**: internal/diff, internal/gitcmd and internal/scan compute the change set and context deterministically before internal/agent and internal/llmloop run a tool-using review loop, which the README says trades some recall for higher precision and fewer tokens.
2. **One Go binary distributed through npm optional dependencies**: The root package.json lists @alibaba-group/ocr-<os>-<arch> packages under npm/ as optionalDependencies, and bin/ocr.js plus scripts/install.js pick the right CGO_ENABLED=0 binary built by the Makefile for six OS/arch targets.
3. **Provider-agnostic LLM layer with official SDKs**: internal/llm wraps both openai-go and anthropic-sdk-go, and the AWS SDK config is included for credential resolution, so teams point the reviewer at any OpenAI-compatible or Anthropic endpoint.
4. **Same engine exposed to CI, IDEs and coding agents**: action.yml and examples/ cover GitHub Actions, GitLab CI, Bitbucket, Gerrit and Codeup; extensions/ ships VS Code and JetBrains plugins; skills/, .claude-plugin and plugins/open-code-review package it for Claude Code, Kimi and OpenCode.
5. **Docs site isolated as its own Go module**: pages/go.mod exists only so go list ./... in the root module never walks into pages/node_modules, keeping go test, vet, govulncheck and the coverage gate clean without per-command filters.
---
## 4. NON-NEGOTIABLE ARCHITECTURAL GUARDRAILS
1. **Monorepo & Modular Separation**:
- Structure as a Turborepo monorepo with strict package boundaries:
- `apps/web`: Application UI, routing, layouts, and server endpoints.
- `packages/ui`: Shared design tokens, CSS variables, and Radix UI primitive components.
- `packages/db`: Database schemas, client singleton, declarative migrations, and seed scripts.
- `packages/config`: Shared TypeScript, ESLint, and build configurations.
2. **Strict Type Safety & Zero `any` Policy**:
- Enable `strict: true`, `noImplicitAny: true`, and `strictNullChecks: true`.
- Validate ALL external inputs, API request bodies, and query parameters with **Zod** schemas before execution.
3. **Frontend & Rendering Guidelines**:
- Isolate interactive UI state to leaf components. Keep core pages lightweight and performant.
4. **Design System & Aesthetics**:
- Keep every color, radius, shadow and font in a single token file (CSS variables) and consume tokens everywhere; never hardcode hex values in components.
- Prefer crisp 1px borders and one subtle shadow scale over blurry default shadows. Pair one sans-serif for body/headings with one monospace for tags, badges, metrics, and code.
5. **Data Layer & Reliability**:
- Write declarative schema definitions with foreign keys, composite indexes on queried filters, and automated timestamp triggers.
- Use connection pooling and prepared statements for serverless database execution.
---
## 5. STEP-BY-STEP SCAFFOLDING ROADMAP
- **Phase 1: Workspace & Root Config**: Initialize package manager, monorepo configuration (`turbo.json`, `tsconfig.base.json`, `package.json`).
- **Phase 2: Database Schema & Client**: Set up the data layer: client, connection pool, models, and migration scripts.
- **Phase 3: Design Tokens & UI Primitives**: Build accessible `Button`, `Input`, `Card`, `Badge`, and layout wrappers inside `packages/ui`.
- **Phase 4: Core Application Routes & Handlers**: Implement primary authentication, user session handling, and application routes.
- **Phase 5: Quality Assurance & Build Verification**: Run `tsc --noEmit`, ESLint, Prettier, and smoke test suites to ensure zero compilation or runtime errors.
---
## 6. EXECUTION INSTRUCTIONS
1. Review all specifications, architectural guardrails, and stack choices above.
2. Present the full monorepo directory tree structure.
3. Systematically generate the complete, production-ready codebase according to the 5-phase roadmap above — starting with the root workspace setup, followed by the database schema, UI design system package, and full-stack application routes until the repository is fully scaffolded and ready to run.Frequently asked about Open Code Review
What is Open Code Review built with?
Open Code Review is a Go CLI built with Cobra and Bubble Tea. It calls models through the official OpenAI and Anthropic Go SDKs, exposes an MCP server, exports OpenTelemetry traces, and ships through npm as per-platform static binaries. IDE plugins use TypeScript and Kotlin.
How does Open Code Review differ from asking a general coding agent to review code?
It runs a deterministic diff and context pipeline before a focused LLM review loop. Its README reports higher precision and far lower token usage than a general-purpose agent on the same model, with lower recall as a deliberate trade-off.
Can I run Open Code Review in CI?
Yes. The repository ships a GitHub Action (action.yml) and example configurations for GitLab CI, Bitbucket Pipelines, Gerrit and Codeup under examples/, which post line-level review comments.
Which models does Open Code Review support?
Any OpenAI-compatible endpoint through openai-go and Anthropic models through anthropic-sdk-go. The user configures a model endpoint and key, and no specific vendor is required.
One email a month: new deep dives and stack trends
New source-audited architectures, head-to-head comparisons and the monthly stack report. No spam, unsubscribe anytime.
Similar architectures
- PocketBaseClassicEmbedded Backend · SoloShares Go
- GotifyClassicSelf-Hosted Real-Time Push Server · 2-5 PeopleShares Go · TypeScript · React
- GiteaClassicLightweight Self-Hosted Git Service · 20+ peopleShares Go · TypeScript
- tRPCHybridEnd-to-End Typesafe API Framework · 1M+ MAUShares TypeScript · React · Node.js
- Cosmo (WunderGraph)HybridFederated GraphQL API Gateway · 6-20 PeopleShares TypeScript · Go
- Next.jsHybridFullstack React Framework · 1M+ MAUShares TypeScript · React · Node.js