
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
open-code-review-alibaba
Advanced tools
AI-powered code review tool that reads Git diffs, sends changed files to a configurable LLM via OpenAI-compatible API, and generates structured review comments. It goes beyond surface-level analysis — the Agent can read project context for deep reviews.
npm install -g @alibaba/open-code-review
After installation, the ocr command is available globally.
# Install specific version
OCR_VERSION=v1.0.0 npm install -g @alibaba/open-code-review
You must configure an LLM provider before using ocr. The tool requires access to an OpenAI-compatible API endpoint (OpenAI, Claude, local models, etc.).
ocr config set llm.url https://api.anthropic.com/v1/messages \
&& ocr config set llm.auth_token {{your-api-key}} \
&& ocr config set llm.model claude-opus-4-6 \
&& ocr config set llm.use_anthropic true \
&& ocr config set language Chinese
Config is stored in ~/.open-code-review/config.json.
Or via environment variables:
export OCR_LLM_URL=https://api.anthropic.com/v1/messages
export OCR_LLM_TOKEN=your-api-key
export OCR_LLM_MODEL=claude-opus-4-6
ocr llm test
Navigate to any Git repository and run:
# Review all workspace changes
ocr review
# Review diff between two branches
ocr review --from main --to feature-branch
# Review a single commit
ocr review --commit abc123
| Command | Description |
|---|---|
ocr review / ocr r | Start code review |
ocr config set <key> <value> | Manage configuration |
ocr llm test | Test LLM connectivity |
ocr viewer | Start WebUI session viewer |
ocr version | Show version info |
| Flag | Shorthand | Default | Description |
|---|---|---|---|
--repo | current dir | Git repository root | |
--from | Source ref (e.g., main) | ||
--to | Target ref (e.g., feature-branch) | ||
--commit | -c | Review a single commit | |
--format | -f | text | Output format: text or json |
--concurrency | 4 | Max concurrent file reviews | |
--timeout | 10 | Per-file timeout (minutes) |
git grep, inspects diffsApache-2.0
FAQs
OpenCodeReview CLI — AI-powered code review tool
The npm package open-code-review-alibaba receives a total of 3 weekly downloads. As such, open-code-review-alibaba popularity was classified as not popular.
We found that open-code-review-alibaba demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.