Application method of DevOps pipeline business code audit

By using the DevOps pipeline business code auditing system and leveraging the LLM model for automated code auditing, the problem of low efficiency in traditional manual review has been solved, achieving efficient and low-cost code quality management.

CN120315987BActive Publication Date: 2025-10-24SHENZHEN YOURONG INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510811791.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-10-24
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

Traditional code auditing processes rely on manual review, resulting in low efficiency, high costs, and quality that depends on the experience of the reviewers, making it impossible to address code quality issues in a timely manner.

Method used

We adopt a DevOps pipeline business code auditing system, which includes a code repository unit, a design management unit, an LLM code auditing unit, and an auditing support unit. We use the LLM model to automate code auditing, generate modification suggestions, and iteratively optimize the system through a rules engine.

Benefits of technology

It improves code auditing efficiency and quality, reduces labor costs, and allows developers to directly mark issues and suggestions through the LLM auditing module, improving the efficiency of developer confirmation and assisting auditing engineers in quickly processing modification suggestions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120315987B_ABST
    Figure CN120315987B_ABST
Patent Text Reader

Abstract

The application discloses an application method of DevOps pipeline business code auditing, belongs to the technical field of business code auditing, and comprises a code auditing system composed of a code warehouse unit, a design management unit, an LLM code auditing unit and an auditing auxiliary unit, wherein the design management unit is composed of a design management module and a rule engine. In the code architecture process, the application is combined based on the LLM model and the rule engine, the code auditing efficiency and the auditing quality can be greatly improved, in the auditing process, the auditing code efficiency and the auditing quality can be improved through the agent auditing of the LLM auditing module, the auditing labor cost and the time cost are greatly reduced, the problems and the modification suggestions of the code are directly marked on specific code lines or code blocks through the LLM code auditing unit, the developer can confirm and complete the problem corresponding to the modification suggestion by referring to the modification suggestion step by step, and the problem solving efficiency is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of business code auditing, and particularly relates to an application method of DevOps pipeline business code auditing. BACKGROUND

[0002] In the project development process, in order to ensure the quality, the code developed by the development engineer needs to be audited, so as to trigger subsequent compilation, packaging, automatic testing and other tasks. The traditional core process of code auditing in DevOps at present is as follows:

[0003] 1. The developer completes program coding according to the design, self-checks and tests, and then submits the code to the Git warehouse;

[0004] 2. The developer initiates a code merging request;

[0005] 3. The code is scanned by a retrieval tool to ensure that it meets the specifications and has no security vulnerabilities;

[0006] 4. After the tool inspection, the code is assigned to an experienced engineer who understands the design to review the logic, specification, extensibility, readability, complexity and the like of the code according to the design;

[0007] 5. If problems are found, comments are made in the MR and sent back to the developer for modification; until all problems are solved, the MR is agreed, and subsequent tasks are triggered.

[0008] The above traditional code auditing process mainly relies on manual auditing, and in the manual auditing process, the manual transfer efficiency is low, the cost is high; and the auditing effect and quality completely depend on the ability level and working meticulousness of the code auditing personnel, and the auditing experience of the code auditing personnel is required to be high, so that the code quality cannot be audited in time. SUMMARY

[0009] The purpose of the present application is to solve the problem that the traditional code auditing process mainly relies on manual auditing, the manual code auditing process has low manual transfer efficiency and high cost, and the code auditing personnel needs to have high auditing experience, resulting in that the code quality cannot be audited in time, and the application method of DevOps pipeline business code auditing is proposed.

[0010] In order to achieve the above purpose, the present application adopts the following technical scheme:

[0011] The application method of DevOps pipeline business code audit includes a code audit system composed of a code repository unit, a design management unit, an LLM code audit unit and an audit auxiliary unit. The code repository unit is a personal end code repository generated based on a Git code project. The design management unit is composed of a design management module and a rule engine. The LLM code audit unit is composed of a prompt word construction module, an LLM audit module and a code audit result construction module. The audit auxiliary unit is composed of an audit engineer intervention processing module and a suggestion audit module.

[0012] The specific steps of the code audit method in the code audit system are as follows:

[0013] S1: Generate code architecture rules. In the project creation stage, generate code architecture specification rules according to the framework and service version of the Git code project;

[0014] S2: Code merge request. In the code repository unit, the personal end sends the code for merging request to the LLM code audit unit;

[0015] S3: Proxy audit. In the LLM code audit unit, the code for merging request is audited and comments and modification suggestions are provided for the contents not meeting the code architecture rules;

[0016] S4: Upgrade iteration. When there is a difference between the modification made by the personal end and the modification suggestion provided by the LLM code audit unit, the modification is approved through the audit auxiliary unit, the modification result is recorded in the rule engine, the code architecture rules in the rule engine are modified, and the code audit system is upgraded and iterated.

[0017] Preferably, in step S1, the code architecture rules are generated based on the COLA framework in the Git code project, and the rule engine is the storage and call of the code architecture rules.

[0018] Preferably, in step S2, before the personal end of the code repository unit sends the code merge request, the code is audited by the personal end through coding and self-checking, and the uncertain code branches are sent to the LLM code audit unit.

[0019] Preferably, in step S3, the specific steps of the LLM code audit unit for auditing the code for merging request are as follows:

[0020] S31: Generate audit prompt words. The prompt word construction module analyzes the modification feature set of the code based on the LLM model, loads the code audit rules corresponding to each modification feature from the rule engine according to the modification, organizes a complete rule list, generates the audit prompt word text of this time based on the preset code audit prompt word template, and combines the code fragment and the code audit rule list;

[0021] S32: generating an audit result, the LLM audit module generates a prompt word according to the prompt word generated by the prompt word construction module, calls an LLM model to complete code auditing, and some LLM models will adopt a split context multi-round dialogue mode to complete the auditing due to the input length limitation;

[0022] S33: extracting and labeling the result, the code audit result construction module extracts the code variable, line number, problem and modification suggestion of each code segment from the generated audit result, and calls the API interface of the Git repository to label the result to the code.

[0023] Preferably, in step S32, the specific steps of generating code modification suggestions by the LLM audit module are as follows:

[0024] First step: classifying code problems, in the auditing process of the LLM audit module, the characteristics of code problems are recognized and classified by analyzing the code audit result;

[0025] Second step: generating a code modification suggestion tree, reading each audit problem of each code segment from the rule engine to generate a code modification suggestion tree;

[0026] Third step: generating targeted code modification suggestions, the LLM audit module generates modification suggestion prompt text in combination with the code modification suggestion tree, and generates targeted code modification suggestions by the LLM model.

[0027] Preferably, in step S4, the basis for the intervention of the review engineer intervention processing module is the difference between the personal end modification and the modification suggestion provided by the LLM code audit unit, and after the review engineer approves the personal end modification, the code architecture rules stored in the rule engine are corrected, and after the review engineer approves the personal end modification, the personal end modification result is saved to the error result set area of the rule engine.

[0028] Preferably, the suggestion review module is used to assist the review engineer intervention processing module to make further intervention judgment, and the suggestion review module upgrades the modification suggestion to a modification execution instruction when it is determined that the personal end modification and the modification suggestion provided by the LLM code audit unit exist difference, and the personal end modification result in the error result set area is the same, and forces the personal end to make modification in accordance with the code architecture rules;

[0029] The suggestion review module downgrades the modification suggestion to a modifiable suggestion when it is determined that the personal end modification suggestion and the personal end modification result in the error result set area are different, and waits for the review engineer to intervene in the review and reclassify the modification suggestion.

[0030] Preferably, in the suggestion review module, after the review engineer intervenes in the review, the modification suggestion can be cancelled, at which time the individual end providing the modification result suggestion is marked with a high level, and when the modification suggestion is converted into a modification execution instruction, the individual end not complying with the modification suggestion is marked with a low level, so that the personnel in the design management unit can timely understand the modification of the individual end.

[0031] Compared with the prior art, the beneficial effects of the present application are:

[0032] 1. In the code architecture process, the LLM model and the rule engine are combined and applied, which can greatly improve the code auditing efficiency and auditing quality, and through the agent auditing of the LLM auditing module in the auditing process, the code auditing efficiency and auditing quality can be improved, and the labor cost and time cost of auditing can be greatly reduced.

[0033] 2. The LLM code auditing unit directly marks the code problems and modification suggestions on the specific code line or code block, the developer can confirm and refer to the modification suggestion to complete the corresponding problem, which greatly improves the problem efficiency.

[0034] 3. Through the suggestion review module and the review engineer intervention processing module, the error result set stored in the rule engine can help the review engineer intervention processing module to determine whether to intervene and process quickly, thereby improving the processing efficiency of manual intervention. BRIEF DESCRIPTION OF DRAWINGS

[0035] Figure 1 The application method of the DevOps pipeline business code auditing provided by the present application is a code auditing information flow diagram in the code auditing system. DETAILED DESCRIPTION

[0036] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0037] In the description of the present application, it should be noted that the terms "upper", "lower", "inner", "outer", "top / bottom end" and the like indicate the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. In addition, the terms "first", "second" are only for the purpose of description, and cannot be understood as indicating or implying relative importance.

[0038] Embodiments, with reference to Figure 1 The application method of the DevOps pipeline business code audit comprises a code audit system composed of a code repository unit, a design management unit, an LLM code audit unit and an audit auxiliary unit. The code repository unit is a personal end code repository generated based on a Git code project. The design management unit is composed of a design management module and a rule engine. The LLM code audit unit is composed of a prompt word construction module, an LLM audit module and a code audit result construction module. The audit auxiliary unit is composed of an audit engineer intervention processing module and a suggestion audit module.

[0039] The specific steps of the code audit method in the code audit system are as follows:

[0040] S1: Generating code architecture rules. In the project creation stage, code architecture specification rules are generated according to the framework and service version of the Git code project.

[0041] S2: Code merging request. In the code repository unit, the personal end sends the code for merging request to the LLM code audit unit.

[0042] S3: Proxy audit. In the LLM code audit unit, the code for merging request is audited and comments and modification suggestions are provided for the contents not meeting the code architecture rules.

[0043] S4: Upgrading iteration. When there is a difference between the modification made by the personal end and the modification suggestion provided by the LLM code audit unit, the modification is approved through the audit auxiliary unit, the modification result is recorded in the rule engine, the code architecture rules in the rule engine are modified, and the code audit system is upgraded and iterated.

[0044] Further, in step S1, the code architecture rules are generated based on the COLA framework in the Git code project, and the rule engine is the storage and call of the code architecture rules. After each iteration design is completed, the LLM model converts the program design data into code audit rules according to a specific template: for example, the bounded context, aggregation, domain object, elements and their relationships in the DDD domain object design are constructed into multiple description information according to a SQL-like statement mode; the dependency relationship between objects and the boundaries of bounded context and aggregation are converted into multiple audit rules that meet the matching requirements.

[0045] Further, in step S2, before the personal end of the code repository unit sends the code merging request, the code is audited by coding and self-checking, and the uncertain code branches are sent to the LLM code audit unit. The input parameters include MR_ID, project_id and other parameters.

[0046] Further, in step S3, the LLM code audit unit specifically audits the combined code as follows:

[0047] S31: Generate an audit prompt, the prompt construction module analyzes the modification feature set of the code based on the LLM model, and loads the code audit rules corresponding to each modification feature from the rule engine according to the modification to organize a complete rule list; the prompt construction module generates the audit prompt text for this time based on the pre-set code audit prompt template, combined with the code snippet and the code audit rule list;

[0048] S32: Generate an audit result, the LLM audit module calls the LLM model to complete the code audit according to the prompt generated by the prompt construction module, and some LLM models will use the split context multi-round dialogue mode to complete the audit due to the input length limit;

[0049] S33: Extract and label the results, the code audit result construction module extracts the code variable, line number, problem, and modification suggestion for each code snippet from the generated audit results, and calls the API interface of the Git repository to label the results to the code;

[0050] The above further benefits are: in step S31, the prompt construction module calls the Git repository API interface according to the received project_id, MR_ID and other parameters to obtain the modified code snippet set involved in this MR;

[0051] In step S2, the modification feature set involves: modifying the code layout, modifying the comments, code refactoring, modifying the component reference, adding the function, modifying the function, and abandoning the function, and the identification of the code problem feature classification includes: specification problem, readability problem, maintenance problem, complexity problem, design mismatch, security problem, and performance problem.

[0052] Based on the above, in step S32, the specific steps of generating code modification suggestions by the LLM audit module are as follows:

[0053] First step: classify the code problems, identify and classify the code problem features by analyzing the code audit results in the LLM audit module audit process;

[0054] Second step: generate a code modification suggestion tree, read each audit problem of each code snippet from the rule engine to combine a code modification suggestion tree;

[0055] Third step: generate targeted code modification suggestions, the LLM audit module generates modification suggestion prompt text based on the code modification suggestion tree, and generates targeted code modification suggestions by the LLM model.

[0056] Further, in step S4, the basis for the intervention of the review engineer in the intervention of the processing module is that there is a difference between the personal end modification and the modification suggestion provided by the LLM code auditing unit, and after the review engineer approves that the personal end modification is correct, the code architecture rules originally stored in the rule engine are corrected, and after the review engineer approves that the personal end modification is incorrect, the personal end modification result is saved to the error result set area of the rule engine.

[0057] The suggestion review module is used to assist the review engineer in the intervention processing module to make further intervention judgment. When the suggestion review module determines that there is a difference between the personal end modification and the modification suggestion provided by the LLM code auditing unit, and the personal end modification result in the error result set area is the same, the modification suggestion is upgraded to a modification execution instruction, and the personal end is forced to make a modification in accordance with the code architecture rules;

[0058] When the suggestion review module determines that the personal end modification suggestion and the personal end modification result in the error result set area are different, the modification suggestion is downgraded to a modifiable suggestion, and the review engineer is intervened to review and reclassify the modification suggestion;

[0059] Further, in the suggestion review module, when the review engineer intervenes in the review and cancels the modifiable suggestion, the personal end that provides the modification result suggestion is marked as a priority at this time, and when the modification suggestion is converted into a modification execution instruction, the personal end that does not comply with the modification suggestion is marked as a secondary at this time, to assist the personnel in the design management unit to timely understand the personal end modification;

[0060] It should be noted that when the development engineer corresponds to the problem and initiates the code audit again, the audit prompt word construction module reads the existing problems and modification suggestions of each code segment, and compares the differences between the actual corresponding code and the modification suggestions of the engineer; if the actual corresponding code and the modification suggestions are inconsistent, it proves that the engineer has not adopted the modification suggestion, and the list of unadopted modification suggestions is recorded;

[0061] When the review engineer cannot timely approve the difference between the personal end modification and the modification suggestion, the error result set stored in the rule engine can help the review engineer to intervene in the processing module to determine whether to intervene in the approval, to quickly process, avoid the accumulation of a large number of modification suggestions when the review engineer is on break, and affect the approval quality, so that the personal modification to be approved can be quickly processed when the intervention interval of the review engineer is too long;

[0062] Based on the above, when the modification suggestion is upgraded to the modification execution instruction for multiple times, the individual end not complying with the modification suggestion is marked as a poor engineer, when the modification suggestion is downgraded to the modifiable suggestion for multiple times, and the suggestion is cancelled in the later approval process, the individual end providing the modification result suggestion is marked as a high-quality vulnerability repair engineer, so that the management personnel in the management unit can understand the advantages and disadvantages of the individual end engineer in time based on the audit standard.

[0063] The above is only a preferred embodiment of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can make equivalent replacement or change according to the technical scheme and the inventive concept of the present application within the technical range disclosed by the present application, which should be covered in the protection scope of the present application.

Claims

1. An application method of DevOps pipeline business code audit, comprising a code audit system composed of a code warehouse unit, a design management unit, an LLM code audit unit and an audit auxiliary unit, characterized in that, The code repository unit is a personal end code repository generated based on a Git code project, the design management unit is composed of a design management module and a rule engine, the LLM code auditing unit is composed of a prompt word construction module, an LLM auditing module and a code auditing result construction module, and the auditing auxiliary unit is composed of an auditing engineer intervention processing module and a suggestion auditing module; The specific steps of the code auditing method in the code auditing system are as follows: S1: generating code architecture rules, in the engineering creation stage, generating code architecture specification rules according to the framework and service version of the Git code project; S2: code merging request, in the code repository unit, the personal end sends the merging request code to the LLM code auditing unit; S3: proxy auditing, in the LLM code auditing unit, auditing the merging request code and providing comments and modification suggestions for the content not meeting the code architecture rules; S4: upgrade iteration, when there is a difference between the personal end modification and the modification suggestion provided by the LLM code auditing unit, the modification is approved through the auditing auxiliary unit, and the modification result is recorded in the rule engine, the code architecture rules in the rule engine are modified, and the code auditing system is upgraded and iterated; In step S3, the specific steps of the LLM code auditing unit auditing the merging request code are as follows: S31: generating an audit prompt word, the prompt word construction module analyzes the modification feature set of the code based on the LLM model, and loads the code auditing rules corresponding to each modification feature from the rule engine according to the modification to organize a complete rule list; The prompt word construction module generates the audit prompt word text of this time based on the preloaded code audit prompt word template, combined with the code snippet and the code audit rule list; S32: generating an audit result, the LLM auditing module calls the LLM model to complete the code auditing according to the prompt word generated by the prompt word construction module, and some LLM models will adopt the split into context multi-round dialogue mode to complete the auditing due to the input length limitation; S33: extracting and marking the result, the code auditing result construction module extracts the code variable, line number, problem and modification suggestion of each code snippet from the generated audit result, and calls the API interface of the Git repository to mark the result to the code; In step S4, the basis for the intervention of the auditing engineer intervention processing module is that there is a difference between the personal end modification and the modification suggestion provided by the LLM code auditing unit, and after the auditing engineer approves the personal end modification, the original stored code architecture rules in the rule engine are corrected, and after the auditing engineer approves the personal end modification, the personal end modification result is saved to the error result set area of the rule engine; The suggestion auditing module is used to assist the auditing engineer intervention processing module to make further intervention judgment, and the suggestion auditing module upgrades the modification suggestion to a modification execution instruction to force the personal end to make modification meeting the code architecture rules when it is judged that there is a difference between the personal end modification and the modification suggestion provided by the LLM code auditing unit, and the personal end modification result is the same as that in the error result set area; The suggestion review module degrades the modification suggestion to a modifiable suggestion when the personal terminal modification suggestion and the personal terminal modification result in the error result set area are different, waits for the review engineer to intervene in the review, and re-ranks the modification suggestion; In the suggestion review module, when the review engineer cancels the modifiable suggestion after intervening in the review, the personal terminal providing the modification result suggestion is marked as a high level at this time, and the personal terminal not complying with the modification suggestion is marked as a low level when the modification suggestion is converted into a modification execution instruction, so that the personnel in the design management unit can understand the personal terminal modification in a timely manner.

2. The application method of DevOps pipeline business code audit according to claim 1, characterized in that, In step S1, the code framework rule is generated based on the COLA framework in the Git code project, and the rule engine is the storage and calling of the code framework rule.

3. The application method of DevOps pipeline business code audit according to claim 1, characterized in that, In step S2, before the code repository unit personal terminal sends a code merging request, the code is audited by coding and self-checking, and the uncertain code branch is sent to the LLM code audit unit.

4. The application method of DevOps pipeline business code audit according to claim 1, characterized in that, In step S32, the specific steps of generating the code modification suggestion through the LLM audit module are as follows: First step: classify the code problems, in the LLM audit module audit process, through analyzing the code audit result, identifying the code problem characteristics and classifying; Second step: generate a code modification suggestion tree, read each audit problem of each code fragment from the rule engine, and combine it into a code modification suggestion tree; Third step: generate targeted code modification suggestions, the LLM audit module generates modification suggestion prompt text combined with the code modification suggestion tree, and generates targeted code modification suggestions by the LLM model.

Citation Information

Patent Citations

  • Intelligent and efficient error detection and repair method and system

    CN118656107A

  • Code review method, system and device, storage medium and program product

    CN119576740A