Code review method and device, electronic equipment and storage medium
By automating the code review process, using pre-trained code review models and knowledge text information in the knowledge base, the problems of inefficient and high cost of manual code review are solved, and more efficient and high-quality code review is achieved.
Patent Information
- Application Number
- CN202510270628.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-06-17
AI Technical Summary
The existing code review methods rely on labor, resulting in high labor costs, low efficiency, and omissions of subjectivity and potential problems.
By receiving code merge requests, obtaining the target code and related source code files, determining the code file merge information, obtaining the knowledge text information in the knowledge base associated with the source code files, filtering the target knowledge text information based on similarity, and calling the pre-trained code review model for code review.
It reduces the labor cost investment in code review, improves the efficiency and quality of code review, and can promptly detect potential security vulnerabilities and other problems.
Smart Images

Figure CN120162237A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of software development technology, and in particular to a code review method, device, electronic device and storage medium. Background Art
[0002] CR (Code Review) is an important part of the software development process. Code review is a systematic review of computer source code, which aims to discover and correct errors that were not discovered in the early stages of software development, improve software quality and the technical level of developers. Code review plays a positive role in improving code quality and promoting team collaboration, and can reduce the risk of system failures.
[0003] Currently, the most commonly used code review method is manual review, which takes a lot of time, especially when the amount of code is large. It may extend the project development cycle, reduce the review efficiency, and require a lot of manpower costs. Manual review depends on the personal experience and skill level of the reviewer, so it may be subjective. In addition, manual review may miss or misjudge potential problems due to factors such as fatigue and lack of concentration, resulting in poor code quality. Summary of the invention
[0004] The purpose of the embodiments of the present application is to provide a code review method, device, electronic device and storage medium to reduce the human cost of code review and improve code review efficiency and code quality. The specific technical solution is as follows:
[0005] In a first aspect of the implementation of the present application, a code review method is first provided, comprising:
[0006] After receiving the code merge request, obtaining the target code written by the user, and obtaining the source code file involving code changes associated with the target code;
[0007] Determining code file merging information based on the target code and the source code file;
[0008] Acquire knowledge text information in a pre-established knowledge base associated with the source code file;
[0009] Based on the similarity between the code file merge information and the knowledge text information, determining target knowledge text information in the knowledge text information whose similarity with the code file merge information is greater than a threshold;
[0010] A pre-trained code review model is called to perform code review on the code file merging information according to the target knowledge text information to obtain a code review result.
[0011] In a second aspect of the implementation of the present application, a code review device is provided, including:
[0012] A target code acquisition module, configured to acquire the target code written by the user and the source code files related to code changes associated with the target code after receiving a code merge request;
[0013] A code file determination module, configured to determine code file merge information based on the target code and the source code files;
[0014] A knowledge text acquisition module, configured to acquire knowledge text information in a knowledge base established in advance and associated with the source code files;
[0015] A target text determination module, configured to determine target knowledge text information in the knowledge text information whose similarity to the code file merge information is greater than a threshold based on the similarity between the code file merge information and the knowledge text information;
[0016] A review result acquisition module, configured to call a pre-trained code review model to perform code review on the code file merge information according to the target knowledge text information, and obtain a code review result.
[0017] In yet another aspect of the implementation of the present application, an electronic device is further provided, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus;
[0018] The memory is used to store a computer program;
[0019] The processor is configured to implement the code review method described in any one of the above when executing the program stored on the memory.
[0020] In yet another aspect of the implementation of the present application, a computer-readable storage medium is further provided. Instructions are stored in the computer-readable storage medium, and when it runs on a computer, it causes the computer to execute the code review method described in any one of the above.
[0021] In yet another aspect of the implementation of the present application, a computer program product containing instructions is further provided. A computer program is stored thereon, and when the computer program runs on a computer, it causes the computer to execute the code review method described in any one of the above.
[0022] The solution provided by the embodiments of the present application, after receiving a code merge request, obtains the target code written by the user and the source code files related to the code changes associated with the target code. Based on the target code and the source code files, code file merge information is determined. Knowledge text information in the knowledge base pre-established and associated with the source code files is obtained. Based on the similarity between the code file merge information and the knowledge text information, target knowledge text information in the knowledge text information with a similarity greater than a threshold to the code file merge information is determined. The pre-trained code review model is called to perform code review on the code file merge information according to the target knowledge text information, and a code review result is obtained. By using the code review model for code review, the embodiments of the present application can reduce the input of human resources for code review and improve the code review efficiency compared with the manual review method. At the same time, combining the pre-established knowledge base associated with the code files for code review can avoid the problem that the review process only includes publicly available materials on the Internet and there are no unified review guidelines and standards, can timely detect potential security vulnerabilities and other problems, improve the quality of code review, and thus improve the quality of the code. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art.
[0024] Figure 1 It is a flowchart of the steps of a code review method provided by the embodiments of the present application;
[0025] Figure 2 It is a flowchart of the steps of a method for determining code file merge information provided by the embodiments of the present application;
[0026] Figure 3 It is a flowchart of the steps of a method for obtaining target knowledge text provided by the embodiments of the present application;
[0027] Figure 4 It is a flowchart of the steps of a method for obtaining a code review result provided by the embodiments of the present application;
[0028] Figure 5 It is a schematic diagram of a code review process provided by the embodiments of the present application;
[0029] Figure 6 It is a schematic structural diagram of a code review device provided by the embodiments of the present application;
[0030] Figure 7 It is a schematic structural diagram of an electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.
[0032] Figure 1 It is a step flowchart of a code review method provided by an embodiment of the present application. As Figure 1 shown, the code review method may include: Step 101, Step 102, Step 103, Step 104, and Step 105.
[0033] Step 101: After receiving a code merge request, obtain the target code written by the user, and obtain the source code files related to the code changes associated with the target code.
[0034] The embodiments of the present application can be applied to scenarios where code review is performed using a code review model in combination with a pre-established knowledge base.
[0035] A code merge request refers to a request for merging the code written by the user with the source file code.
[0036] The target code is the code used to change the corresponding code in the source code file.
[0037] In this example, after the user completes the writing of the target code and hopes to merge the target code into the main branch (such as master or main, etc.), a code merge request (merge request) corresponding to the target code can be initiated. In addition to the target code, the code merge request may also include detailed information about the changes to be merged, such as file information (such as file name, path, etc.) of the source code files to be changed, newly added functions, bugs fixed, etc.
[0038] In practical applications, a Webhook (hook function) can be configured on Git (that is, using Git as a version control system service, such as GitHub, GitLab, Bitbucket, etc.) to trigger the execution of the CR (Code Review) program and the comment callback process. Specifically, a Webhook refers to a mechanism that is automatically triggered by an HTTP request when a specific event occurs. Specifically, a Webhook allows a Git repository (such as GitHub, GitLab, etc.) to send an HTTP request to a specified URL when events such as code submission and merge request occur, thereby triggering the target system (such as the CR program) to perform corresponding operations.
[0039] After receiving a code merge request, the code merge request can be parsed to obtain the target code written by the user, and the source code files involved in code changes associated with the target code can be obtained. Specifically, the file information (such as file name, path, etc.) of the source code files with changes is included in the code merge request, and the corresponding file name is found through the path in the file information of the source code files, so as to obtain the source code files.
[0040] After obtaining the target code written by the user and the source code files involved in code changes associated with the target code, step 102 is executed.
[0041] Step 102: Determine the code file merge information based on the target code and the source code files.
[0042] The code file merge information refers to the code file generated by associating the target code with the source code files.
[0043] After obtaining the target code written by the user and the source code files involved in code changes associated with the target code, the code file merge information can be determined based on the target code and the source code files. Specifically, the source code files, as well as the original file path, the changed path, and the changed code of the current change of the source code files, etc., can be obtained, so as to obtain the code file merge information. The implementation process will be described in detail in the following embodiments in combination with Figure 2 and will not be elaborated here in this embodiment.
[0044] After determining the code file merge information based on the target code and the source code files, step 103 is executed.
[0045] Step 103: Obtain the knowledge text information in the knowledge base pre-established and associated with the source code files.
[0046] The knowledge base is a structured database or document collection used to store, organize, manage, and retrieve information related to source code files. The information related to source code files stored in the knowledge base can include business names and terms (such as various names and terms used in business logic, such as "gold member", "platinum member", etc.), code snippets and examples (such as code to implement specific functions, algorithm implementations, common utility functions, etc.), code interpretation information (providing detailed explanations and descriptions of key parts in the source code, such as complex algorithms, business logic processing flows, etc.), business logic and rules (describing the core logic and rules in the business platform, such as member upgrade conditions, point calculation rules, order processing flows, etc.), interface documents and API descriptions (such as request parameters, response formats, error codes, etc.), version history and change records (such as information about the content, time, person in charge, etc. of each change), etc.
[0047] When conducting code review, the business platform corresponding to the source code file can be determined according to the source code files related to code changes associated with the target code. Furthermore, the knowledge base pre-established for this business platform, that is, the knowledge base associated with the source code file, can be obtained. Then, the knowledge text information within this knowledge base can be extracted.
[0048] After obtaining the knowledge text information within the pre-established knowledge base associated with the source code file, step 104 is executed.
[0049] Step 104: Based on the similarity between the code file merge information and the knowledge text information, determine the target knowledge text information in the knowledge text information whose similarity to the code file merge information is greater than the threshold.
[0050] After obtaining the knowledge text information within the pre-established knowledge base associated with the source code file, the similarity between the code file merge information and the knowledge text information can be obtained, and based on this similarity, the target knowledge text information in the knowledge text information whose similarity to the code file merge information is greater than the threshold can be determined. Specifically, the vectors of the code file merge information and the knowledge text information can be obtained respectively, and the similarity between the code file merge information and the knowledge text information can be calculated through the cosine distance between the vectors. Then, the target knowledge text information is screened according to the similarity. The implementation process will be described in detail in the following embodiments Figure 3 and will not be elaborated herein in this embodiment.
[0051] The embodiments of the present application screen out the target knowledge text information highly relevant to the current code change from the knowledge base. This information includes coding specifications, best practices, solutions to potential problems, etc. The code review program can locate key information faster, thereby more accurately evaluating the quality, compliance, and potential problems of the code, thus improving the accuracy and efficiency of code review.
[0052] After determining the target knowledge text information in the knowledge text information whose similarity to the code file merge information is greater than the threshold based on the similarity between the code file merge information and the knowledge text information, step 105 is executed.
[0053] Step 105: Invoke the pre-trained code review model to conduct code review on the code file merge information according to the target knowledge text information, and obtain the code review result.
[0054] The code review model refers to a neural network model used for code quality review. In this example, the code review model can be, but is not limited to, LLMs (Large Language Models), etc.
[0055] After determining the target knowledge text information in the knowledge text information with a similarity greater than the threshold to the code file merging information based on the similarity between the code file merging information and the knowledge text information, a pre-trained code review model can be called to perform a code review on the code file merging information according to the target knowledge text information, and a code review result can be obtained. In a specific implementation, a code review prompt text for instructing the model to perform code checking can be generated according to the target knowledge text information and the code file merging information to assist the model in performing a code review. The implementation process will be described in detail in the following embodiments in combination with Figure 4 This will not be elaborated herein.
[0056] By using a code review model to perform a code review in the embodiments of the present application, compared with the manual review method, the labor cost input for code review can be reduced, and the code review efficiency can be improved. At the same time, by combining a pre-established knowledge base associated with the code file for code review, the problem that the review procedure only includes publicly available materials on the Internet and there is no unified review criterion and standard can be avoided, potential security vulnerabilities and other problems can be discovered in a timely manner, the code review quality can be improved, and thus the quality of the code can be improved.
[0057] Next, in combination with Figure 2 The process of determining the code file merging information will be described in detail.
[0058] Referring to Figure 2 , a flowchart of the steps of a method for determining code file merging information provided by an embodiment of the present application is shown. As Figure 2 shown, the method for determining code file merging information may include: step 201, step 202, and step 203.
[0059] Step 201: Obtain the source code and the original file path information corresponding to the source code file.
[0060] In this embodiment, after determining the source code file corresponding to the target code, the source code and the original file path information corresponding to the source code file can be obtained. Among them, the original file path information is the original storage path of the source code file.
[0061] After obtaining the source code and the original file path information corresponding to the source code file, step 202 is executed.
[0062] Step 202: Compare the source code with the target code to obtain the changed code that needs to be changed in the source code file.
[0063] The changed code refers to the code that needs to be changed in the source code file.
[0064] After obtaining the source code and the original file path information corresponding to the source code file, the source code and the target code can be compared to check for the changed code that needs to be changed in the source code file. Specifically, a code comparison tool can be used to compare the syntax and structure of the source code and the target code, including identifying structural elements such as code blocks, loops, conditional statements, function calls, etc., and comparing the differences of these elements between the source code and the target code. These differences may include: newly added code, deleted old code, or modified code lines, and the changed code that needs to be changed in the source code file is directly pointed out through the differences between the codes.
[0065] After determining the changed code corresponding to the source code file based on the source code and the target code, step 203 is executed.
[0066] Step 203: Determine the code file merging information according to the target code, the changed code, the original file path information, and the new file path information corresponding to the changed file.
[0067] After determining the changed code corresponding to the source code file based on the source code and the target code, the code file merging information can be determined according to the target code, the changed code, the original file path information, and the new file path information corresponding to the changed file. That is, the target code, the changed code, the original file path information, and the new file path information corresponding to the changed file are jointly used as the code file merging information, that is, the MR (merge request) information.
[0068] By obtaining the detailed information of the target code and the source code file in the embodiments of the present application, detailed logical information can be provided for subsequent intelligent code review, improving the accuracy of code review.
[0069] Next, in combination with Figure 3 The acquisition process of the target knowledge text will be described in detail.
[0070] Referring to Figure 3 , a flowchart showing the steps of a method for obtaining a target knowledge text provided by an embodiment of the present application is shown. As Figure 3 shown, the method for obtaining the target knowledge text may include: step 301, step 302, step 303, and step 304.
[0071] Step 301: Filter the code file merging information to obtain filtered code file information.
[0072] In this embodiment, after obtaining the code file merging information, the code file merging information can be filtered to obtain the filtered code file information. Specifically, invalid data, duplicate data, etc. in the code file merging information can be filtered out to streamline the code file information.
[0073] After filtering the merged information of the code files to obtain the filtered code file information, step 302 is executed.
[0074] Step 302: Perform desensitization processing on the filtered code file information to obtain preprocessed code file information.
[0075] After obtaining the filtered code file information, the filtered code file information can be desensitized to obtain preprocessed code file information. Specifically, for the privacy information in the filtered code file information, desensitization processing can be performed, such as desensitizing privacy information such as enterprise accounts and database passwords to improve the security of privacy information.
[0076] After desensitizing the filtered code file information to obtain preprocessed code file information, step 303 is executed.
[0077] Step 303: Calculate the similarity between the preprocessed code file information and the knowledge text information.
[0078] After preprocessing the merged information of the code files to obtain preprocessed code file information, the similarity between the preprocessed code file information and the knowledge text information can be calculated. In this example, the calculation process of the similarity can be as follows:
[0079] 1. Obtain the first vector corresponding to the preprocessed code file information and the second vector corresponding to the knowledge text information.
[0080] After obtaining the preprocessed code file information and the knowledge text information, the first vector corresponding to the preprocessed code file information and the second vector corresponding to the knowledge text information can be obtained. In specific implementation, existing pre-trained word embedding models can be selected, such as Word2Vec, GloVe, or more advanced models such as BERT and GPT. These models have been trained on large-scale text data and can well convert words into vectors. Since the structure and vocabulary of code files may be very different from ordinary texts, models specifically designed for code (such as Code2Vec, CodeBERT, etc.) may be needed. These models can capture the syntax and semantic information in the code and convert code snippets into vectors, that is, the first vector. Use the selected or trained word embedding model to convert each word (or sub-word) in the knowledge text into a vector. For the entire text, the vector representation of the entire text can be obtained through methods such as averaging, summing, or other pooling methods, that is, the second vector.
[0081] 2. Calculate the similarity between the preprocessed code file information and the knowledge text information according to the first vector and the second vector.
[0082] After obtaining the first vector and the second vector, the similarity between the preprocessed code file information and the knowledge text information can be calculated based on the first vector and the second vector. Specifically, the cosine similarity between the first vector and the second vector can be calculated (such as using the dot product (inner product) and the norm (length) of the vector, etc.), and this cosine similarity is used as the similarity between the preprocessed code file information and the knowledge text information.
[0083] Of course, in practical applications, other methods can also be used to calculate the similarity between the preprocessed code file information and the knowledge text information. For example, the Euclidean distance between the first vector and the second vector can be calculated (such as by calculating the square root of the sum of the squares of the differences between the corresponding elements of the two vectors), and the similarity between the preprocessed code file information and the knowledge text information can be determined through this Euclidean distance. The calculation method for the similarity between the preprocessed code file information and the knowledge text information can be determined according to business requirements, and this embodiment does not limit it.
[0084] After calculating the similarity between the preprocessed code file information and the knowledge text information, step 304 is executed.
[0085] Step 304: Screen out the knowledge text information with a similarity greater than the threshold from the knowledge text information as the target knowledge text information.
[0086] After calculating the similarity between the preprocessed code file information and the knowledge text information, the knowledge text information with a similarity greater than the threshold can be screened out from the knowledge text information as the target knowledge text information.
[0087] In the embodiment of the present application, by screening out the target knowledge text highly similar to the source code file from the knowledge text information in the knowledge base according to the similarity to assist the code review process, the useless knowledge text input to the model can be reduced, the model processing efficiency can be improved, and thus the code review efficiency can be improved.
[0088] Next, in combination with Figure 4 The implementation process of code review will be described in detail.
[0089] Referring to Figure 4 , a step flowchart of a method for obtaining code review results provided by an embodiment of the present application is shown. As Figure 4 shown, the method for obtaining code review results may include: step 401 and step 402.
[0090] Step 401: Generate a code review prompt text for instructing the model to perform code inspection according to the target knowledge text information and the code file merge information.
[0091] In this embodiment, the code review prompt text refers to the text used to instruct the code review model to conduct a code review, which can be used to help the code review model understand the review objectives, key areas of concern, expected review depth, and code sections that may require special attention.
[0092] After obtaining the target knowledge text information and the code file merge information, a code review prompt text for instructing the model to conduct a code check can be generated based on the target knowledge text information and the code file merge information. Specifically, the main purpose of the review (such as security, performance, code style, etc.), key areas (such as indicating areas or modules in the code that require special attention), checkpoints (such as listing specific code check items, such as potential errors, non-compliant places, etc.), and reference standards (links or overviews of relevant coding specifications, security standards, or performance metrics) can be clarified through the target knowledge text. The code change information (such as understanding the scope of code changes, including added, modified, or deleted files and code segments), key changes (such as identifying code changes that have a significant impact on system behavior or performance), dependency relationships (such as the dependency relationships between the changed code and other modules or systems), etc. can be clarified through the code file merge information. Combining this information can generate the corresponding code review prompt text.
[0093] After generating the code review prompt text for instructing the model to conduct a code check based on the target knowledge text information and the code file merge information, step 402 is executed.
[0094] Step 402: Invoke the code review model to conduct a code review on the code file merge information according to the code review prompt text, and obtain the code review result.
[0095] After generating the code review prompt text for instructing the model to conduct a code check based on the target knowledge text information and the code file merge information, the code review model can be invoked to conduct a code review on the code file merge information according to the code review prompt text, and obtain the code review result. In this example, the code review result may include at least one of inspection results such as code compliance result, logical accuracy result, code performance result, and code security result.
[0096] Among them, the code compliance result refers to evaluating whether the code follows the established coding standards and best practices. This includes checks in aspects such as naming conventions, code formatting, comments, code structure, and exception handling. For example, whether variable and function names conform to camel case naming or Pascal naming, whether code indentation is consistent, whether necessary comments are missing, and whether the code structure is clear.
[0097] The logical accuracy result refers to evaluating whether the logic of the code is correct and whether it can achieve the expected functions. This includes inspections of aspects such as algorithm logic, conditional judgments, and loop structures. For example, whether there are errors in the algorithm logic (such as whether the sorting algorithm is incorrect, etc.), whether there are loopholes in the conditional judgments (such as when processing user input, whether all possible input formats are checked and processed, etc.), whether there are errors in the loop structures (such as when traversing an array, whether the loop condition is set incorrectly, resulting in array out-of-bounds or missing some elements), etc.
[0098] The code performance result refers to evaluating the execution efficiency of the code, including inspections of aspects such as algorithm complexity, database query optimization, and resource usage. For example, whether the algorithm complexity is too high (such as whether unnecessary nested loops or recursive calls are used, etc.), whether the database query is optimized (such as whether indexes or query statements are used), whether the resource usage is improper (such as when processing a large amount of data, whether appropriate data structures or algorithms are used to reduce memory occupancy, etc.).
[0099] The code security result refers to evaluating whether there are security vulnerabilities and risks in the code and whether it can resist malicious attacks. This includes inspections of aspects such as input validation, permission control, and encryption algorithms. For example, whether the input validation is strict (such as when processing user input, whether parameterized queries are used or necessary escaping processing is performed on user input, etc.), whether the permission control is improper (such as when accessing the database, whether a suitable permission control mechanism is used to limit the access rights of users, etc.), whether the encryption algorithm is used improperly (such as whether an insecure encryption algorithm is used or the key management is improper, etc.).
[0100] In the embodiments of the present application, by pre-generating code review prompt texts to assist the model in code review, the model can be enabled to focus on key review items, improving the efficiency of the model in code review and at the same time improving the accuracy of the code review results.
[0101] After obtaining the code review result, the code review result can also be sent to the user based on a preset notification method, such as any one of the intelligent comment notification method, email notification method, instant messaging software notification method, etc., so that the user can timely understand the code review result and make code changes in a timely manner when there are problems with the code, improving the efficiency of project development.
[0102] Next, in combination with Figure 5 The process of code review will be described in detail.
[0103] Referring to Figure 5 , a schematic diagram of a code review process provided by the embodiments of the present application is shown. As Figure 5 shown, the code review process may include:
[0104] 1. Submit or update a merge request. Specifically, after developers finish writing the code, they initiate a request. Configure it on Gitlib and execute the configured request to trigger a merge request for code submission or update.
[0105] 2. Execute AI-CR. Based on the code submitted by developers, the changed files diff (such as source code file information, etc.) can be obtained to trigger the intelligent code review process.
[0106] 3. MR file information. After triggering AI-CR, detailed MR file information (i.e., code file merge information) can be obtained, such as source code, current code change information, old and new paths, etc.
[0107] 4. After code extraction, the extracted code file information can be filtered and desensitized for sensitive information to obtain a preprocessed file.
[0108] 5. For a custom knowledge base, knowledge text information can be screened from the knowledge base associated with the source code file. These knowledge text information are pre-stored in the knowledge base and are segmented texts. The main purpose of text segmentation is to split long documents into small pieces that are easy to manage and process, while trying to maintain the semantic integrity of the text.
[0109] 6. Similarity retrieval. That is, calculate the similarity through the vector representation of the retrieved indicator text information and the vector representation of the preprocessed file, and screen out the target knowledge text for code review from the knowledge text according to the calculated similarity.
[0110] 7. Obtain context information (knowledge base, usage). Through similarity retrieval, the knowledge base content associated with the current code update (i.e., the target knowledge text in this example) can be obtained.
[0111] 8. Generate a prompt. That is, jointly generate a code review prompt text for instructing the model to conduct code review based on the target knowledge text and MR file information.
[0112] 9. The LLM (i.e., the code review model) can conduct code review on the MR file information by combining the code review prompt text and the obtained context information in the knowledge base to obtain a CR result (i.e., the code review result).
[0113] 10. After obtaining the CR result, the CR result can be informed to the user, such as AI comments, session software notifications, email reminders, etc., so that the user can process it in a timely manner.
[0114] The code review method provided by the embodiments of this application, after receiving a code merge request, obtains the target code written by the user and obtains the source code files involving code changes associated with the target code. Based on the target code and the source code files, code file merge information is determined. Knowledge text information in a knowledge base pre-established and associated with the source code files is obtained. Based on the similarity between the code file merge information and the knowledge text information, target knowledge text information in the knowledge text information with a similarity greater than a threshold to the code file merge information is determined. A pre-trained code review model is called to perform code review on the code file merge information according to the target knowledge text information, and a code review result is obtained. By using a code review model to perform code review, the embodiments of this application can reduce the labor cost input for code review and improve the code review efficiency compared with the manual review method. At the same time, by combining the pre-established knowledge base associated with the code files for code review, the problem that the review process only includes publicly available materials on the Internet and there is no unified review criterion and standard can be avoided, potential security vulnerabilities and other problems can be detected in a timely manner, the code review quality can be improved, and thus the quality of the code can be improved.
[0115] Refer to Figure 6 , which shows a schematic structural diagram of a code review device provided by the embodiments of this application. As Figure 6 shown, the code review device 600 may include the following modules:
[0116] A target code acquisition module 610, configured to, after receiving a code merge request, obtain the target code written by the user and obtain the source code files involving code changes associated with the target code;
[0117] A code file determination module 620, configured to determine code file merge information based on the target code and the source code files;
[0118] A knowledge text acquisition module 630, configured to obtain knowledge text information in a knowledge base pre-established and associated with the source code files;
[0119] A target text determination module 640, configured to determine target knowledge text information in the knowledge text information with a similarity greater than a threshold to the code file merge information based on the similarity between the code file merge information and the knowledge text information;
[0120] A review result acquisition module 650, configured to call a pre-trained code review model to perform code review on the code file merge information according to the target knowledge text information, and obtain a code review result.
[0121] Optionally, the code file determination module includes:
[0122] A source code acquisition unit for acquiring the source code corresponding to the source code file and the original file path information;
[0123] A changed code acquisition unit for comparing the source code with the target code to obtain the changed code that needs to be changed in the source code file;
[0124] A code file determination unit for determining the code file merging information according to the target code, the changed code, the original file path information, and the new file path information corresponding to the changed file.
[0125] Optionally, the target text determination module includes:
[0126] A file filtering unit for filtering the code file merging information to obtain filtered code file information;
[0127] A preprocessing file acquisition unit for desensitizing the filtered code file information to obtain preprocessed code file information;
[0128] A similarity calculation unit for calculating the similarity between the preprocessed code file information and the knowledge text information;
[0129] A target text acquisition unit for screening out the knowledge text information with a similarity greater than the threshold from the knowledge text information as the target knowledge text information.
[0130] Optionally, the similarity calculation unit includes:
[0131] A vector acquisition sub-unit for acquiring a first vector corresponding to the preprocessed code file information and a second vector corresponding to the knowledge text information;
[0132] A similarity calculation sub-unit for calculating the similarity between the preprocessed code file information and the knowledge text information according to the first vector and the second vector.
[0133] Optionally, the review result acquisition module includes:
[0134] A prompt text generation unit for generating a code review prompt text for instructing the model to perform code inspection according to the target knowledge text information and the code file merging information;
[0135] A review result acquisition unit for calling the code review model to perform code review on the code file merging information according to the code review prompt text to obtain the code review result;
[0136] Among them, the code review result includes at least one of the following: code standardization result, logical accuracy result, code performance result, and code security result.
[0137] Optionally, the device further includes:
[0138] A review result sending module, configured to send the code review result to the user based on a preset notification method;
[0139] The preset notification method includes any one of an intelligent comment notification method, an email notification method, and a chat software notification method.
[0140] The code review device provided by the embodiment of the present application, after receiving a code merge request, obtains the target code written by the user, and obtains the source code file related to the code change associated with the target code. Based on the target code and the source code file, the code file merge information is determined. The knowledge text information in the knowledge base pre-established and associated with the source code file is obtained. Based on the similarity between the code file merge information and the knowledge text information, the target knowledge text information in the knowledge text information whose similarity to the code file merge information is greater than the threshold is determined. The pre-trained code review model is called to perform code review on the code file merge information according to the target knowledge text information, and the code review result is obtained. By using the code review model to perform code review, the embodiment of the present application can reduce the labor cost input of code review and improve the code review efficiency compared with the manual review method. At the same time, combining the pre-established knowledge base associated with the code file for code review can avoid the problem that the review process only includes publicly available materials on the Internet and there is no unified review criterion and standard, and can timely discover potential security vulnerabilities and other problems, improve the code review quality, and thus improve the code quality.
[0141] The embodiment of the present application also provides an electronic device, as Figure 7 shown, including a processor 701, a communication interface 702, a memory 703, and a communication bus 704. Among them, the processor 701, the communication interface 702, and the memory 703 communicate with each other through the communication bus 704.
[0142] The memory 703 is used to store a computer program;
[0143] The processor 701, when executing the program stored on the memory 703, implements the following steps:
[0144] After receiving a code merge request, obtain the target code written by the user, and obtain the source code file related to the code change associated with the target code;
[0145] Based on the target code and the source code file, determine the code file merge information;
[0146] Obtain knowledge text information in a pre-established knowledge base associated with the source code file;
[0147] Based on the similarity between the code file merge information and the knowledge text information, determine target knowledge text information in the knowledge text information whose similarity to the code file merge information is greater than a threshold;
[0148] Invoke a pre-trained code review model to perform code review on the code file merge information according to the target knowledge text information, and obtain a code review result.
[0149] Optionally, the determining the code file merge information based on the target code and the source code file includes:
[0150] Obtain the source code and the original file path information corresponding to the source code file;
[0151] Compare the source code with the target code to obtain the changed code to be changed in the source code file;
[0152] Determine the code file merge information according to the target code, the changed code, the original file path information, and the new file path information corresponding to the changed file.
[0153] Optionally, the determining the target knowledge text information in the knowledge text information whose similarity to the code file merge information is greater than a threshold based on the similarity between the code file merge information and the knowledge text information includes:
[0154] Perform filtering processing on the code file merge information to obtain filtered code file information;
[0155] Perform desensitization processing on the filtered code file information to obtain preprocessed code file information;
[0156] Calculate the similarity between the preprocessed code file information and the knowledge text information;
[0157] Screen out knowledge text information with a similarity greater than the threshold from the knowledge text information as the target knowledge text information.
[0158] Optionally, the calculating the similarity between the preprocessed code file information and the knowledge text information includes:
[0159] Obtain a first vector corresponding to the preprocessed code file information and a second vector corresponding to the knowledge text information;
[0160] Calculate the similarity between the preprocessed code file information and the knowledge text information based on the first vector and the second vector
[0161] Determine the similarity between the preprocessed code file information and the knowledge text information according to the cosine distance.
[0162] Optionally, call the pre-trained code review model to perform code review on the code file merge information according to the target knowledge text information, and obtain a code review result, including:[[]]
[0163] Generate a code review prompt text for instructing the model to perform code inspection according to the target knowledge text information and the code file merge information;
[0164] Call the code review model to perform code review on the code file merge information according to the code review prompt text, and obtain the code review result;
[0165] Wherein, the code review result includes at least one of: code standardization result, logical accuracy result, code performance result, and code security result.
[0166] Optionally, after calling the pre-trained code review model to perform code review on the code file merge information according to the target knowledge text information and obtaining a code review result, it further includes:[[]]
[0167] Send the code review result to the user based on a preset notification method;
[0168] The preset notification method includes any one of: intelligent comment notification method, email notification method, and instant messaging software notification method.
[0169] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity, only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0170] The communication interface is used for communication between the above terminal and other devices.
[0171] The memory may include a Random Access Memory (RAM), or may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0172] The aforementioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0173] In another embodiment provided by the present application, a computer-readable storage medium is further provided. Instructions are stored in the computer-readable storage medium. When it runs on a computer, the computer is caused to execute the code review method described in any one of the above embodiments.
[0174] In another embodiment provided by the present application, a computer program product containing instructions is further provided. A computer program is stored thereon. When the computer program runs on a computer, the computer is caused to execute the code review method described in any one of the above.
[0175] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)).
[0176] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or device that includes a series of elements includes not only those elements but also other elements not expressly listed, or elements that are inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device that includes the element.
[0177] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.
[0178] The above are only the preferred embodiments of the present application and are not intended to limit the protection scope of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application are all included in the protection scope of the present application.
Claims
1. A code review method, characterized in that: include: After receiving the code merge request, obtaining the target code written by the user, and obtaining the source code file involving code changes associated with the target code; Determining code file merging information based on the target code and the source code file; Acquire knowledge text information in a pre-established knowledge base associated with the source code file; Based on the similarity between the code file merge information and the knowledge text information, determining target knowledge text information in the knowledge text information whose similarity with the code file merge information is greater than a threshold; A pre-trained code review model is called to perform code review on the code file merging information according to the target knowledge text information to obtain a code review result.
2. The method according to claim 1, characterized in that The determining code file merging information based on the target code and the source code file includes: Obtain source code and original file path information corresponding to the source code file; Comparing the source code and the target code to obtain the changed code that needs to be changed in the source code file; The code file merging information is determined according to the target code, the changed code, the original file path information and the new file path information corresponding to the changed file.
3. The method according to claim 1, characterized in that The determining, based on the similarity between the code file merge information and the knowledge text information, target knowledge text information having a similarity with the code file merge information greater than a threshold in the knowledge text information comprises: Filtering the code file merge information to obtain filtered code file information; Desensitizing the filtering code file information to obtain preprocessing code file information; Calculating the similarity between the preprocessing code file information and the knowledge text information; The knowledge text information having a similarity greater than a threshold is screened out from the knowledge text information to serve as the target knowledge text information.
4. The method according to claim 3, characterized in that The calculating and obtaining the similarity between the preprocessing code file information and the knowledge text information includes: Obtaining a first vector corresponding to the preprocessing code file information and a second vector corresponding to the knowledge text information; The similarity between the preprocessing code file information and the knowledge text information is calculated based on the first vector and the second vector.
5. The method according to claim 1, characterized in that The calling of the pre-trained code review model performs code review on the code file merge information according to the target knowledge text information to obtain a code review result, including: Generate a code review prompt text for instructing the model to perform code checking according to the target knowledge text information and the code file merge information; Calling the code review model to perform code review on the code file merging information according to the code review prompt text to obtain the code review result; The code review result includes at least one of a code standardization result, a logic accuracy result, a code performance result and a code security result.
6. The method according to claim 1, characterized in that After the calling of the pre-trained code review model to perform code review on the code file merge information according to the target knowledge text information and obtaining the code review result, the method further includes: Sending the code review result to the user based on a preset notification method; The preset notification method includes: any one of an intelligent comment notification method, an email notification method, and a conversation software notification method.
7. A code review device, characterized in that: include: The target code acquisition module is used to acquire the target code written by the user and acquire the source code file related to the code change associated with the target code after receiving the code merge request; A code file determination module, used to determine code file merging information based on the target code and the source code file; A knowledge text acquisition module, used to acquire knowledge text information in a pre-established knowledge base associated with the source code file; A target text determination module, configured to determine, based on the similarity between the code file merge information and the knowledge text information, target knowledge text information whose similarity with the code file merge information is greater than a threshold in the knowledge text information; The review result acquisition module is used to call a pre-trained code review model to perform code review on the code file merging information according to the target knowledge text information to obtain a code review result.
8. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing any of the methods described in claims 1-6 when executing a program stored in a memory.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. A computer program product comprising instructions, on which a computer program is stored, characterized in that When the computer program is executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 6.