Installation
Requirements, installing ocra from npm, and building it from source.
ocra is an early 0.x release: options and output may still change between minor versions. Measured quality shows what its reviews find and miss.
Requirements
- Node.js 22.19 or newer
- Git
- An API key for at least one model provider
The OpenCode agent runtime, the default, is installed automatically as an optional dependency; no separate install is needed. To install without it, see Without OpenCode.
From npm
npm install -g @open-cr-agent/cli
ocra --versionTo update: npm install -g @open-cr-agent/cli@latest. To remove it: npm uninstall -g @open-cr-agent/cli.
To run it without installing, npx downloads it first:
npx @open-cr-agent/cli reviewInstall with optional dependencies, as npm does by default: the OpenCode runtime and its binary are optional dependencies, and --omit=optional leaves OpenCode out (see Without OpenCode).
npm 11.16 and later warn that opencode-ai has an install script not covered by allowScripts, and npm 12 blocks it. ocra does not need that script: it finds the OpenCode binary in the platform package without it, so you can leave it blocked.
Without OpenCode
The OpenCode runtime, @open-cr-agent/runtime-opencode, is an optional dependency of the CLI: with its native binary it is about 165 MB of the 175 MB an install takes. If every model you use is on an endpoint you declare and the configuration sets "runtime": "direct" (Choosing the runtime), you can leave it out. npm install -g installs optional dependencies whatever you pass, so install ocra into a directory of its own instead:
npm install --prefix ~/.ocra --omit=optional @open-cr-agent/cli
~/.ocra/node_modules/.bin/ocra --version # or put ~/.ocra/node_modules/.bin on your PATHThe same --omit=optional works for ocra as a dependency of a project. ocra imports a runtime only when a review needs one, and ocra review --plan needs none. A review whose configuration selects opencode, the default, stops before any model call with exit code 2, names the missing package and both ways out: set "runtime": "direct", or install the runtime next to ocra at ocra's exact version (npm install --prefix ~/.ocra @open-cr-agent/runtime-opencode@<version>).
In the GitHub Action, the input opencode: false does the same (GitHub).
Container image
Since 0.2.0, each release is also a container image for amd64 and arm64, ghcr.io/jma49/ocra:<version>. It is built by the release workflow from the packages just published, installed as the GitHub Action installs them (pinned dependencies, signatures and provenance checked), with git, running as the unprivileged node user.
docker run --rm --user "$(id -u):$(id -g)" --volume "$PWD:/repo" \
--env GEMINI_API_KEY ghcr.io/jma49/ocra:0.2.0 ocra review --from mainImages after 0.2.0 have ocra as their entrypoint, so docker run <image> review --from main is enough; a leading ocra, as above, works with every image. Run it as your own user, as above, so it can write .ocra/sessions/ in your checkout. Pass the model key and any OCRA_* variables with --env. Check where an image came from with gh attestation verify oci://ghcr.io/jma49/ocra:<version> --repo jma49/Open-CR-Agent.
From source
To work on ocra itself, or to run a version that is not released yet:
git clone https://github.com/jma49/Open-CR-Agent.git
cd Open-CR-Agent
npm install
npm run build
npm link --workspace @open-cr-agent/clinpm link makes the ocra command available globally. To update, pull and rebuild:
git pull && npm install && npm run buildTo remove it: npm unlink --global @open-cr-agent/cli.
Or run the built CLI directly, without linking:
node /path/to/Open-CR-Agent/packages/cli/dist/main.js reviewOpenCode binary
ocra looks for the OpenCode binary for your platform in opencode-ai's platform package, then in opencode-ai/bin/, where that package's install script puts one when it runs. If neither has it, point ocra at an OpenCode binary:
export OCRA_OPENCODE_BIN=/path/to/opencode