Skip to content

pruefbyte: GitLab MR review bot on top of OpenCodeReview - #1

Merged
testudor merged 4 commits into
mainfrom
feat/initial-implementation
Oct 5, 2026
Merged

testudor merged 4 commits into
mainfrom
feat/initial-implementation

Conversation

@testudor

@testudor testudor commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Summary

pruefbyte reviews GitLab merge requests with OpenCodeReview (ocr) and posts the findings as inline discussions from a bot account. It works like pr-agent, but runs as a GitLab CI job.

  • Review: runs ocr review on the MR's base..head range in an isolated home directory and parses OCR's JSON output. Works with any LLM provider OCR supports.
  • Comments: each finding is attached to the right diff line, including findings about removed code. GitLab "apply suggestion" blocks are only offered when the quoted code matches those lines. Findings that can't be placed on the diff go into one summary note that is updated in place.
  • Repeat runs: hidden fingerprints stop the same finding from being posted twice. The bot resolves its own threads only after the flagged code has changed in a file OCR actually reviewed.
  • Config: settings are layered: defaults < global file < .pruefbyte.yml < PRUEFBYTE_* env vars.
    • .pruefbyte.yml and OCR's rule files are read at the MR's base commit, so an MR can't change its own review settings.
    • The repo file can't change credentials, endpoints or which binaries run.
  • When it runs: the CI job's rules: decide this; pruefbyte has no draft, label, author or branch filters of its own. The README has rule examples.
  • Delivery: a Dockerfile with a pinned, checksum-verified ocr binary and a GitLab CI template.
  • This repo's CI: a GitHub Actions pipeline runs gofmt, go mod tidy, golangci-lint, go vet, race tests and amd64/arm64 builds. Once those pass, it builds the linux/amd64 + linux/arm64 image, which is pushed to ghcr.io/feinarbyte/pruefbyte from main and v* tags. Pull requests only build it.

Test plan

  • go test ./... covers config layering, OCR JSON parsing, diff placement, dedupe across runs, the fallback when GitLab rejects a position (400), thread resolution, failure notes, and an end-to-end CLI run against a fake GitLab.
  • golangci-lint shows 0 issues and gofmt is clean.
  • Checked against the real OCR v1.12.10: every config key is accepted, the review arguments are valid, and the failure output is handled.
  • This PR's CI run: lint, test, build, and the multi-arch image build (not tested locally, because Docker wasn't running).
  • After merging, a test review on a sandbox GitLab project using the ghcr.io/feinarbyte/pruefbyte:latest image.

🤖 Generated with Claude Code

testudor and others added 4 commits September 28, 2026 19:29
pruefbyte runs as a GitLab CI job, reviews the merge request with the
OpenCodeReview CLI and posts findings as inline discussions from a bot
account (PAT). Findings are anchored to diff lines with suggestion blocks,
deduplicated via hidden fingerprints, and the bot's own threads are
resolved once the flagged code changed. Unplaceable or over-limit
findings go to a single summary note that is updated in place.

Configuration is layered (defaults < global file < .pruefbyte.yml at the
MR base commit < PRUEFBYTE_* env); the repo file cannot change the LLM
endpoint, GitLab settings or executed binaries. Includes a Dockerfile
bundling a pinned, checksum-verified ocr binary and a reusable CI template.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Fixes from code review:
- Pass one generated --rule file built from the base commit, so a merge
  request's own .opencodereview/rule.json cannot exclude files or rewrite
  review instructions.
- Place findings on removed lines when the quoted code was deleted; only
  offer suggestion blocks when existing_code matches the new lines.
- Escape GitLab quick actions in LLM text; do not trust markers inside it.
- Fetch the MR diff before running OCR; do not resend discussion POSTs
  after 5xx; count open bot threads against max_comments; list failed
  posts in the summary.
- Fingerprint findings by path, category and quoted code instead of prose.
- Kill the OCR process tree on timeout; never relabel failed runs.
- Resolve threads only for files OCR reviewed, against unfiltered
  findings, on actually changed lines, and never re-resolve reopened ones.
- Add missing OCR provider presets, fix arm64 image, cmd.exe argument
  injection, comma handling, OCR self-update and secret env leakage.
- Skip merge-train and fork pipelines in the CI template.

Remove pruefbyte's own skip filters (drafts, labels, authors, branches,
titles). The CI job's rules decide when pruefbyte runs; the README shows
the equivalent rules. Only the stale-head guard remains.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
GitHub Actions runs gofmt, go mod tidy, golangci-lint (v2.14.0, pinned in
mise.toml), go vet, race-enabled tests and linux/amd64+arm64 builds on
pushes to main, v* tags and pull requests. Once those pass, it builds a
linux/amd64+arm64 image and pushes it to ghcr.io (latest from main,
semver tags from v* tags, sha-<commit>); pull requests only build it.

The Dockerfile now cross-compiles on the build platform so only the final
stage runs under emulation. Lint fixes: wrap both errors with %w, tighter
artifact permissions, sha256 for finding fingerprints.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@testudor
testudor merged commit 2410ae9 into main Oct 5, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant