Repository navigation
pruefbyte local, embedded OCR and installable releases - #3
Merged
Merged
Conversation
`pruefbyte local` reviews the current branch the way the CI job reviews its merge request and prints the findings instead of posting them. It shares the CI's config loading (.pruefbyte.yml and OCR rule files at the merge base), rule merging, OCR options, severity filtering and the fail_on_severity exit code. By default it reviews the working tree too, via a snapshot commit built with a throwaway index, so nothing in the repository changes. The API key falls back to the developer's own OCR config and then to the provider's env var. .pruefbyte.yml may now set llm.provider (OCR built-ins only), so provider and model live in the repository and GitLab variables hold only secrets. Installation: the module is now github.com/feinarbyte/pruefbyte so `go install` works, and v* tags publish GoReleaser binaries for Linux, macOS and Windows on amd64 and arm64. Every CI run builds them as a snapshot. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- A repository may set llm.provider only when the global config leaves it unset, so a merged .pruefbyte.yml cannot send the operator's shared API key to another vendor. - Run api_key_cmd from the developer's OCR config in pruefbyte with the real environment (keychains, pass, ~/ paths), not under ocr's private HOME. - Snapshot starts from a copy of the real index (sparse checkouts, no full rehash); CRLF-insensitive .pruefbyte.yml change note; JSON output always has a findings array; keep the real Toplevel error. - Share the OCR invocation between CI and local runs, and the line range formatting between comments and terminal output. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Release builds (GoReleaser, build tag embedocr) now carry the ocr binary for their platform, gzip-compressed, so a single download is all a developer needs for `pruefbyte local`. A before hook runs `go run ./internal/ocrbin/fetch`, which downloads the OCR release pinned in internal/ocrbin/VERSION for all six platforms and checks each against OCR's sha256sum.txt. On first use pruefbyte unpacks its copy into the user cache directory, verified against the same checksum. ocr.binary now defaults to automatic: a configured binary, else the built-in copy, else ocr from the PATH. The built-in copy comes before PATH so local runs use exactly the OCR version CI uses. The Docker image reads the same VERSION file, release archives ship OCR's license as LICENSE.open-code-review, and CI caches the downloads. Plain go build/test/install and the Docker image embed nothing. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Windows api_key_cmd: build the cmd.exe command line ourselves so quoted arguments survive. - Do not use a key from the developer's OCR config when it belongs to a different endpoint than this review uses. - Error when PRUEFBYTE_LLM_PROVIDER overrides the provider a repository's .pruefbyte.yml sets, instead of mixing provider and model. - Strip control characters from model text printed to the terminal. - Local output: drop repeated findings like CI, show OCR warnings, label the hidden count correctly. - Snapshot takes the HEAD the caller already resolved. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pruefbyte local: run the CI review before pushing--committedlimits it to commits. It reads them from a snapshot commit built with a throwaway index, so the user's index, branch and files are untouched..pruefbyte.ymland OCR rule files at the merge basefail_on_severityexit code (3)PRUEFBYTE_LLM_API_KEYapi_key, orapi_key_cmdrun in the real environment)--format jsongives machine-readable output.Config
.pruefbyte.ymlmay setllm.provider(OCR built-ins only), so provider and model live in the repo and GitLab variables hold only secrets.Embedded OCR and installation
embedocr) embed the gzip-compressed OCR pinned ininternal/ocrbin/VERSION.ocr.binaryif set, then the built-in copy, thenocron the PATH.LICENSE.open-code-review.github.com/feinarbyte/pruefbyte, sogo install …@latestworks (without OCR; that path needsocron the PATH).v*tags publish a GitHub release with archives for Linux, macOS and Windows on amd64 and arm64. Archive names carry no version, soreleases/latest/download/…URLs stay stable.Two
/code-review high --fixpasses ran. Their fixes are included, along with fixes for the findings they left open.Test plan
go test ./...: local vs CI equivalence, snapshot leaves the repo untouched, repo provider rules,api_key_cmd, OCR unpacking (first use, reuse, tamper, checksum mismatch)-tags embedocr; actionlint andgoreleaser checkpasspruefbyte localran end to end on this repo, with both PATH OCR and embedded OCR, failing as expected on an invalid key; the repo was unchangedv0.1.0, then check the release assets, the curl/PowerShell install andmise use -g github:feinarbyte/pruefbyte🤖 Generated with Claude Code