Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,8 @@ Settings are layered; later layers win:

The repository file may set `llm.provider` (OCR built-in providers only, and only when the global config does not set one: a provider the operator names keeps the shared API key with that vendor), `llm.model`, `ocr.*` (except `binary` and `extra_args`) and `review.*`. Anything that decides where credentials are sent, or what gets executed, is rejected there: custom providers with their own `llm.url` belong in the global file.

`llm.model` can be any model ID the provider serves. With the OCR that pruefbyte bundles (the Docker image and release binaries, OCR v1.12.12 or newer), the model lists of OCR's built-in providers are only suggestions: a model that is not listed works, and OCR logs `[ocr] WARNING: model "…" is not in the suggested models for provider "…"; the provider will validate it`. A wrong ID therefore fails at the provider's API, not earlier. OCR v1.12.10 and older rejects unlisted models; that is what pruefbyte 0.1.0 bundles, and what an older `ocr` on your PATH (with `go install` builds, or set via `ocr.binary`) may still do. `pruefbyte version` shows which OCR is used.

Secrets are only ever read from the env vars named by `gitlab.token_env` and `llm.api_key_env`. `ocr` runs with a private, temporary `HOME`, so its config file and session logs never touch the runner.

Example `.pruefbyte.yml`:
Expand Down
5 changes: 3 additions & 2 deletions internal/config/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -240,8 +240,9 @@ func (c Config) Validate() error {
return errors.Join(errs...)
}

// builtinProviders mirrors OCR's built-in provider presets (`ocr llm providers`,
// v1.12.10). OCR rejects a custom provider that uses one of these names.
// builtinProviders mirrors OCR's built-in provider presets (`ocr llm providers`)
// for the version pinned in internal/ocrbin/VERSION; check it on every OCR bump.
// OCR rejects a custom provider that uses one of these names.
var builtinProviders = map[string]bool{
"anthropic": true, "bedrock": true, "openai": true, "openai-responses": true,
"openrouter": true, "gemini": true, "dashscope": true, "dashscope-tokenplan": true,
Expand Down
2 changes: 1 addition & 1 deletion internal/ocrbin/VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
v1.12.10
v1.12.12
2 changes: 1 addition & 1 deletion internal/ocrbin/ocrbin.go
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ var (
sum string // hex sha256 of the uncompressed binary, from OCR's release checksums
)

// Version is the OCR release pruefbyte is built and tested against, e.g. v1.12.10.
// Version is the OCR release pruefbyte is built and tested against, as pinned in VERSION (e.g. vX.Y.Z).
func Version() string { return strings.TrimSpace(versionFile) }

// Available reports whether this build carries an ocr binary.
Expand Down
2 changes: 1 addition & 1 deletion pruefbyte.example.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ llm:
# A provider set here is fixed: repositories cannot switch the shared API key to
# another vendor. Leave it out to let each repository choose.
provider: anthropic # any OCR built-in provider; other names are custom providers
model: claude-sonnet-5
model: claude-sonnet-5 # any model ID the provider serves; OCR's built-in lists are only suggestions
api_key_env: PRUEFBYTE_LLM_API_KEY # env var holding the API key
url: "" # base URL override; required for custom providers
protocol: "" # custom providers: anthropic | openai | openai-responses | anthropic-bedrock
Expand Down
Loading