Add AI_PROVIDER=openai-compatible mode that reuses OpenAISynthesisProvider with a validated custom base_url, allowing any OpenAI-compatible API (OpenRouter, Ollama, LiteLLM proxy, etc.) without new code. Configuration: - AISettings.provider now accepts openai-compatible - New AISettings.allow_insecure_http: bool = False (HTTP opt-in) - .env.example: commented examples for OpenRouter (HTTPS) and Ollama (HTTP) Factory validation (_validate_openai_compatible_config): - base_url and model required, api_key required (MVP) - HTTPS enforced unless allow_insecure_http=true - Credentials in URL rejected, sensitive query params rejected (including valueless params via keep_blank_values=True) - Malformed URLs and missing hostname rejected (ValueError caught) - No /v1 manipulation; degraded to None + warning on invalid config - redact_url() used for all URL warnings Tests: 13 new factory tests in test_synthesis.py covering routing, URL validation, HTTP policy, credentials, sentinel non-leak, no-network. Coverage: 91.57% (synthesis module). Docs: GUIDE_DEV_PYTHON.md §9.5 updated with 3-provider table, validation rules, and synchronized code example. mypy override for openai.* (follow_imports=skip) to work around mypy 2.3.1 internal error in pre-commit's isolated environment. Co-authored-by: opencode/coder anthropic.claude-sonnet-4-5 <anthropic.claude-sonnet-4-5@agents.invalid> Co-authored-by: opencode/test-engineer anthropic.claude-sonnet-4-5 <anthropic.claude-sonnet-4-5@agents.invalid> Co-authored-by: opencode/tech-writer anthropic.claude-sonnet-4-5 <anthropic.claude-sonnet-4-5@agents.invalid>
182 lines
3.9 KiB
Plaintext
182 lines
3.9 KiB
Plaintext
{
|
|
"version": "1.5.0",
|
|
"plugins_used": [
|
|
{
|
|
"name": "ArtifactoryDetector"
|
|
},
|
|
{
|
|
"name": "AWSKeyDetector"
|
|
},
|
|
{
|
|
"name": "AzureStorageKeyDetector"
|
|
},
|
|
{
|
|
"name": "Base64HighEntropyString",
|
|
"limit": 4.5
|
|
},
|
|
{
|
|
"name": "BasicAuthDetector"
|
|
},
|
|
{
|
|
"name": "CloudantDetector"
|
|
},
|
|
{
|
|
"name": "DiscordBotTokenDetector"
|
|
},
|
|
{
|
|
"name": "GitHubTokenDetector"
|
|
},
|
|
{
|
|
"name": "GitLabTokenDetector"
|
|
},
|
|
{
|
|
"name": "HexHighEntropyString",
|
|
"limit": 3.0
|
|
},
|
|
{
|
|
"name": "IbmCloudIamDetector"
|
|
},
|
|
{
|
|
"name": "IbmCosHmacDetector"
|
|
},
|
|
{
|
|
"name": "IPPublicDetector"
|
|
},
|
|
{
|
|
"name": "JwtTokenDetector"
|
|
},
|
|
{
|
|
"name": "KeywordDetector",
|
|
"keyword_exclude": ""
|
|
},
|
|
{
|
|
"name": "MailchimpDetector"
|
|
},
|
|
{
|
|
"name": "NpmDetector"
|
|
},
|
|
{
|
|
"name": "OpenAIDetector"
|
|
},
|
|
{
|
|
"name": "PrivateKeyDetector"
|
|
},
|
|
{
|
|
"name": "PypiTokenDetector"
|
|
},
|
|
{
|
|
"name": "SendGridDetector"
|
|
},
|
|
{
|
|
"name": "SlackDetector"
|
|
},
|
|
{
|
|
"name": "SoftlayerDetector"
|
|
},
|
|
{
|
|
"name": "SquareOAuthDetector"
|
|
},
|
|
{
|
|
"name": "StripeDetector"
|
|
},
|
|
{
|
|
"name": "TelegramBotTokenDetector"
|
|
},
|
|
{
|
|
"name": "TwilioKeyDetector"
|
|
}
|
|
],
|
|
"filters_used": [
|
|
{
|
|
"path": "detect_secrets.filters.allowlist.is_line_allowlisted"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.common.is_baseline_file",
|
|
"filename": ".secrets.baseline"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.common.is_ignored_due_to_verification_policies",
|
|
"min_level": 2
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_indirect_reference"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_likely_id_string"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_lock_file"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_not_alphanumeric_string"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_potential_uuid"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_sequential_string"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_swagger_file"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_templated_secret"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.regex.should_exclude_file",
|
|
"pattern": [
|
|
"\\.venv/.*",
|
|
"\\.git/.*"
|
|
]
|
|
}
|
|
],
|
|
"results": {
|
|
"GUIDE_DEV_PYTHON.md": [
|
|
{
|
|
"type": "Hex High Entropy String",
|
|
"filename": "GUIDE_DEV_PYTHON.md",
|
|
"hashed_secret": "90bd1b48e958257948487b90bee080ba5ed00caa",
|
|
"is_verified": true,
|
|
"line_number": 4916,
|
|
"is_secret": false
|
|
}
|
|
],
|
|
"tests/unit/test_caldav_gateway.py": [
|
|
{
|
|
"type": "Secret Keyword",
|
|
"filename": "tests/unit/test_caldav_gateway.py",
|
|
"hashed_secret": "1c58bd92003bbaa0538e249fff6ee19a270dec5f",
|
|
"is_verified": false,
|
|
"line_number": 152
|
|
},
|
|
{
|
|
"type": "Basic Auth Credentials",
|
|
"filename": "tests/unit/test_caldav_gateway.py",
|
|
"hashed_secret": "1c58bd92003bbaa0538e249fff6ee19a270dec5f",
|
|
"is_verified": false,
|
|
"line_number": 763
|
|
}
|
|
],
|
|
"tests/unit/test_caldav_security.py": [
|
|
{
|
|
"type": "Basic Auth Credentials",
|
|
"filename": "tests/unit/test_caldav_security.py",
|
|
"hashed_secret": "8e1f07a2939b6324c70f48a3e7f64b463a4a3f8b",
|
|
"is_verified": false,
|
|
"line_number": 27
|
|
},
|
|
{
|
|
"type": "Secret Keyword",
|
|
"filename": "tests/unit/test_caldav_security.py",
|
|
"hashed_secret": "6b554cd7b7e0115065fb4907307a74f1902154d4",
|
|
"is_verified": false,
|
|
"line_number": 28
|
|
}
|
|
]
|
|
},
|
|
"generated_at": "2026-09-07T17:24:40Z"
|
|
}
|