Skip to content

fix: update default model to openai/gpt-5-mini and correct GitHub Mod… - #3

Merged
nattbl49 merged 9 commits into
mainfrom
fix/test
Jul 10, 2026
Merged

fix: update default model to openai/gpt-5-mini and correct GitHub Mod…#3
nattbl49 merged 9 commits into
mainfrom
fix/test

Conversation

@n-devs

@n-devs n-devs commented Jul 10, 2026

Copy link
Copy Markdown
Owner

…els API URL


Open in Devin Review

@github-actions

Copy link
Copy Markdown

AI Code Review — openai/gpt-5-mini via github-models

⚠️ AI API returned status 400. Response: {"error":{"code":"unavailable_model","message":"Unavailable model: gpt-5-mini","details":"Unavailable model: gpt-5-mini"}}

devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions

Copy link
Copy Markdown

AI Code Review — openai/gpt-4o-mini via github-models

⚠️ AI API returned status 403. Response: {"error":{"message":"Unable to proceed with model usage. This account has reached its budget limit."}}

devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions

Copy link
Copy Markdown

AI Code Review — gpt-4o via github-models

⚠️ AI API returned status 403. Response: {"error":{"message":"Unable to proceed with model usage. This account has reached its budget limit."}}

devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions

Copy link
Copy Markdown

AI Code Review — openai/gpt-4o-mini via github-models

⚠️ AI API returned status 403. Response: {"error":{"message":"Unable to proceed with model usage. This account has reached its budget limit."}}

devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions

Copy link
Copy Markdown

AI Code Review — gpt-4o via github-models

โค้ดที่คุณให้มาเป็นส่วนที่ถูกเปลี่ยนแปลงในไฟล์ README.md โดยเฉพาะในตารางที่อธิบายเกี่ยวกับพารามิเตอร์สำหรับการตั้งค่าต่าง ๆ ในระบบ คุณได้ปรับเปลี่ยนค่าของ model จาก gpt-4o เป็น openai/gpt-4o-mini โดยเฉพาะชื่อโมเดลที่ใช้ แต่จากตัวโค้ดส่วนนี้ ไม่มีส่วนที่เกี่ยวข้องกับการเขียนโปรแกรมโดยตรง เพราะเป็นเอกสาร README ที่เน้นอธิบายการตั้งค่าเท่านั้น

คำแนะนำในการปรับปรุง

  1. ความชัดเจนในเอกสาร:

    • หากชื่อโมเดล openai/gpt-4o-mini เป็นทางเลือกใหม่แทน gpt-4o ก็ควรมีส่วนอธิบายใน README ว่าโมเดลนี้คืออะไร และข้อแตกต่างระหว่างทั้งสองโมเดล หากต้องการให้ผู้ใช้งานเข้าใจได้ง่ายขึ้น
    • ตรวจสอบและเพิ่มการอ้างอิงในส่วน Providers เพื่อให้สอดคล้องกับโมเดลใหม่ว่าโมเดลนี้ได้รับการสนับสนุนจริงหรือไม่
  2. ชื่อโมเดล:

    • การเปลี่ยนชื่อโมเดลอาจส่งผลต่อความสับสน หากมีผู้ใช้งานที่ยังคงอ้างอิงการตั้งค่ากับชื่อเดิม (gpt-4o) ควรพิจารณาว่าจะให้คำอธิบ��ยเพิ่มเติม หรือมีส่วนบันทึกเ���ี่ยวกับการเปลี่ยนแปลงไว้ เช่นในบันทึกการเปลี่ยนเวอร์ชัน (Changelog)
  3. Consistency:

    • ควรตรวจสอบชื่อโมเดลนี้ในส่วนอื่น ๆ ของโปรเจกต์ เช่น ที่ตัวโค้ด implementation หรือไฟล์ config ว่าได้มีการรองรับชื่อใหม่นี้โดยสมบูรณ์หรือไม่

ความปลอดภัย

จากตัวโค้ดที่ปรากฏ ณ ที่นี้ ไม่มีส่วนที่เกี่ยวข้องกับฟังก์ชันการทำงานเชิงโปรแกรมหรือการเรียก API จึงไม่พบช่องโหว่ด้านความปลอดภัยโดยตรงในส่วนที่แก้ไข อย่างไรก็ตาม มีบางประเด็นที่อาจตรวจสอบเสริม:

  • หากโมเดล openai/gpt-4o-mini ต้องใช้ api_key หรือการตั้งค่าเพิ่มเติม ควรมีคำแนะนำที่ชัดเจนใน README เรื่องวิธีการจัดเก็บค่าคีย์อย่างปลอดภัย เช่น การใช้ environment variables แทนการเขียนคีย์ลงในไฟล์ config

บทสรุป

การเปลี่ยนชื่อโมเดลดูเหมือนเป็นการเปลี่ยนแปลงง่าย ๆ ในเอกสาร แต่สิ่งสำคัญคือต้องตรวจสอบเอกสาร และ implementation อื่น ๆ ให้มีความสอดคล้องกัน รวมถึงอธิบายข้อมูลเพิ่มเติมเกี่ยวกับการใช้งานโมเดลใหม่ เพื่อให้ผู้ใช้งานสามารถใช้งานได้ง่ายขึ้นโดยไม่มีความสับสน และควรจับตาดูด้านความปลอดภัยโดยรวม เช่น การแนะนำการจัดการ api_key อย่างเหมาะสมในเอกสาร

- Added dependencies for @azure-rest/ai-inference and @azure/core-auth in package.json and package-lock.json.
- Updated PROVIDER_BASES to change GitHub Models base URL.
- Implemented isGithubModelsProvider function to identify GitHub Models provider.
- Created askGitHubModels function to handle requests to the GitHub Models API.
- Updated askAI function to route requests to GitHub Models when applicable.
- Added licenses for new dependencies in licenses.txt.
@github-actions

Copy link
Copy Markdown

AI Code Review — gpt-4o via github-models

⚠️ GitHub Models API returned status 403. Response: "{"error":{"message":"Unable to proceed with model usage. This account has reached its budget limit."}}"

@github-actions

Copy link
Copy Markdown

AI Code Review — openai/gpt-4o via github-models

⚠️ GitHub Models API returned status 403. Response: "{"error":{"message":"Unable to proceed with model usage. This account has reached its budget limit."}}"

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 new potential issues.

View 4 additional findings in Devin Review.

Open in Devin Review

Comment thread src/config.ts
Comment on lines +70 to +72
export function isGithubModelsProvider(provider: Provider | undefined, url: string): boolean {
return provider === "github-models" || url.includes(".inference.ai.azure.com");
}

@devin-ai-integration devin-ai-integration Bot Jul 10, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 GitHub Models URL detection checks the old domain instead of the new one

The URL-based detection for the GitHub Models provider checks for the old domain .inference.ai.azure.com (url.includes(".inference.ai.azure.com") at src/config.ts:71) even though the base URL was changed to models.github.ai/inference, so custom-provider users pointing at the new endpoint will not be routed to the correct SDK path.

Impact: Users who set provider: custom with a models.github.ai URL will not get the GitHub Models SDK integration.

Mechanism: URL pattern mismatch after base URL migration

The PROVIDER_BASES["github-models"] was changed from https://models.inference.ai.azure.com to https://models.github.ai/inference at src/config.ts:24, but the newly added isGithubModelsProvider function at src/config.ts:70-72 still checks for the old domain pattern .inference.ai.azure.com. The URL-based fallback will never match the new URL. It should check for models.github.ai instead.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread src/index.ts
// 2b. GitHub Models — ใช้ @azure-rest/ai-inference SDK อย่างเป็นทางการ
async function askGitHubModels(systemPrompt: string, userPrompt: string): Promise<string> {
const endpoint = PROVIDER_BASES["github-models"]!;
const token = GH_PAT ?? API_KEY;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 GitHub Models authentication ignores the explicit API key and always uses the general-purpose token

The authentication token for GitHub Models is selected with wrong priority (GH_PAT ?? API_KEY at src/index.ts:155), so the explicitly provided API key is ignored whenever the general GitHub PAT is set — which is always, since it is a required input.

Impact: Users who provide a dedicated API key for GitHub Models will silently authenticate with the wrong credential, potentially causing authorization failures.

Mechanism: GH_PAT takes precedence over the resolved API_KEY

GH_PAT is the gh_pat input (required, always set). API_KEY at src/index.ts:41 is resolved as EXPLICIT_API_KEY ?? GH_PAT ?? "", meaning it already incorporates the explicit api_key input with GH_PAT as fallback. By writing GH_PAT ?? API_KEY, the code always picks GH_PAT (since it's always truthy for a required input), ignoring any explicitly provided api_key. All other API functions (askOpenAICompat, askAnthropic, askResponses) correctly use API_KEY. The fix should be API_KEY (or API_KEY ?? GH_PAT if a different priority is intended).

Suggested change
const token = GH_PAT ?? API_KEY;
const token = API_KEY || GH_PAT || "";
Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@github-actions

Copy link
Copy Markdown

AI Code Review — gpt-4o via github-azure-models

⚠️ GitHub Models API returned status 403. Response: "{"error":{"message":"Unable to proceed with model usage. This account has reached its budget limit."}}"

devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions

Copy link
Copy Markdown

AI Code Review — gpt-4o via github-azure-models

รีวิวและคำแนะนำสำหรับส่วนต่างของโค้ด (Code Diff)

ไฟล์: README.md

  1. การเปลี่ยนแปลง

    • เปลี่ยนค่าเริ่มต้นของ model จาก gpt-4o เป็น openai/gpt-4o-mini
    • เปลี่ยนค่าเริ่มต้นของ provider จาก github-models เป็น github-azure-models
  2. คำแนะนำ

    • เพิ่มข้อมูลและคำอธิบายเกี่ยวกับโมเดล openai/gpt-4o-mini ในไฟล์ README.md เพื่อให้ผู้อ่านเข้าใจความแตกต่างระหว่างโมเดลนี้กับโมเดลก่อนหน้า (gpt-4o) เช่น การปรับปรุงสมรรถนะหรือการใช้ทรัพยากรที่น้อยลง
    • การเปลี่ยน provider เป็น github-azure-models เป็นสิ่งที่อาจส่งผลต่อการตั้งค่าอื่น เช่น การตั้งค่า api_url หรือ token ที่เชื่อมโยงกับระบบ Azure ควรเพิ่มคำอธิบายเพิ่มเติมเกี่ยวกับระบบนี้ในเอกสาร
  3. ความเสี่ยงด้านความปลอดภัย

    • ให้ตรวจสอบว่าเมื่อใช้ provider github-azure-models มีการจัดการความปลอดภัยของ api_key และ api_url อย่างเหมาะสม โดยเฉพาะเพื่อป้องกันการรั่วไหลของข้อมูล API Key ในระบบหรือ log ต่างๆ

ไฟล์: action.yml

  1. การเปลี่ยนแปลง

    • เปลี่ยนค่าเริ่มต้นของ provider จาก github-models เป็น github-azure-models
  2. คำแนะนำ

    • ให้ใส่คำอธิบายเพิ่มเติมในหัวข้อ provider ว่า github-azure-models รองรับความสามารถและข้อจำกัดอะไรบ้าง เพื่อช่วยให้ผู้ใช้งานใหม่เข้าใจและปรับใช้งานได้อย่างถูกต้อง
    • ตรวจสอบว่า provider ใหม่ (github-azure-models) ได้รับการสนับสนุนในโครงสร้างระบบปัจจุบันอย่างครบถ้วน (เช่น, รองรับค่า api_url และ api_type)
  3. ความเสี่ยงด้านความปลอดภัย

    • การเปลี่ยนไปใช้ github-azure-models อาจเพิ่มองค์ประกอบที่ต้องตรวจสอบ เช่น การตั้งค่า Azure Service Principal หรือ API Endpoint ที่จะต้องมีการเชื่อมต่อ ควรแน่ใจว่ามีการจัดการความปลอดภัยในส่วนนี้อย่างระมัดระวัง เช่น การป้องกัน Cross-Tenant Access
    • ตรวจสอบให้แน่ใจว่าไม่มีการ hard-code ค่า sensitive data (เช่น API Key) ใน action.yml หรือส่วนอื่นๆ ของโค้ด

ไฟล์: dist/licenses.txt

  1. การเปลี่ยนแปลง

    • มีการเพิ่มไฟล์ licenses.txt พร้อมข้อมูลเกี่ยวกับไลเซนส์ซอฟต์แวร์มากมาย (MIT License)
  2. คำแนะนำ

    • ในการจัดการไฟล์ licenses.txt ควรแน่ใจว่าไม่มี library หรือ dependency ที่ละเมิดข้อกำหนดการใช้งาน Open Source โดยเฉพาะการใช้ในเชิงพาณิชย์
    • รวมข้อมูลเกี่ยวกับไฟล์นี้ใน README.md หรือไฟล์ที่เกี่ยวข้อง เพื่อที่ผู้ใช้งานจะสามารถตรวจสอบไลเซนส์ได้ในจุดเดียว
  3. ความเสี่ยงด้านความปลอดภัย

    • ไม่มีความเสี่ยงด้านความปลอดภัยโดยตรงสำหรับส่วนของไลเซนส์ แต่ควรตรวจสอบว่าแอปพลิเคชันไม่มีการนำความสามารถจาก dependency ที่มีไลเซนส์ที่มีข้อจำกัดไปใช้ในทางที่ไม่เหมาะสม (เช่น SGPL หรือไลเซนส์ที่ต้องเปิด source code ทั้งหมด)
    • ระวังการดึงและติดตั้ง library จากแหล่งที่ไม่น่าเชื่อถือ

ประเด็นด้านความปลอดภัยโดยรวม

  1. Environment Variables
    • ให้แน่ใจว่าข้อมูลที่เป็นความลับ (เช่น api_key) ถูกจัดการผ่าน environment variables เท่านั้น และไม่มี hard-coded ในโค้ดหรือไฟล์ใดๆ
  2. Dependency Audit
    • ตรวจสอบ library หรือ dependency ที่เพิ่มเข้ามาใหม่ว่าปลอดภัยหรือไม่ (เช่น การตรวจสอบ CVE - Common Vulnerabilities and Exposures)
  3. Validation ของ API URL
    • สำหรับ api_url ควรมีการตรวจสอบความถูกต้องของค่า (validation) ก่อนนำไปใช้งาน เพื่อป้องกันการใช้ URL ที่ไม่เหมาะสมที่อาจนำไปสู่การโจมตีเช่น Server-Side Request Forgery (SSRF)

สรุปการปรับปรุง

  • ปรับปรุงเอกสารให้ครอบคลุมข้อมูลของโมเดลและ provider ใหม่
  • ตรวจสอบความปลอดภัยในส่วนการจัดการ API Key และ Environment Variables
  • ตรวจสอบ dependency ทั้งหมดเพื่อแน่ใจว่าไม่มีความเสี่ยงหรือปัญหาด้านไลเซนส์
  • ใช้ validation และการควบคุมการตั้งค่าที่เกี่ยวข้องกับ API อย่างเหมาะสม

หากมีคำถามเพิ่มเติมเกี่ยวกับคำแนะนำหรือส่วนใดเพิ่มเติม แจ้งได้ครับ! 😊

@nattbl49
nattbl49 merged commit ab1b9c4 into main Jul 10, 2026
2 of 3 checks passed

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

View 6 additional findings in Devin Review.

Open in Devin Review

Comment thread action.yml
description: "AI provider shorthand: copilot, github-models, openai, anthropic, openrouter, ollama, xai, zai, google, azure, aws, custom — sets api_url and api_type defaults automatically (azure/aws require api_url). Use github-models to authenticate with GITHUB_TOKEN without needing a personal PAT."
required: false
default: "github-models"
default: "github-azure-models"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Default provider in the action definition doesn't match what the documentation promises

The action's default provider is set to github-azure-models (action.yml:29) but the README documents the default as github-models, so users relying on the documented default will unknowingly hit a different API endpoint.

Impact: Users following the Quick Start guide without specifying a provider will connect to the Azure-hosted endpoint instead of the documented GitHub-hosted endpoint, which may behave differently or require different permissions.

Inconsistency between action.yml and README

The README at line 41 states:

| `provider` | | `github-models` | AI provider shorthand (see [Providers](#providers)) |

But action.yml:29 sets:

default: "github-azure-models"

The github-azure-models provider resolves to https://models.inference.ai.azure.com while github-models resolves to https://models.github.ai/inference. These are different endpoints. Additionally, github-azure-models is not listed in the README's Providers table at all, so users have no documentation for the actual default behavior.

Prompt for agents
The action.yml default provider is set to 'github-azure-models' but the README documents the default as 'github-models'. Either update action.yml line 29 to use 'github-models' as the default (matching the README), or update the README to document 'github-azure-models' as the default and add it to the Providers table. The choice depends on which endpoint is preferred for the default zero-config experience.
Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants