Conversation
Typing analysisNote: Ignored files are excluded from the next sections.
|
|
✅ All CI checks and tests passed. 🎉 All green!🧪 All tests passed 🎯 Code Coverage (details) 🔗 Commit SHA: 03f8e22 | Docs | View more details | Give us feedback! |
* Apply sensitive data redaction to RubyLLM
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new code breaks a marked public API and has a reproducible missing json dependency.
Review effort: Balanced
Findings: 1
Open (6)
Preserve backward compatibility for the public assistant API · New Load JSON dependency before calling JSON.generate · New Match Matrixfile quoting and trailing-comma conventions · New Define the concrete type for text-part serialization · New Define an explicit type for serialized tool-call records · New Define the concrete type for tool-call serialization · New
What changed in this PR
Adds default-on sensitive-data redaction to AI Guard evaluations and RubyLLM 2.x integration flows.
Changes:
- Adds typed redaction parsing, application, outcomes, telemetry, and configuration.
- Updates RubyLLM instrumentation to redact provider prompts and tool-call arguments.
- Refactors evaluation transport and message serialization APIs.
| File | Description |
|---|---|
vendor/rbs/ruby_llm/0/ruby_llm.rbs |
Updates RubyLLM 2.x types. |
unreleased/20260928082914.json |
Notes RubyLLM 2.x requirement. |
unreleased/20260928082908.json |
Announces redaction. |
supported-configurations.json |
Registers the redaction setting. |
spec/datadog/ai_guard/redaction/result_spec.rb |
Tests redaction state. |
spec/datadog/ai_guard/redaction/replacements_spec.rb |
Tests replacement normalization. |
spec/datadog/ai_guard/metrics/telemetry_spec.rb |
Tests telemetry metrics. |
spec/datadog/ai_guard/http_client_spec.rb |
Updates client tests. |
spec/datadog/ai_guard/evaluation/result_spec.rb |
Tests refactored results. |
spec/datadog/ai_guard/evaluation/response_spec.rb |
Tests response parsing. |
spec/datadog/ai_guard/evaluation/request_spec.rb |
Tests request serialization. |
spec/datadog/ai_guard/evaluation/outcome_spec.rb |
Tests blocking decisions. |
spec/datadog/ai_guard/evaluation/message_spec.rb |
Tests message serialization. |
spec/datadog/ai_guard/evaluation/client_spec.rb |
Tests evaluation orchestration. |
spec/datadog/ai_guard/evaluation_spec.rb |
Tests end-to-end redaction. |
spec/datadog/ai_guard/contrib/ruby_llm/redaction_change_set_spec.rb |
Tests safe RubyLLM changes. |
spec/datadog/ai_guard/contrib/ruby_llm/message_adapter_spec.rb |
Tests message conversion. |
spec/datadog/ai_guard/contrib/ruby_llm/chat_instrumentation_spec.rb |
Tests RubyLLM instrumentation. |
spec/datadog/ai_guard/configuration/settings_spec.rb |
Tests redaction configuration. |
spec/datadog/ai_guard/component_spec.rb |
Tests HTTP client wiring. |
spec/datadog/ai_guard_spec.rb |
Tests public helpers. |
sig/datadog/core/configuration/settings.rbs |
Types the new setting. |
sig/datadog/ai_guard/redaction/result.rbs |
Types redaction results. |
sig/datadog/ai_guard/redaction/replacements.rbs |
Types replacement parsing. |
sig/datadog/ai_guard/redaction.rbs |
Types redaction operations. |
sig/datadog/ai_guard/metrics/telemetry.rbs |
Types telemetry reporting. |
sig/datadog/ai_guard/http_client.rbs |
Types the renamed client. |
sig/datadog/ai_guard/ext.rbs |
Types the redaction tag. |
sig/datadog/ai_guard/evaluation/tool_call.rbs |
Updates tool-call types. |
sig/datadog/ai_guard/evaluation/result.rbs |
Updates result types. |
sig/datadog/ai_guard/evaluation/response.rbs |
Adds response types. |
sig/datadog/ai_guard/evaluation/request.rbs |
Updates request types. |
sig/datadog/ai_guard/evaluation/outcome.rbs |
Types evaluation outcomes. |
sig/datadog/ai_guard/evaluation/no_op_result.rbs |
Updates no-op result types. |
sig/datadog/ai_guard/evaluation/message.rbs |
Updates message types. |
sig/datadog/ai_guard/evaluation/content_part.rbs |
Types content serialization. |
sig/datadog/ai_guard/evaluation/client.rbs |
Types evaluation client. |
sig/datadog/ai_guard/evaluation.rbs |
Updates evaluation signatures. |
sig/datadog/ai_guard/contrib/ruby_llm/redaction_change_set.rbs |
Types RubyLLM changes. |
sig/datadog/ai_guard/contrib/ruby_llm/message_adapter.rbs |
Types the adapter. |
sig/datadog/ai_guard/contrib/ruby_llm/chat_instrumentation.rbs |
Updates instrumentation types. |
sig/datadog/ai_guard/configuration/ext.rbs |
Types the environment constant. |
sig/datadog/ai_guard/component.rbs |
Updates component types. |
sig/datadog/ai_guard/api_client.rbs |
Removes obsolete client types. |
sig/datadog/ai_guard.rbs |
Updates public API signatures. |
Matrixfile |
Updates RubyLLM test coverage. |
lib/datadog/core/configuration/supported_configurations.rb |
Registers the environment variable. |
lib/datadog/ai_guard/redaction/result.rb |
Implements redaction results. |
lib/datadog/ai_guard/redaction/replacements.rb |
Normalizes backend replacements. |
lib/datadog/ai_guard/redaction.rb |
Applies replacements. |
lib/datadog/ai_guard/metrics/telemetry.rb |
Reports evaluation metrics. |
lib/datadog/ai_guard/http_client.rb |
Renames the HTTP client. |
lib/datadog/ai_guard/ext.rb |
Adds the redaction span tag. |
lib/datadog/ai_guard/evaluation/tool_call.rb |
Serializes tool arguments. |
lib/datadog/ai_guard/evaluation/result.rb |
Separates result data. |
lib/datadog/ai_guard/evaluation/response.rb |
Parses backend responses. |
lib/datadog/ai_guard/evaluation/request.rb |
Builds request bodies. |
lib/datadog/ai_guard/evaluation/outcome.rb |
Encapsulates blocking state. |
lib/datadog/ai_guard/evaluation/no_op_result.rb |
Preserves unevaluated messages. |
lib/datadog/ai_guard/evaluation/message.rb |
Supports multiple tool calls. |
lib/datadog/ai_guard/evaluation/content_part.rb |
Serializes content parts. |
lib/datadog/ai_guard/evaluation/client.rb |
Orchestrates evaluation and redaction. |
lib/datadog/ai_guard/evaluation.rb |
Reports redacted evaluation data. |
lib/datadog/ai_guard/contrib/ruby_llm/redaction_change_set.rb |
Rebuilds redacted RubyLLM messages. |
lib/datadog/ai_guard/contrib/ruby_llm/patcher.rb |
Loads the adapter. |
lib/datadog/ai_guard/contrib/ruby_llm/message_adapter.rb |
Converts RubyLLM messages. |
lib/datadog/ai_guard/contrib/ruby_llm/integration.rb |
Requires RubyLLM 2.0+. |
lib/datadog/ai_guard/contrib/ruby_llm/chat_instrumentation.rb |
Redacts provider and tool inputs. |
lib/datadog/ai_guard/configuration/ext.rb |
Adds the environment variable. |
lib/datadog/ai_guard/configuration.rb |
Adds the redaction option. |
lib/datadog/ai_guard/component.rb |
Wires new AI Guard components. |
lib/datadog/ai_guard.rb |
Updates public construction helpers. |
gemfiles/ruby_4.0_ruby_llm_min.gemfile.lock |
Locks RubyLLM 2.0 dependencies. |
gemfiles/ruby_4.0_ruby_llm_min.gemfile |
Sets RubyLLM minimum version. |
gemfiles/ruby_3.4_ruby_llm_min.gemfile.lock |
Locks RubyLLM 2.0 dependencies. |
gemfiles/ruby_3.4_ruby_llm_min.gemfile |
Sets RubyLLM minimum version. |
gemfiles/ruby_3.3_ruby_llm_min.gemfile |
Sets RubyLLM minimum version. |
gemfiles/ruby_3.2_ruby_llm_min.gemfile |
Sets RubyLLM minimum version. |
gemfiles/ruby_3.1_ruby_llm_min.gemfile |
Sets RubyLLM minimum version. |
docs/GettingStarted.md |
Documents redaction configuration. |
appraisal/ruby-4.0.rb |
Updates RubyLLM appraisal. |
appraisal/ruby-3.4.rb |
Updates RubyLLM appraisal. |
appraisal/ruby-3.3.rb |
Updates RubyLLM appraisal. |
appraisal/ruby-3.2.rb |
Updates RubyLLM appraisal. |
appraisal/ruby-3.1.rb |
Updates RubyLLM appraisal. |
.gitlab-ci.yml |
Updates the system-tests pin. |
.github/workflows/system-tests.yml |
Updates system-tests workflow pins. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
BenchmarksBenchmark execution time: 2026-09-29 10:11:13 Comparing candidate commit b918575 in PR branch Found 0 performance improvements and 0 performance regressions! Performance is the same for 52 metrics, 0 unstable metrics.
|
y9v
left a comment
There was a problem hiding this comment.
nice! The code looks way cleaner now
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2dda3a9cbd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| desired_execution_time: 300 # 5 minutes | ||
| scenarios_groups: tracer_release | ||
| ref: 70f36a2a612d0f9e98af5f4882142e941ae09717 # Automated: Updated by .github/workflows/update-system-tests.yml. | ||
| ref: 7624ea2919a72738a2e923adbdf9c2d538bc4ae2 # Automated: Updated by .github/workflows/update-system-tests.yml. |
There was a problem hiding this comment.
This ref is not merged yet on system-tests. We had a case yesterday of merging such a thing by accident, causing the CI to fail on every system-tests PR. Please revert this or merge it on system-tests before merging this here. There will be a job to prevent this in the future but it's not merged yet:
DataDog/system-tests#7874
There was a problem hiding this comment.
There is a dead-lock, this PR heavily changing AI Guard interface and gem requirements due to non GA status, ST will be never green on prod environment because I have to change weblogs, hence I can't merge it
|
@vpellan Could you please take a minute and read through PR description please, we heavily changed the AI Guard interface as it's not GA so far and we don't want to fall into the trap. System tests are unable to pass on prod due to that refactoring, but that's OK in this case. Thanks ❤️ P.S I've resolved Codex comments as they refer to my note above |



What does this PR do?
This PR introduces Sensitive Data Redaction implementation with AI Guard upgrade.
Motivation:
During chat with LLM some sensitive data might escape, so we catch it before it's too late 🛡️
Change log entry
Yes.
Additional Notes:
This PR contains many changes, during discussion we come to agreement to keep it in one PR to avoid design drift. I will highlight few adjustments worth mention.
Design changes:
AIGuard::APIClientrenamed intoAIGuard::HTTPClientAIGuard::Evaluation::Clienttakes a role of a glue between SDK and BackendAIGuard::ToolCall,AIGuard::Message,AIGuard::ContentParttake responsibility fromAIGuard::Requestof their own representation as aHashAIGuard::ToolCall,AIGuard::Message,AIGuard::ContentPartgot methodwith_*to generate new instance with replaced dependenciesAIGuard::RequestandAIGuard::Responsenow have clear separation of concernsAnd additional to the RFC I took a step forward and introduced redaction back to the RubyLLM (not only to the model). Because of that a few missing abstractions pops up and a few limitations that goes beyond this PR.
Features outside RFC:
AIGuard::Contrib::RubyLLM::RedactionChangeSetAIGuard::Contrib::RubyLLM::ChatInstrumentationBug fixes:
How to test the change?
CI + ST