Conversation
…ibutors (CM-1824) Signed-off-by: Mouad BANI <mouad-mb@outlook.com>
…ark (CM-1824) Signed-off-by: Mouad BANI <mouad-mb@outlook.com>
…-1824) Signed-off-by: Mouad BANI <mouad-mb@outlook.com>
Signed-off-by: Mouad BANI <mouad-mb@outlook.com>
PR SummaryMedium Risk Overview Schema migration adds nullable Wires Reviewed by Cursor Bugbot for commit 362bc8a. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Page-local aggregation can corrupt commit totals, and completed activity retries can fail due to the persisted watermark.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds daily Tinybird-to-packages-db synchronization for repository commit contributors.
Changes:
- Adds contributor schema and watermark state.
- Implements full/incremental synchronization and mapping.
- Registers Temporal workflows, schedules, and tests.
| File | Description |
|---|---|
backend/src/osspckgs/migrations/V1790954467__repo_contributors_git_activity.sql |
Adds contributor metrics and sync state. |
services/apps/packages_worker/src/activities.ts |
Exports the sync activity. |
services/apps/packages_worker/src/bin/security-contacts-worker.ts |
Registers the new schedules. |
services/apps/packages_worker/src/member-contributors/activities.ts |
Exposes the member-contributor activity. |
services/apps/packages_worker/src/member-contributors/git-activity/mapRows.ts |
Maps Tinybird rows to contributors. |
services/apps/packages_worker/src/member-contributors/git-activity/readCommitContributors.ts |
Implements Tinybird keyset paging. |
services/apps/packages_worker/src/member-contributors/git-activity/syncGitActivityContributors.ts |
Implements synchronization and reconciliation. |
services/apps/packages_worker/src/member-contributors/schedule.ts |
Defines full and incremental schedules. |
services/apps/packages_worker/src/member-contributors/workflows.ts |
Adds the Temporal workflow. |
services/apps/packages_worker/src/member-contributors/__tests__/syncGitActivityContributors.test.ts |
Tests mapping and synchronization behavior. |
services/apps/packages_worker/src/workflows/index.ts |
Exports the workflow. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 2ccbe53. Configure here.
Signed-off-by: Mouad BANI <mouad-mb@outlook.com>
…824) Signed-off-by: Mouad BANI <mouad-mb@outlook.com>
Review Feedback AddressedChanges Made
No Change Needed
Threads Resolved3 of 3 unresolved threads addressed in this iteration. |
…snapshot (CM-1824) Signed-off-by: Mouad BANI <mouad-mb@outlook.com>
Review Feedback AddressedCommit: 362bc8a Changes Made
Threads Resolved1 of 1 unresolved thread addressed in this iteration. |



Summary
Second half of CM-1824, consuming the Tinybird snapshot shipped in #4886 (
repo_commit_contributors_copy_ds, now live inlfx_insights).Adds
git_activityrows torepo_contributors: onecommit-authorrow per repo and identity, for every repo crowd.dev tracks, with the CDP member id and the first/last commit timestamps (authored + co-authored). Bots, team members and organization profiles are already excluded upstream by the cleaned Tinybird source.Changes
V1790954467: nullablecdp_member_id UUIDonrepo_contributors, plusrepo_contributors_sync_state (source PK, watermark, updated_at).member-contributors/git-activity/: pages the Tinybird datasource in sorting-key order with a 4-column keyset cursor, mapschannelto a packages-db repo (same canonicalisation as the governance sync) andusernameto anemailorgithub-loginidentity, upserts withcdp_member_id;first_seen_at/last_seen_atuseLEAST/GREATESTso channel spelling variants of one repo widen the window instead of overwriting it.security-contacts-workerqueue, next to the governance sync:git-activity-contributors-incremental-sync,0 6 2-14,16-31 * *git-activity-contributors-full-sync,0 6 1,15 * *How the incremental sync works
lastUpdatedAt = max(activityRelations.updatedAt), which moves on ingestion and on member merges.max(computedAt)and throws if the snapshot is empty or not newer than the stored watermark, so a copy job that did not run is loud instead of silently reprocessing the same data.lastUpdatedAt > watermark - 1 dayand upsert them. Nothing is deleted.updated_at = NOW(), thengit_activityrows withupdated_at < run startare deleted. This closes the gaps a pure watermark cannot see (bot flag flips, repos disabled or re-enabled, identities absorbed by a merge, hard-deleted activities).git_activityrows would be deleted, which is what a truncated-but-non-empty snapshot (truncate + Sequin backfill during the copy) looks like.Deployment
CROWD_TINYBIRD_BASE_URLandCROWD_TINYBIRD_ACTIVITIES_TOKENmust be present in thesecurity-contacts-workerdeployment, and the token needs read access torepo_commit_contributors_copy_ds. To be checked after deploy.Depends on #4886 (merged).