Skip to content

feat: add repository and contributor detail views - #504

Merged
exploreriii merged 3 commits into
mainfrom
entity-detail-views
Sep 30, 2026
Merged

exploreriii merged 3 commits into
mainfrom
entity-detail-views

Conversation

@danielmarv

@danielmarv danielmarv commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Description:

Add detail views for individual repositories and contributors, opened from their names anywhere on the dashboard, backed by period-accurate activity computed from the persisted events and published through the data API.

  • Add an entity_activity pipeline (offline-capable, every org). It counts each repository's, contributor's and (repository, contributor) pair's tracked actions for Week, 1 month, 1 year and all time, plus monthly trends. Each window is counted from its own events, so distinct active contributors are exact.

  • Publish, additively within v1, per-org repository and contributor indexes (manifest.orgs.<org>.entities) and one lazily fetched detail document per entity. Each document states its source, generation time, freshness, population, methodology, limits and window dates. Periods with no activity are published as zeros.

  • Join the optional per-repository tables into a repository's view:

    • releases
    • governance: role counts, active permission-holders, organisation mix, review load, CODEOWNERS and role holders
    • HIP engagement
    • onboarding: open issues by difficulty, untriaged included
    • OpenSSF Scorecard

    A table a run did not produce is named as unavailable, and each section links back to the dashboard sections it summarises.

  • Add the repository and contributor views. Each shows counts by period, work mix, the monthly trend, the contributor or repository breakdown with period tabs and CSV export, and a methodology card. It states that tracked activity covers PR authoring, reviews, merges, issue creation and label applications, and does not measure commits, comments, reactions or individual performance.

  • Make repository and contributor names in tables, heatmaps, ranking and release-timeline axes, chart Data views and the network panel open the view, with a separate GitHub link beside each. A name with no tracked activity opens a view that says so.

  • Keep navigation in the URL (entity=repo:<id> / entity=contributor:<id>), so shared links, Back and Forward work. Switching tab closes the view, switching org clears it with the focus, and "Focus the dashboard on …" sets the focus and returns to the tab in one step.

  • Hold a section jump (#widget=, used by shared links and the new source links) on its target while charts above it load, so it no longer lands short.

  • Add chart_document(table=…) so a timeseries or categories chart can be built from an in-memory slice.

  • Cover the calculations, documents, contract, navigation and rendering with tests, and document the data model in docs/entity-views.md.

Related issue(s):

Fixes #503
Fixes #357

Notes for reviewer:

  • Design.
    • Counting. Counts reuse combined_activity_events and the same definitions as the contributor profiles. Merges are credited to the merger; label removals and automation accounts are excluded.
    • Layering. analysis/entity_activity.py is pure. pipelines/entity_activity.py writes five org-level CSVs with sidecars. export/entity_views.py builds the documents from them, and data_api is still the only writer. dashboard_spec/entities.py declares the files, wording and joined tables as data.
    • No aggregation in the browser. Every number comes from the entity's own document.
    • Why this shape. This follows Per-repo insight: a detail-on-demand repo view reachable from any repo name #357's recommended option: per-entity documents assembled from CSVs the emit already reads, rather than a client-side join over other sections' documents.
  • Compatibility.
    • Additive only: new manifest key, new files under <org>/entities/, and new optional document fields.
    • SectionTable accepts any section-shaped table (TableDoc).
    • PrintControls takes an optional label.
    • The entities/ tree is rewritten on each emit, so no stale documents are left behind.
  • Size.
    • hiero-ledger publishes about 1,500 detail documents, which brings the API to about 24 MB across about 1,660 files (1.3 MB gzipped).
    • Most documents change on every refresh, so the snapshot branch will grow faster; this is noted in docs/snapshots.md.
  • Checked on the real datasets.
    • hiero-ledger has 328,373 events, producing 42 repositories and 1,473 contributors. The pipeline takes about 2.5 s.
    • Every repository and person name on every tab opens a view. Back and Forward, source links landing on their section, dark mode, phone width and printing were all checked.
  • Limits of the source data.
    • At most 100 reviews per PR and 100 label events per issue are read.
    • Events whose author GitHub no longer reports are dropped.
    • Windows end when the pipeline runs, so stale datasets undercount the recent windows. The view detects this and warns.
    • Automation accounts that is_bot_login misses (e.g. stepsecurity-app) count as people; see Flag bot-like logins that slip past is_bot_login for review. #410.
  • Tests.
    • Python: 892 tests, 25 new, at 95.8% coverage. Ruff lint and format are clean.
    • Web: 191 tests, 10 new. npm run lint shows only existing warnings, and npm run format:check and npm run build pass.
    • Playwright: 30 tests in each of Chromium and Firefox, 3 new.
  • Screenshots of a repository and a contributor view to follow in a comment.

Checklist

  • I claimed the linked issue with /assign before starting (see contributing guide)
  • uv run pytest and uv run ruff check src tests pass locally
  • Tests added/updated for the change (mirroring the src/ layout)
  • Commits are signed and signed-off: git commit -S -s
  • Docs updated if relevant

Open a detail view for any repository or contributor from its name in
the dashboard's tables and charts, backed by period-accurate activity
computed from the persisted events and published through the data API.

* Add the entity_activity pipeline: tracked actions per repository,
  contributor and (repository, contributor) pair for Week, 1 month,
  1 year and all time, each counted from its own events, plus monthly
  trends
* Publish per-org entity indexes and lazily fetched detail documents
  (additive to API v1) with source, freshness, population, methodology
  and window dates; empty periods are zeros
* Join releases, governance, HIP engagement, onboarding and security
  into a repository's view, naming tables a run did not produce and
  linking each figure back to its dashboard section
* Link repository and contributor names in tables and charts to their
  view, keeping a separate GitHub link; keep navigation in the URL so
  shared links, Back and Forward work
* Hold a section jump on its target while charts above it load
* Cover calculations, documents, contract, navigation and rendering
  with tests; document the data model in docs/entity-views.md

Fixes #503
Fixes #357

Signed-off-by: Ntege Daniel <danientege785@gmail.com>
@danielmarv danielmarv added enhancement New feature or request python Touches Python code (src/, tests/) typescript Touches TypeScript/React code (web/) labels Sep 30, 2026
Comment thread src/hiero_analytics/dashboard_spec/entities.py Fixed
Comment thread src/hiero_analytics/dashboard_spec/entities.py Fixed
Comment thread src/hiero_analytics/dashboard_spec/entities.py Fixed
Comment thread src/hiero_analytics/dashboard_spec/entities.py Fixed
Comment thread src/hiero_analytics/dashboard_spec/entities.py Fixed
Comment thread src/hiero_analytics/dashboard_spec/entities.py Fixed
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

📊 Dashboard preview

The dashboard was built for this PR.

➡️ Download dashboard-preview-504, unzip, then serve it with python3 -m http.server -d . and open the URL it prints. (The app fetches its data over HTTP, so opening index.html directly shows an empty page.)

The artifact is built from this PR — treat it as contributor-authored code and glance at the diff before opening it. It expires after 7 days and is replaced on each new push.

Wrap each multi-line methodology and limits entry in the entity views'
spec in parentheses, as the family modules already do, so an implicit
string concatenation cannot be mistaken for a missing comma. The text of
every entry is unchanged.

Signed-off-by: Ntege Daniel <danientege785@gmail.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: hiero-hackers/analytics/.coderabbit.yml

Review profile: CHILL

Plan: Advanced

Run ID: a1ef69cd-1af7-424f-a43d-cf5ccbbe763a

📥 Commits

Reviewing files that changed from the base of the PR and between 3659fcb and 0b9ada1.

📒 Files selected for processing (4)
  • docs/entity-views.md
  • web/src/components/EntityView.tsx
  • web/src/entities.ts
  • web/src/test/entities.test.tsx
🚧 Files skipped from review as they are similar to previous changes (3)
  • web/src/test/entities.test.tsx
  • docs/entity-views.md
  • web/src/entities.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

This change adds period-based repository and contributor activity data, publishes entity indexes and detail documents, and adds dashboard navigation and detail views. It also adds entity links across tables and charts, print-specific behavior, documentation, and test coverage.

Changes

Entity activity and publication

Layer / File(s) Summary
Activity aggregation and pipeline
src/hiero_analytics/analysis/entity_activity.py, src/hiero_analytics/pipelines/*, tests/analysis/test_entity_activity.py, tests/pipelines/test_entity_activity.py, tests/contracts/test_output_contract.py, README.md
Adds period-based and monthly activity tables for repositories, contributors, and repository-contributor pairs. Registers the pipeline and tests calculations, saved tables, and output coverage.
Entity documents and API publication
src/hiero_analytics/export/*, src/hiero_analytics/dashboard_spec/entities.py, tests/export/test_entity_views.py, tests/contracts/test_output_contract.py, docs/architecture.md, docs/entity-views.md, docs/snapshots.md
Builds and publishes entity indexes and detail documents, adds source-section links and freshness fields, and covers related repository data and document publication.
Entity contracts and dashboard navigation
web/src/api.ts, web/src/entities.ts, web/src/App.tsx, web/src/test/entityFixtures.ts, web/src/test/entities.test.tsx
Adds typed entity documents, index and document loading, URL-based selection, history handling, organization switching, and navigation between details and dashboard sections.
Detail views and entity links
web/src/components/*, web/src/printing.tsx, web/README.md, web/e2e/entities.spec.ts
Adds repository and contributor detail pages, links from tables and charts, print-specific output, loading and error states, and browser coverage.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 0b9ad

No actionable merge-blocking issue remains identified. Unavailable entity indexes now show appropriate states instead of misleading zero-activity results; the change is mergeable subject to normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0b9ad

The new views expose published activity summaries without adding demonstrated write authority or an authorization bypass. Organization-scoped lookup and loading guards limit navigation mistakes. Complete data-exposure and live-publication guarantees remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The effective read exposure encompasses the entity activity and optional governance and security summaries published for every organization on the static site, not just the organization currently selected in the UI. Organization-scoped navigation is not a server-side confidentiality boundary.

Trust Boundaries and Controls

  • observed — Attacker-supplied entity references select indexed rows rather than arbitrary API paths. The matched ID is encoded before template substitution, and missing rows do not trigger detail loading. Routing authority remains with the published directory; document validation checks basic shape but does not independently bind returned organization, kind and ID to the request.

Resilience and Maintainability Implications

  • observed — The asynchronous loader ignores settlements after effect cleanup and renders stored results only when their path matches the current request. Directory results must also match the current organization and retry attempt. These checks contain late-response effects across entity and organization transitions.

Hardening Proposals

  • proposed — Validate document schema version, organization, kind and ID against the selected directory entry before rendering. This would make producer-consumer identity guarantees explicit under malformed or misrouted responses; no such response or exploitable bypass was demonstrated.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 68.15% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 135 functions across 30 files. (1 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely summarizes the main change: adding repository and contributor detail views.
Description check ✅ Passed The description is directly related to the changeset and explains the activity pipeline, entity documents, dashboard views, navigation, testing, and documentation.
Linked Issues check ✅ Passed The PR meets the coding requirements in [#503] and [#357]. The offline entity_activity pipeline computes repository, contributor, and pair activity from persisted events for all required windows and…
Out of Scope Changes check ✅ Passed The changes remain within [#503] and [#357]. Documentation, chart support, printing, fixtures, navigation changes, and tests support the requested detail views and API contract. The PR does not add th…
Full details: Docstring Coverage

Explanation

Docstring coverage is 68.15% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 135 functions across 30 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: hiero-hackers/analytics/.coderabbit.yml

Review profile: CHILL

Plan: Advanced

Run ID: e8ecbb8f-6950-4418-aff5-4aecf2a640a3

📥 Commits

Reviewing files that changed from the base of the PR and between d2ce076 and 3659fcb.

📒 Files selected for processing (35)
  • README.md
  • docs/architecture.md
  • docs/entity-views.md
  • docs/snapshots.md
  • src/hiero_analytics/analysis/entity_activity.py
  • src/hiero_analytics/dashboard_spec/entities.py
  • src/hiero_analytics/export/chart_data.py
  • src/hiero_analytics/export/data_api.py
  • src/hiero_analytics/export/entity_views.py
  • src/hiero_analytics/pipelines/__init__.py
  • src/hiero_analytics/pipelines/entity_activity.py
  • tests/analysis/test_entity_activity.py
  • tests/contracts/test_output_contract.py
  • tests/export/test_chart_data.py
  • tests/export/test_entity_views.py
  • tests/pipelines/test_entity_activity.py
  • web/README.md
  • web/e2e/entities.spec.ts
  • web/src/App.tsx
  • web/src/api.ts
  • web/src/components/ContributorCell.tsx
  • web/src/components/DataTable.tsx
  • web/src/components/EntityLink.tsx
  • web/src/components/EntityView.tsx
  • web/src/components/RepoCell.tsx
  • web/src/components/SectionTable.tsx
  • web/src/components/charts/EntityTick.tsx
  • web/src/components/charts/EventsView.tsx
  • web/src/components/charts/MatrixView.tsx
  • web/src/components/charts/NetworkView.tsx
  • web/src/components/charts/SeriesView.tsx
  • web/src/entities.ts
  • web/src/printing.tsx
  • web/src/test/entities.test.tsx
  • web/src/test/entityFixtures.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

Comment thread web/src/components/EntityView.tsx
A detail view could claim a contributor had no tracked activity when the
contributor index had failed to load, and a shared detail link stayed on
its loading skeleton forever when no index loaded.

* Track each kind's index as loaded, failed or unpublished, with a retry
  that reloads the directory
* Say "no tracked activity" only from a loaded index; show a Retry for a
  failed index and a notice when the org publishes none
* Link names only when their kind's index has loaded
* Cover the failed, retried and unpublished cases with tests

Signed-off-by: Ntege Daniel <danientege785@gmail.com>
@exploreriii
exploreriii merged commit 4b26332 into main Sep 30, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request python Touches Python code (src/, tests/) typescript Touches TypeScript/React code (web/)

Projects

None yet

2 participants