Skip to content

feat(github): add travnie activity source - #471

Merged
trvny merged 5 commits into
mainfrom
feat/github-travnie-activity
Oct 4, 2026
Merged

trvny merged 5 commits into
mainfrom
feat/github-travnie-activity

Conversation

@trvny

@trvny trvny commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Adds the requested GitHub organization activity source without committing or using the legacy private Atom token.

  • keeps the existing Star History Beehiiv feed unchanged because it is already registered exactly
  • adds tokenless public travnie organization events from GitHub's public Events API
  • deliberately excludes public: false events because Feedseek publishes tracked public feeds
  • updates the existing scraper registry test and adds regression coverage for the requested Beehiiv source and event normalization

The authenticated private organization dashboard cannot be mirrored 1:1 into a public Feedseek feed without exposing private activity metadata, so this PR intentionally uses the public subset only.

Summary by CodeRabbit

  • 新功能
    • 新增 Travnie 的 GitHub 公开活动源,可查看活动标题、日期和相关链接。
    • 活动条目会过滤私有事件及已知链接,并限制数量;推送、评论、评审和讨论等活动会显示各自对应的标题与链接。

@mergify

mergify Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again.

@deepsource-io

deepsource-io Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in f5849b4...f0dff18 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
JavaScript Oct 4, 2026 10:44p.m. Review ↗
Python Oct 4, 2026 10:44p.m. Review ↗
Shell Oct 4, 2026 10:44p.m. Review ↗
Secrets Oct 4, 2026 10:44p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated
Comment thread tests/test_github_requested_sources.py Outdated
Comment thread tests/test_github_requested_sources.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c4adda8790

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py
Comment thread feed_generators/github.py Outdated
@gptomek
gptomek Bot force-pushed the feat/github-travnie-activity branch 2 times, most recently from cdf5981 to 1b92958 Compare October 4, 2026 21:07

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cdf5981024

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated
@kanarek-companion

kanarek-companion Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

🐤 Kanarek · 🟣 merged

main ✅

Code is in the nest. The machinery may rest.

Feedseek · 3 files

Comment thread feed_generators/github.py Outdated
@gptomek
gptomek Bot force-pushed the feat/github-travnie-activity branch from af47c5f to bb753e4 Compare October 4, 2026 21:13

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af47c5f317

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread feed_generators/github.py Outdated
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2542a475-b61b-4fc5-b1e9-0c1a87a6202b
📥 Commits

Reviewing files that changed from the base of the PR and between f5849b4 and 15028ed.

📒 Files selected for processing (3)
  • feed_generators/github.py
  • tests/test_github_requested_sources.py
  • tests/test_github_sources.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

新增 Travnie GitHub 活动源。抓取器从公开 Events API 请求事件,过滤非公开及无效事件,将有效事件转换为 Feed 条目,并注册到额外抓取器列表。代码还更新来源配额、来源列表和主 Feed 描述,并设置主 Feed 不按标题去重。新增测试覆盖请求、事件转换、来源注册及去重配置。

Sequence Diagram(s)

sequenceDiagram
  participant GitHubFeed
  participant scrape_travnie_activity
  participant GitHubEventsAPI
  GitHubFeed->>scrape_travnie_activity: 调用已注册的抓取器
  scrape_travnie_activity->>GitHubEventsAPI: 请求 Travnie 公开事件
  GitHubEventsAPI-->>scrape_travnie_activity: 返回事件列表
  scrape_travnie_activity-->>GitHubFeed: 返回规范化条目
Loading

Priority: ⬇️ Low

Change: Feature

Merge Risk: ⚪ Minimal · up to 15028

The Travnie source can proceed with normal checks; the supplied evidence does not establish a merge-blocking regression.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 15028

The new source uses public GitHub activity without private-access credentials. No security regression was established, but downstream rendering, link enrichment, and concurrent publication behavior remain incompletely verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — Users able to generate activity represented in the public organization API can influence derived feed text and GitHub page links. The directly supported exposure is the combined GitHub feed, its persistent cache, and the generator's existing enrichment path; the new producer introduces no write-capable GitHub authority.

Trust Boundaries and Controls

  • observed — The initial API destination is fixed. Payload page links must begin with https://github.com/, and fallback links use that host. Published text is generated from selected event metadata rather than copied comment bodies, and XML-invalid control characters are removed. That sanitizer alone does not establish safe HTML rendering.
  • observed — Event links also reach the existing image-backfill path, not only feed readers. That path fetches entry URLs with redirects enabled. The initial GitHub-host restriction therefore does not itself prove a downstream destination restriction; no attacker-controlled redirect bypass was established.

Resilience and Maintainability Implications

  • observed — The source quota bounds Travnie's contribution to visible output. The inherited image-enrichment path limits batches and records transient attempts, and enrichment exceptions are caught rather than allowed to fail feed generation.

Hardening Proposals

  • proposed — As defense in depth, require an explicit public=true before publication, particularly if the endpoint or authentication policy changes later. This would reduce reliance on upstream schema guarantees; it is not remediation for a demonstrated private-data leak.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 38.10% which is insufficient. The required threshold is 50.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed 标题准确概括了新增 travnie GitHub 活动源这一主要变更,且简洁明确。
Description check ✅ Passed 描述说明了新增公开活动源、排除私有事件的原因,以及相关测试变更,与本次改动相关。
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

我是小兔,跳到代码旁,
公开事件送进篮筐。
推送有标题,评论有锚点,
无效条目不入场。
新来源并入 Feed 行列,
月光下我抱着胡萝卜歌唱。

Comment @coderabbitai help to get the list of available commands.

@gptomek
gptomek Bot force-pushed the feat/github-travnie-activity branch from 8b2d30f to f910dcc Compare October 4, 2026 21:16

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8b2d30f1f6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated
@gptomek
gptomek Bot force-pushed the feat/github-travnie-activity branch from 715c97a to 15028ed Compare October 4, 2026 21:21

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 715c97a3ae

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated
Comment thread feed_generators/github.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f0dff188fb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread feed_generators/github.py
@trvny
trvny merged commit c0a5dfd into main Oct 4, 2026
3 checks passed
@trvny
trvny deleted the feat/github-travnie-activity branch October 4, 2026 22:54

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 91c2e77791

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread feed_generators/github.py
parsed.fragment,
)
)
return f"{base_link}#feedseek-event-{quote(event_id, safe='')}"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep event IDs out of canonical links

When an event target lacks a real fragment—such as a push commit, pull request, release, or wiki page—this appends a fabricated #feedseek-event-* anchor and publishes it as the Atom/JSON Feed alternate link, so consumers receive a noncanonical URL and browsers attempt to navigate to a nonexistent page anchor. Fresh evidence after the earlier event-identity comments is that the finalized helper stores the ID in link itself; keep base_link as the canonical link and use the event ID as a separate persisted identity and merge key.

AGENTS.md reference: AGENTS.md:L13-L13

Useful? React with 👍 / 👎.

Comment thread feed_generators/github.py
"DeleteEvent": "deleted a ref from",
"DiscussionCommentEvent": "commented on a discussion in",
"ForkEvent": "forked",
"GollumEvent": "updated wiki pages in",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve wiki creation actions

When a GollumEvent contains a page whose action is created, this hardcoded title says the actor merely “updated wiki pages,” silently losing the creation fact. GitHub's event schema explicitly distinguishes created from edited in payload.pages[].action, so derive the title from those page actions instead of assigning every wiki event the same verb.

AGENTS.md reference: AGENTS.md:L14-L14

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant