Skip to content

feat(infra): add github pr event feed - #7403

Closed
t3-code[bot] wants to merge 2 commits into
mainfrom
feat/github-pr-event-feed
Closed

t3-code[bot] wants to merge 2 commits into
mainfrom
feat/github-pr-event-feed

Conversation

@t3-code

@t3-code t3-code Bot commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

what changed

  • adds a standalone cloudflare worker at infra/github-events
  • verifies github webhook hmac signatures and normalizes pull request, comment, review, check, workflow, and status events
  • stores an ordered, deduplicated 512-event replay window in a per-repository sqlite durable object
  • exposes an authenticated sse feed with sequence resume and optional pull request filtering
  • documents deployment, github webhook setup, subscription, replay, security, and limits

why

pr babysitters currently need to poll github independently, which wastes rate limit and duplicates work. this gives contributors one authenticated stream with the event content needed to react to pr activity.

verification

  • vp fmt --check infra/github-events docs/operations/github-pr-event-feed.md
  • vp lint infra/github-events
  • vp run --filter t3code-github-events typecheck
  • focused vitest suite: 27 tests passed
  • local wrangler integration: signed webhooks returned 202, live sse emitted comment content, replay streamed sequences 1 through 10 in order, duplicate delivery emitted no second event, a sha-only status inherited pr 42 from the association index, a future cursor returned 409, invalid feed auth returned 401, and /health returned 200

deployment

not deployed from this pr. production setup needs cloudflare credentials plus fresh webhook and feed secrets, followed by the github repository webhook configuration documented in docs/operations/github-pr-event-feed.md.

checklist

  • this pr is focused on one deployable service
  • behavior and operational setup are documented
  • security, replay, normalization, and subscription paths are tested

request provenance


Note

Medium Risk
New internet-facing webhook and token-authenticated SSE surface with HMAC verification and fail-closed config, but mishandling could leak or drop PR automation events; deployment and secret rotation are operational dependencies.

Overview
Adds a new infra/github-events Cloudflare Worker so PR babysitters can subscribe to GitHub activity instead of polling the API.

The worker accepts signed webhooks at /v1/github/webhook, normalizes PR-related deliveries (comments, reviews, checks, workflows, statuses), and forwards them to a per-repo GitHubEventHub Durable Object. The hub stores an ordered replay window (512 events), deduplicates deliveries (10k ids), enriches SHA-only CI/status events from a head-sha→PR index, and streams github SSE messages from /v1/repos/{owner}/{repo}/events with bearer auth, optional pull filtering, and resume via Last-Event-ID / after (including 410 / 409 cursor errors).

docs/operations/github-pr-event-feed.md documents deploy secrets, GitHub webhook setup, subscription examples, event envelope, and security limits. Alchemy wiring lives in alchemy.run.ts; behavior is covered by unit tests across normalization, signatures, HTTP handling, event log, and SSE formatting.

Reviewed by Cursor Bugbot for commit 2c46d3c. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add GitHub PR event feed service as a Cloudflare Worker with SSE streaming

  • Adds a new Cloudflare Worker at infra/github-events that receives GitHub webhook deliveries, normalizes them, and fans them out to subscribers via Server-Sent Events.
  • The GitHubEventHub Durable Object persists events in SQLite, deduplicates by delivery ID, maintains a rolling retention window, and streams retained+live events to SSE consumers with optional PR-number filtering and cursor-based resume.
  • POST /v1/github/webhook verifies HMAC-SHA256 signatures, enforces a 512 KiB / 10-second body limit, normalizes eight GitHub webhook event types into a canonical envelope, and restricts to a configured repository allowlist.
  • GET /v1/repos/:owner/:repo/events serves SSE with bearer token auth, returning 410 when the resume cursor has expired beyond the retention window.
  • Risk: subscriber count is capped (MAX_SUBSCRIBERS) and PR-head association memory is bounded; overflow drops connections silently.

Macroscope summarized 2c46d3c.

Co-authored-by: Alex Southwell <4596216+saphid@users.noreply.github.com>
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 18, 2026
@github-actions

github-actions Bot commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 12.6 KiB 12.6 KiB +6 B (+0.0%) 15.1 KiB ✅
Codex Thread snapshot wire 6.3 KiB 6.3 KiB −3 B (−0.0%) 7.3 KiB ✅
Codex Live turn WebSocket wire 6.3 KiB 6.3 KiB +9 B (+0.1%) 7.8 KiB ✅
Codex Live turn WebSocket decoded 51.8 KiB 51.8 KiB 0 B (0.0%) 66.4 KiB ✅
Codex Live turn messages 16 16 0 (0.0%) 21 ✅
Claude Total thread wire 12.6 KiB 12.6 KiB −6 B (−0.0%) 15.1 KiB ✅
Claude Thread snapshot wire 6.3 KiB 6.3 KiB +5 B (+0.1%) 7.3 KiB ✅
Claude Live turn WebSocket wire 6.3 KiB 6.3 KiB −11 B (−0.2%) 7.8 KiB ✅
Claude Live turn WebSocket decoded 52.7 KiB 52.7 KiB 0 B (0.0%) 66.4 KiB ✅
Claude Live turn messages 16 16 0 (0.0%) 21 ✅

Baseline: 82b8a93 · PR result: 2c46d3c · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 99.9 KiB
  • Claude decoded thread snapshot: 100.6 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Co-authored-by: Alex Southwell <4596216+saphid@users.noreply.github.com>
@macroscopeapp

macroscopeapp Bot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR introduces a new Cloudflare Worker service with production deployment, webhook signature verification, and bearer token authentication. New infrastructure capabilities with security-sensitive operations warrant human review.

You can add or adjust custom eligibility rules. Learn more.

@t3dotgg

t3dotgg commented Aug 28, 2026

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

This adds a separate GitHub webhook, Durable Object event log, SSE service, deployment workflow, and operations runbook. T3 Code does not need a second pull-request event service for its current operation.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL 1,000+ changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant