chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes#1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercelLangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:
- Remove the `langfuse-vercel` `LangfuseExporter` registration from
`instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
`registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
along with the now-unused `traceId` prop. `metadata.traceId` is still
produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
metadata. The telemetry block itself is left in place, gated on
`SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
`NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.
Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in:3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s)Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Linked Issues check⚠️ WarningThe PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453.Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Out of Scope Changes check✅ PassedThe changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment threadCHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitaicoderabbitaiBotAug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claudeclaudeBotAug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
`.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

 NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
- NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}- NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2196
Resolved (non-standard)17
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (17)
PackageVersionOriginalResolvedSource
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma2.1.0UNKNOWNMITshipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir1.1.2UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream0.1.0UNKNOWNMITshipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream0.3.1UNKNOWNMITextracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream0.0.11MIT,Apache2(MIT OR Apache-2.0)extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js1.369.0SEE LICENSE IN LICENSE(Apache-2.0 AND MIT)shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url1.0.9UNKNOWNMITshipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into mainAug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes#1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercelLangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:
- Remove the `langfuse-vercel` `LangfuseExporter` registration from
`instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
`registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
along with the now-unused `traceId` prop. `metadata.traceId` is still
produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
metadata. The telemetry block itself is left in place, gated on
`SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
`NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.
Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in:3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s)Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Linked Issues check⚠️ WarningThe PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453.Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Out of Scope Changes check✅ PassedThe changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment threadCHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitaicoderabbitaiBotAug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claudeclaudeBotAug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
`.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

 NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
- NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}- NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2196
Resolved (non-standard)17
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (17)
PackageVersionOriginalResolvedSource
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma2.1.0UNKNOWNMITshipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir1.1.2UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream0.1.0UNKNOWNMITshipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream0.3.1UNKNOWNMITextracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream0.0.11MIT,Apache2(MIT OR Apache-2.0)extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js1.369.0SEE LICENSE IN LICENSE(Apache-2.0 AND MIT)shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url1.0.9UNKNOWNMITshipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into mainAug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes#1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercelLangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:
- Remove the `langfuse-vercel` `LangfuseExporter` registration from
`instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
`registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
along with the now-unused `traceId` prop. `metadata.traceId` is still
produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
metadata. The telemetry block itself is left in place, gated on
`SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
`NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.
Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in:3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s)Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Linked Issues check⚠️ WarningThe PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453.Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Out of Scope Changes check✅ PassedThe changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment threadCHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitaicoderabbitaiBotAug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claudeclaudeBotAug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
`.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

 NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
- NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}- NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2196
Resolved (non-standard)17
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (17)
PackageVersionOriginalResolvedSource
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma2.1.0UNKNOWNMITshipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir1.1.2UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream0.1.0UNKNOWNMITshipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream0.3.1UNKNOWNMITextracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream0.0.11MIT,Apache2(MIT OR Apache-2.0)extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js1.369.0SEE LICENSE IN LICENSE(Apache-2.0 AND MIT)shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url1.0.9UNKNOWNMITshipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into mainAug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes#1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercelLangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:
- Remove the `langfuse-vercel` `LangfuseExporter` registration from
`instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
`registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
along with the now-unused `traceId` prop. `metadata.traceId` is still
produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
metadata. The telemetry block itself is left in place, gated on
`SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
`NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.
Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in:3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s)Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Linked Issues check⚠️ WarningThe PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453.Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Out of Scope Changes check✅ PassedThe changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment threadCHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitaicoderabbitaiBotAug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claudeclaudeBotAug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
`.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

 NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
- NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}- NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2196
Resolved (non-standard)17
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (17)
PackageVersionOriginalResolvedSource
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma2.1.0UNKNOWNMITshipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir1.1.2UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream0.1.0UNKNOWNMITshipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream0.3.1UNKNOWNMITextracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream0.0.11MIT,Apache2(MIT OR Apache-2.0)extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js1.369.0SEE LICENSE IN LICENSE(Apache-2.0 AND MIT)shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url1.0.9UNKNOWNMITshipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into mainAug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes#1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercelLangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:
- Remove the `langfuse-vercel` `LangfuseExporter` registration from
`instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
`registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
along with the now-unused `traceId` prop. `metadata.traceId` is still
produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
metadata. The telemetry block itself is left in place, gated on
`SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
`NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.
Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in:3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s)Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Linked Issues check⚠️ WarningThe PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453.Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Out of Scope Changes check✅ PassedThe changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment threadCHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitaicoderabbitaiBotAug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claudeclaudeBotAug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
`.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

 NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
- NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}- NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2196
Resolved (non-standard)17
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (17)
PackageVersionOriginalResolvedSource
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma2.1.0UNKNOWNMITshipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir1.1.2UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream0.1.0UNKNOWNMITshipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream0.3.1UNKNOWNMITextracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream0.0.11MIT,Apache2(MIT OR Apache-2.0)extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js1.369.0SEE LICENSE IN LICENSE(Apache-2.0 AND MIT)shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url1.0.9UNKNOWNMITshipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into mainAug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes#1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercelLangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:
- Remove the `langfuse-vercel` `LangfuseExporter` registration from
`instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
`registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
along with the now-unused `traceId` prop. `metadata.traceId` is still
produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
metadata. The telemetry block itself is left in place, gated on
`SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
`NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.
Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in:3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s)Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Linked Issues check⚠️ WarningThe PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453.Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Out of Scope Changes check✅ PassedThe changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment threadCHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitaicoderabbitaiBotAug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claudeclaudeBotAug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
`.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

 NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
- NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}- NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2196
Resolved (non-standard)17
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (17)
PackageVersionOriginalResolvedSource
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma2.1.0UNKNOWNMITshipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir1.1.2UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream0.1.0UNKNOWNMITshipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream0.3.1UNKNOWNMITextracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream0.0.11MIT,Apache2(MIT OR Apache-2.0)extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js1.369.0SEE LICENSE IN LICENSE(Apache-2.0 AND MIT)shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url1.0.9UNKNOWNMITshipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into mainAug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes#1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercelLangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:
- Remove the `langfuse-vercel` `LangfuseExporter` registration from
`instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
`registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
along with the now-unused `traceId` prop. `metadata.traceId` is still
produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
metadata. The telemetry block itself is left in place, gated on
`SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
`NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.
Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in:3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s)Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Linked Issues check⚠️ WarningThe PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453.Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Out of Scope Changes check✅ PassedThe changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment threadCHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitaicoderabbitaiBotAug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claudeclaudeBotAug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
`.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

 NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
- NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}- NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2196
Resolved (non-standard)17
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (17)
PackageVersionOriginalResolvedSource
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma2.1.0UNKNOWNMITshipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir1.1.2UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream0.1.0UNKNOWNMITshipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream0.3.1UNKNOWNMITextracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream0.0.11MIT,Apache2(MIT OR Apache-2.0)extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js1.369.0SEE LICENSE IN LICENSE(Apache-2.0 AND MIT)shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url1.0.9UNKNOWNMITshipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into mainAug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes#1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercelLangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:
- Remove the `langfuse-vercel` `LangfuseExporter` registration from
`instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
`registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
along with the now-unused `traceId` prop. `metadata.traceId` is still
produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
metadata. The telemetry block itself is left in place, gated on
`SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
`NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.
Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in:3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s)Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Linked Issues check⚠️ WarningThe PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453.Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Out of Scope Changes check✅ PassedThe changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment threadCHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitaicoderabbitaiBotAug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claudeclaudeBotAug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
`.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

 NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
- NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}- NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2196
Resolved (non-standard)17
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.12(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (17)
PackageVersionOriginalResolvedSource
@sentry/cli2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm2.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i6862.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x642.58.5FSL-1.1-MITFSL-1.1-MITnpm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma2.1.0UNKNOWNMITshipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir1.1.2UNKNOWNApache-2.0shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream0.1.0UNKNOWNMITshipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream0.3.1UNKNOWNMITextracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream0.0.11MIT,Apache2(MIT OR Apache-2.0)extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js1.369.0SEE LICENSE IN LICENSE(Apache-2.0 AND MIT)shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url1.0.9UNKNOWNMITshipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into mainAug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant

@brendan-kellam