feat(backend): add Bull Board metrics history - #1604

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics
Aug 17, 2026
Merged

feat(backend): add Bull Board metrics history#1604
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • upgrade Bull Board packages from 6.11.2 to 9.0.0
  • enable one week of native BullMQ metrics and record long-retention metrics in Redis
  • expose history and latency charts in the read-only Bull Board and stop the recorder cleanly

Validation

  • yarn workspace @sourcebot/backend build
  • yarn workspace @sourcebot/backend test --run

Note

Medium Risk
Major dependency upgrade (Bull Board 6→9, Express 5 for bull-board only) plus new Redis-backed metrics writers; shutdown order changed but scoped to observability and lifecycle.

Overview
Upgrades Bull Board from 6.11.2 to 9.0.0 and adds @bull-board/metrics so the read-only /admin/queues UI can show queue history and latency charts backed by Redis.

The API wires a RedisMetricsHistoryProvider and MetricsRecorder (shared Redis connection, latency errors logged per queue), starts recording at boot, and stops the recorder / disconnects the history provider on shutdown. Graceful shutdown now disposes the API before stopping workers and closing Redis.

BullMQ workers retain one week of native metrics (MetricsTime.ONE_WEEK / 10,080 data points), with a unit test asserting that worker option.

Reviewed by Cursor Bugbot for commit 375c1da. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added queue performance metrics to the monitoring dashboard, including latency tracking and historical data.
    • Metrics history is retained for up to one week for easier trend analysis.
    • Improved metrics handling during application startup and shutdown.
  • Bug Fixes

    • Improved reliability when collecting and displaying queue metrics.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e99c9319-532a-4774-b734-e9eb105c9453

📥 Commits

Reviewing files that changed from the base of the PR and between a135f1a and f28ab2b.

📒 Files selected for processing (1)
  • packages/backend/src/api.ts

Walkthrough

The backend upgrades Bull Board, adds Redis-backed metrics history, configures BullMQ worker metric retention for one week, and updates API startup and shutdown ordering.

Changes

Metrics integration

Layer / File(s)Summary
Worker metrics retention
packages/backend/src/jobManager.ts, packages/backend/src/jobManager.test.ts
Workers retain one week of native BullMQ metrics. Tests verify the maxDataPoints configuration.
Bull Board metrics lifecycle
packages/backend/package.json, packages/backend/src/api.ts, packages/backend/src/index.ts
Bull Board uses Redis-backed metrics history. The API starts and stops metrics recording and disposes metrics resources before Redis shutdown.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
participant Server
participant Api
participant BullBoard
participant RedisMetricsHistory
participant BullMQMetricsRecorder
Server->>Api: initialize API server
Api->>BullBoard: register queue adapters and history provider
Api->>RedisMetricsHistory: configure Redis-backed history
Api->>BullMQMetricsRecorder: start recording
Server->>Api: dispose API
Api->>BullMQMetricsRecorder: stop recording
Api->>RedisMetricsHistory: disconnect history provider
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: adding Bull Board metrics history to the backend.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bull-board-metrics

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

CodeRabbit couldn't update its existing comment. The review summary may be out of date.

Error details
No server is currently available to service your request. Sorry about that. Please try resubmitting your request and contact us if the problem persists.

@github-actions

github-actionsBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2171
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.13(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo (livebook-dev/codemirror-lang-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
khroma2.1.0UNKNOWNMITGitHub repo (fabiospampinato/khroma, GitHub license API: MIT), confirmed by MIT "license" file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo (livebook-dev/lezer-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
map-stream0.1.0UNKNOWNMITGitHub repo (dominictarr/map-stream, GitHub license API: MIT), confirmed by MIT LICENCE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
memorystream0.3.1UNKNOWNMITextracted from object: legacy "licenses": [{"type":"MIT","url":"..."}] field in the npm registry manifest; confirmed by MIT LICENSE file in the published npm tarball
pause-stream0.0.11["MIT", "Apache2"]MIT OR Apache-2.0extracted from array license field ["MIT","Apache2"] in the npm registry manifest; LICENSE file in the published npm tarball states "Dual Licensed MIT and Apache 2" and contains both full texts, so "Apache2" normalizes to Apache-2.0
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file referenced by "SEE LICENSE IN LICENSE" in the published npm tarball: Apache License 2.0 grant (Copyright 2020 PostHog / Hiberly, Inc.). A trailing MIT notice applies only to specific expo/expo-derived files, so the package license is Apache-2.0
valid-url1.0.9UNKNOWNMITMIT LICENSE file in the published npm tarball (verbatim MIT text, Copyright (c) 2013 Odysseas Tsatalos and oDesk Corporation); GitHub repo ogt/valid-url reports NOASSERTION (no metadata) and npmjs.com page blocked automated fetch (HTTP 403)

@brendan-kellam
brendan-kellam merged commit 41d90a4 into mainAug 17, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bull-board-metrics branch August 17, 2026 21:05
@github-actionsgithub-actionsBot mentioned this pull request Aug 17, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

bullBoardAdapter.setBasePath('/admin/queues');
const queueAdapters = jobManager
.getQueues()
.map(queue => new BullMQAdapter(queue));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bull Board loses read-only mode

High Severity

BullMQAdapter instances are created without readOnlyMode: true, so /admin/queues becomes a writable Bull Board. The prior board blocked retries, cleans, pauses, and other mutations; this endpoint still has no auth middleware, so anyone who can reach the worker API can alter job queues. That conflicts with the PR’s “read-only Bull Board” intent.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(backend): add Bull Board metrics history - #1604

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics
Aug 17, 2026
Merged

feat(backend): add Bull Board metrics history#1604
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • upgrade Bull Board packages from 6.11.2 to 9.0.0
  • enable one week of native BullMQ metrics and record long-retention metrics in Redis
  • expose history and latency charts in the read-only Bull Board and stop the recorder cleanly

Validation

  • yarn workspace @sourcebot/backend build
  • yarn workspace @sourcebot/backend test --run

Note

Medium Risk
Major dependency upgrade (Bull Board 6→9, Express 5 for bull-board only) plus new Redis-backed metrics writers; shutdown order changed but scoped to observability and lifecycle.

Overview
Upgrades Bull Board from 6.11.2 to 9.0.0 and adds @bull-board/metrics so the read-only /admin/queues UI can show queue history and latency charts backed by Redis.

The API wires a RedisMetricsHistoryProvider and MetricsRecorder (shared Redis connection, latency errors logged per queue), starts recording at boot, and stops the recorder / disconnects the history provider on shutdown. Graceful shutdown now disposes the API before stopping workers and closing Redis.

BullMQ workers retain one week of native metrics (MetricsTime.ONE_WEEK / 10,080 data points), with a unit test asserting that worker option.

Reviewed by Cursor Bugbot for commit 375c1da. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added queue performance metrics to the monitoring dashboard, including latency tracking and historical data.
    • Metrics history is retained for up to one week for easier trend analysis.
    • Improved metrics handling during application startup and shutdown.
  • Bug Fixes

    • Improved reliability when collecting and displaying queue metrics.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e99c9319-532a-4774-b734-e9eb105c9453

📥 Commits

Reviewing files that changed from the base of the PR and between a135f1a and f28ab2b.

📒 Files selected for processing (1)
  • packages/backend/src/api.ts

Walkthrough

The backend upgrades Bull Board, adds Redis-backed metrics history, configures BullMQ worker metric retention for one week, and updates API startup and shutdown ordering.

Changes

Metrics integration

Layer / File(s)Summary
Worker metrics retention
packages/backend/src/jobManager.ts, packages/backend/src/jobManager.test.ts
Workers retain one week of native BullMQ metrics. Tests verify the maxDataPoints configuration.
Bull Board metrics lifecycle
packages/backend/package.json, packages/backend/src/api.ts, packages/backend/src/index.ts
Bull Board uses Redis-backed metrics history. The API starts and stops metrics recording and disposes metrics resources before Redis shutdown.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
participant Server
participant Api
participant BullBoard
participant RedisMetricsHistory
participant BullMQMetricsRecorder
Server->>Api: initialize API server
Api->>BullBoard: register queue adapters and history provider
Api->>RedisMetricsHistory: configure Redis-backed history
Api->>BullMQMetricsRecorder: start recording
Server->>Api: dispose API
Api->>BullMQMetricsRecorder: stop recording
Api->>RedisMetricsHistory: disconnect history provider
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: adding Bull Board metrics history to the backend.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bull-board-metrics

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

CodeRabbit couldn't update its existing comment. The review summary may be out of date.

Error details
No server is currently available to service your request. Sorry about that. Please try resubmitting your request and contact us if the problem persists.

@github-actions

github-actionsBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2171
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.13(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo (livebook-dev/codemirror-lang-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
khroma2.1.0UNKNOWNMITGitHub repo (fabiospampinato/khroma, GitHub license API: MIT), confirmed by MIT "license" file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo (livebook-dev/lezer-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
map-stream0.1.0UNKNOWNMITGitHub repo (dominictarr/map-stream, GitHub license API: MIT), confirmed by MIT LICENCE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
memorystream0.3.1UNKNOWNMITextracted from object: legacy "licenses": [{"type":"MIT","url":"..."}] field in the npm registry manifest; confirmed by MIT LICENSE file in the published npm tarball
pause-stream0.0.11["MIT", "Apache2"]MIT OR Apache-2.0extracted from array license field ["MIT","Apache2"] in the npm registry manifest; LICENSE file in the published npm tarball states "Dual Licensed MIT and Apache 2" and contains both full texts, so "Apache2" normalizes to Apache-2.0
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file referenced by "SEE LICENSE IN LICENSE" in the published npm tarball: Apache License 2.0 grant (Copyright 2020 PostHog / Hiberly, Inc.). A trailing MIT notice applies only to specific expo/expo-derived files, so the package license is Apache-2.0
valid-url1.0.9UNKNOWNMITMIT LICENSE file in the published npm tarball (verbatim MIT text, Copyright (c) 2013 Odysseas Tsatalos and oDesk Corporation); GitHub repo ogt/valid-url reports NOASSERTION (no metadata) and npmjs.com page blocked automated fetch (HTTP 403)

@brendan-kellam
brendan-kellam merged commit 41d90a4 into mainAug 17, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bull-board-metrics branch August 17, 2026 21:05
@github-actionsgithub-actionsBot mentioned this pull request Aug 17, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

bullBoardAdapter.setBasePath('/admin/queues');
const queueAdapters = jobManager
.getQueues()
.map(queue => new BullMQAdapter(queue));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bull Board loses read-only mode

High Severity

BullMQAdapter instances are created without readOnlyMode: true, so /admin/queues becomes a writable Bull Board. The prior board blocked retries, cleans, pauses, and other mutations; this endpoint still has no auth middleware, so anyone who can reach the worker API can alter job queues. That conflicts with the PR’s “read-only Bull Board” intent.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend): add Bull Board metrics history - #1604

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics
Aug 17, 2026
Merged

feat(backend): add Bull Board metrics history#1604
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • upgrade Bull Board packages from 6.11.2 to 9.0.0
  • enable one week of native BullMQ metrics and record long-retention metrics in Redis
  • expose history and latency charts in the read-only Bull Board and stop the recorder cleanly

Validation

  • yarn workspace @sourcebot/backend build
  • yarn workspace @sourcebot/backend test --run

Note

Medium Risk
Major dependency upgrade (Bull Board 6→9, Express 5 for bull-board only) plus new Redis-backed metrics writers; shutdown order changed but scoped to observability and lifecycle.

Overview
Upgrades Bull Board from 6.11.2 to 9.0.0 and adds @bull-board/metrics so the read-only /admin/queues UI can show queue history and latency charts backed by Redis.

The API wires a RedisMetricsHistoryProvider and MetricsRecorder (shared Redis connection, latency errors logged per queue), starts recording at boot, and stops the recorder / disconnects the history provider on shutdown. Graceful shutdown now disposes the API before stopping workers and closing Redis.

BullMQ workers retain one week of native metrics (MetricsTime.ONE_WEEK / 10,080 data points), with a unit test asserting that worker option.

Reviewed by Cursor Bugbot for commit 375c1da. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added queue performance metrics to the monitoring dashboard, including latency tracking and historical data.
    • Metrics history is retained for up to one week for easier trend analysis.
    • Improved metrics handling during application startup and shutdown.
  • Bug Fixes

    • Improved reliability when collecting and displaying queue metrics.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e99c9319-532a-4774-b734-e9eb105c9453

📥 Commits

Reviewing files that changed from the base of the PR and between a135f1a and f28ab2b.

📒 Files selected for processing (1)
  • packages/backend/src/api.ts

Walkthrough

The backend upgrades Bull Board, adds Redis-backed metrics history, configures BullMQ worker metric retention for one week, and updates API startup and shutdown ordering.

Changes

Metrics integration

Layer / File(s)Summary
Worker metrics retention
packages/backend/src/jobManager.ts, packages/backend/src/jobManager.test.ts
Workers retain one week of native BullMQ metrics. Tests verify the maxDataPoints configuration.
Bull Board metrics lifecycle
packages/backend/package.json, packages/backend/src/api.ts, packages/backend/src/index.ts
Bull Board uses Redis-backed metrics history. The API starts and stops metrics recording and disposes metrics resources before Redis shutdown.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
participant Server
participant Api
participant BullBoard
participant RedisMetricsHistory
participant BullMQMetricsRecorder
Server->>Api: initialize API server
Api->>BullBoard: register queue adapters and history provider
Api->>RedisMetricsHistory: configure Redis-backed history
Api->>BullMQMetricsRecorder: start recording
Server->>Api: dispose API
Api->>BullMQMetricsRecorder: stop recording
Api->>RedisMetricsHistory: disconnect history provider
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: adding Bull Board metrics history to the backend.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bull-board-metrics

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

CodeRabbit couldn't update its existing comment. The review summary may be out of date.

Error details
No server is currently available to service your request. Sorry about that. Please try resubmitting your request and contact us if the problem persists.

@github-actions

github-actionsBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2171
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.13(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo (livebook-dev/codemirror-lang-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
khroma2.1.0UNKNOWNMITGitHub repo (fabiospampinato/khroma, GitHub license API: MIT), confirmed by MIT "license" file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo (livebook-dev/lezer-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
map-stream0.1.0UNKNOWNMITGitHub repo (dominictarr/map-stream, GitHub license API: MIT), confirmed by MIT LICENCE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
memorystream0.3.1UNKNOWNMITextracted from object: legacy "licenses": [{"type":"MIT","url":"..."}] field in the npm registry manifest; confirmed by MIT LICENSE file in the published npm tarball
pause-stream0.0.11["MIT", "Apache2"]MIT OR Apache-2.0extracted from array license field ["MIT","Apache2"] in the npm registry manifest; LICENSE file in the published npm tarball states "Dual Licensed MIT and Apache 2" and contains both full texts, so "Apache2" normalizes to Apache-2.0
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file referenced by "SEE LICENSE IN LICENSE" in the published npm tarball: Apache License 2.0 grant (Copyright 2020 PostHog / Hiberly, Inc.). A trailing MIT notice applies only to specific expo/expo-derived files, so the package license is Apache-2.0
valid-url1.0.9UNKNOWNMITMIT LICENSE file in the published npm tarball (verbatim MIT text, Copyright (c) 2013 Odysseas Tsatalos and oDesk Corporation); GitHub repo ogt/valid-url reports NOASSERTION (no metadata) and npmjs.com page blocked automated fetch (HTTP 403)

@brendan-kellam
brendan-kellam merged commit 41d90a4 into mainAug 17, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bull-board-metrics branch August 17, 2026 21:05
@github-actionsgithub-actionsBot mentioned this pull request Aug 17, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

bullBoardAdapter.setBasePath('/admin/queues');
const queueAdapters = jobManager
.getQueues()
.map(queue => new BullMQAdapter(queue));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bull Board loses read-only mode

High Severity

BullMQAdapter instances are created without readOnlyMode: true, so /admin/queues becomes a writable Bull Board. The prior board blocked retries, cleans, pauses, and other mutations; this endpoint still has no auth middleware, so anyone who can reach the worker API can alter job queues. That conflicts with the PR’s “read-only Bull Board” intent.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend): add Bull Board metrics history - #1604

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics
Aug 17, 2026
Merged

feat(backend): add Bull Board metrics history#1604
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • upgrade Bull Board packages from 6.11.2 to 9.0.0
  • enable one week of native BullMQ metrics and record long-retention metrics in Redis
  • expose history and latency charts in the read-only Bull Board and stop the recorder cleanly

Validation

  • yarn workspace @sourcebot/backend build
  • yarn workspace @sourcebot/backend test --run

Note

Medium Risk
Major dependency upgrade (Bull Board 6→9, Express 5 for bull-board only) plus new Redis-backed metrics writers; shutdown order changed but scoped to observability and lifecycle.

Overview
Upgrades Bull Board from 6.11.2 to 9.0.0 and adds @bull-board/metrics so the read-only /admin/queues UI can show queue history and latency charts backed by Redis.

The API wires a RedisMetricsHistoryProvider and MetricsRecorder (shared Redis connection, latency errors logged per queue), starts recording at boot, and stops the recorder / disconnects the history provider on shutdown. Graceful shutdown now disposes the API before stopping workers and closing Redis.

BullMQ workers retain one week of native metrics (MetricsTime.ONE_WEEK / 10,080 data points), with a unit test asserting that worker option.

Reviewed by Cursor Bugbot for commit 375c1da. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added queue performance metrics to the monitoring dashboard, including latency tracking and historical data.
    • Metrics history is retained for up to one week for easier trend analysis.
    • Improved metrics handling during application startup and shutdown.
  • Bug Fixes

    • Improved reliability when collecting and displaying queue metrics.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e99c9319-532a-4774-b734-e9eb105c9453

📥 Commits

Reviewing files that changed from the base of the PR and between a135f1a and f28ab2b.

📒 Files selected for processing (1)
  • packages/backend/src/api.ts

Walkthrough

The backend upgrades Bull Board, adds Redis-backed metrics history, configures BullMQ worker metric retention for one week, and updates API startup and shutdown ordering.

Changes

Metrics integration

Layer / File(s)Summary
Worker metrics retention
packages/backend/src/jobManager.ts, packages/backend/src/jobManager.test.ts
Workers retain one week of native BullMQ metrics. Tests verify the maxDataPoints configuration.
Bull Board metrics lifecycle
packages/backend/package.json, packages/backend/src/api.ts, packages/backend/src/index.ts
Bull Board uses Redis-backed metrics history. The API starts and stops metrics recording and disposes metrics resources before Redis shutdown.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
participant Server
participant Api
participant BullBoard
participant RedisMetricsHistory
participant BullMQMetricsRecorder
Server->>Api: initialize API server
Api->>BullBoard: register queue adapters and history provider
Api->>RedisMetricsHistory: configure Redis-backed history
Api->>BullMQMetricsRecorder: start recording
Server->>Api: dispose API
Api->>BullMQMetricsRecorder: stop recording
Api->>RedisMetricsHistory: disconnect history provider
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: adding Bull Board metrics history to the backend.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bull-board-metrics

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

CodeRabbit couldn't update its existing comment. The review summary may be out of date.

Error details
No server is currently available to service your request. Sorry about that. Please try resubmitting your request and contact us if the problem persists.

@github-actions

github-actionsBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2171
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.13(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo (livebook-dev/codemirror-lang-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
khroma2.1.0UNKNOWNMITGitHub repo (fabiospampinato/khroma, GitHub license API: MIT), confirmed by MIT "license" file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo (livebook-dev/lezer-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
map-stream0.1.0UNKNOWNMITGitHub repo (dominictarr/map-stream, GitHub license API: MIT), confirmed by MIT LICENCE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
memorystream0.3.1UNKNOWNMITextracted from object: legacy "licenses": [{"type":"MIT","url":"..."}] field in the npm registry manifest; confirmed by MIT LICENSE file in the published npm tarball
pause-stream0.0.11["MIT", "Apache2"]MIT OR Apache-2.0extracted from array license field ["MIT","Apache2"] in the npm registry manifest; LICENSE file in the published npm tarball states "Dual Licensed MIT and Apache 2" and contains both full texts, so "Apache2" normalizes to Apache-2.0
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file referenced by "SEE LICENSE IN LICENSE" in the published npm tarball: Apache License 2.0 grant (Copyright 2020 PostHog / Hiberly, Inc.). A trailing MIT notice applies only to specific expo/expo-derived files, so the package license is Apache-2.0
valid-url1.0.9UNKNOWNMITMIT LICENSE file in the published npm tarball (verbatim MIT text, Copyright (c) 2013 Odysseas Tsatalos and oDesk Corporation); GitHub repo ogt/valid-url reports NOASSERTION (no metadata) and npmjs.com page blocked automated fetch (HTTP 403)

@brendan-kellam
brendan-kellam merged commit 41d90a4 into mainAug 17, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bull-board-metrics branch August 17, 2026 21:05
@github-actionsgithub-actionsBot mentioned this pull request Aug 17, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

bullBoardAdapter.setBasePath('/admin/queues');
const queueAdapters = jobManager
.getQueues()
.map(queue => new BullMQAdapter(queue));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bull Board loses read-only mode

High Severity

BullMQAdapter instances are created without readOnlyMode: true, so /admin/queues becomes a writable Bull Board. The prior board blocked retries, cleans, pauses, and other mutations; this endpoint still has no auth middleware, so anyone who can reach the worker API can alter job queues. That conflicts with the PR’s “read-only Bull Board” intent.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(backend): add Bull Board metrics history - #1604

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics
Aug 17, 2026
Merged

feat(backend): add Bull Board metrics history#1604
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • upgrade Bull Board packages from 6.11.2 to 9.0.0
  • enable one week of native BullMQ metrics and record long-retention metrics in Redis
  • expose history and latency charts in the read-only Bull Board and stop the recorder cleanly

Validation

  • yarn workspace @sourcebot/backend build
  • yarn workspace @sourcebot/backend test --run

Note

Medium Risk
Major dependency upgrade (Bull Board 6→9, Express 5 for bull-board only) plus new Redis-backed metrics writers; shutdown order changed but scoped to observability and lifecycle.

Overview
Upgrades Bull Board from 6.11.2 to 9.0.0 and adds @bull-board/metrics so the read-only /admin/queues UI can show queue history and latency charts backed by Redis.

The API wires a RedisMetricsHistoryProvider and MetricsRecorder (shared Redis connection, latency errors logged per queue), starts recording at boot, and stops the recorder / disconnects the history provider on shutdown. Graceful shutdown now disposes the API before stopping workers and closing Redis.

BullMQ workers retain one week of native metrics (MetricsTime.ONE_WEEK / 10,080 data points), with a unit test asserting that worker option.

Reviewed by Cursor Bugbot for commit 375c1da. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added queue performance metrics to the monitoring dashboard, including latency tracking and historical data.
    • Metrics history is retained for up to one week for easier trend analysis.
    • Improved metrics handling during application startup and shutdown.
  • Bug Fixes

    • Improved reliability when collecting and displaying queue metrics.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e99c9319-532a-4774-b734-e9eb105c9453

📥 Commits

Reviewing files that changed from the base of the PR and between a135f1a and f28ab2b.

📒 Files selected for processing (1)
  • packages/backend/src/api.ts

Walkthrough

The backend upgrades Bull Board, adds Redis-backed metrics history, configures BullMQ worker metric retention for one week, and updates API startup and shutdown ordering.

Changes

Metrics integration

Layer / File(s)Summary
Worker metrics retention
packages/backend/src/jobManager.ts, packages/backend/src/jobManager.test.ts
Workers retain one week of native BullMQ metrics. Tests verify the maxDataPoints configuration.
Bull Board metrics lifecycle
packages/backend/package.json, packages/backend/src/api.ts, packages/backend/src/index.ts
Bull Board uses Redis-backed metrics history. The API starts and stops metrics recording and disposes metrics resources before Redis shutdown.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
participant Server
participant Api
participant BullBoard
participant RedisMetricsHistory
participant BullMQMetricsRecorder
Server->>Api: initialize API server
Api->>BullBoard: register queue adapters and history provider
Api->>RedisMetricsHistory: configure Redis-backed history
Api->>BullMQMetricsRecorder: start recording
Server->>Api: dispose API
Api->>BullMQMetricsRecorder: stop recording
Api->>RedisMetricsHistory: disconnect history provider
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: adding Bull Board metrics history to the backend.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bull-board-metrics

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

CodeRabbit couldn't update its existing comment. The review summary may be out of date.

Error details
No server is currently available to service your request. Sorry about that. Please try resubmitting your request and contact us if the problem persists.

@github-actions

github-actionsBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2171
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.13(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo (livebook-dev/codemirror-lang-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
khroma2.1.0UNKNOWNMITGitHub repo (fabiospampinato/khroma, GitHub license API: MIT), confirmed by MIT "license" file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo (livebook-dev/lezer-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
map-stream0.1.0UNKNOWNMITGitHub repo (dominictarr/map-stream, GitHub license API: MIT), confirmed by MIT LICENCE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
memorystream0.3.1UNKNOWNMITextracted from object: legacy "licenses": [{"type":"MIT","url":"..."}] field in the npm registry manifest; confirmed by MIT LICENSE file in the published npm tarball
pause-stream0.0.11["MIT", "Apache2"]MIT OR Apache-2.0extracted from array license field ["MIT","Apache2"] in the npm registry manifest; LICENSE file in the published npm tarball states "Dual Licensed MIT and Apache 2" and contains both full texts, so "Apache2" normalizes to Apache-2.0
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file referenced by "SEE LICENSE IN LICENSE" in the published npm tarball: Apache License 2.0 grant (Copyright 2020 PostHog / Hiberly, Inc.). A trailing MIT notice applies only to specific expo/expo-derived files, so the package license is Apache-2.0
valid-url1.0.9UNKNOWNMITMIT LICENSE file in the published npm tarball (verbatim MIT text, Copyright (c) 2013 Odysseas Tsatalos and oDesk Corporation); GitHub repo ogt/valid-url reports NOASSERTION (no metadata) and npmjs.com page blocked automated fetch (HTTP 403)

@brendan-kellam
brendan-kellam merged commit 41d90a4 into mainAug 17, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bull-board-metrics branch August 17, 2026 21:05
@github-actionsgithub-actionsBot mentioned this pull request Aug 17, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

bullBoardAdapter.setBasePath('/admin/queues');
const queueAdapters = jobManager
.getQueues()
.map(queue => new BullMQAdapter(queue));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bull Board loses read-only mode

High Severity

BullMQAdapter instances are created without readOnlyMode: true, so /admin/queues becomes a writable Bull Board. The prior board blocked retries, cleans, pauses, and other mutations; this endpoint still has no auth middleware, so anyone who can reach the worker API can alter job queues. That conflicts with the PR’s “read-only Bull Board” intent.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend): add Bull Board metrics history - #1604

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics
Aug 17, 2026
Merged

feat(backend): add Bull Board metrics history#1604
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • upgrade Bull Board packages from 6.11.2 to 9.0.0
  • enable one week of native BullMQ metrics and record long-retention metrics in Redis
  • expose history and latency charts in the read-only Bull Board and stop the recorder cleanly

Validation

  • yarn workspace @sourcebot/backend build
  • yarn workspace @sourcebot/backend test --run

Note

Medium Risk
Major dependency upgrade (Bull Board 6→9, Express 5 for bull-board only) plus new Redis-backed metrics writers; shutdown order changed but scoped to observability and lifecycle.

Overview
Upgrades Bull Board from 6.11.2 to 9.0.0 and adds @bull-board/metrics so the read-only /admin/queues UI can show queue history and latency charts backed by Redis.

The API wires a RedisMetricsHistoryProvider and MetricsRecorder (shared Redis connection, latency errors logged per queue), starts recording at boot, and stops the recorder / disconnects the history provider on shutdown. Graceful shutdown now disposes the API before stopping workers and closing Redis.

BullMQ workers retain one week of native metrics (MetricsTime.ONE_WEEK / 10,080 data points), with a unit test asserting that worker option.

Reviewed by Cursor Bugbot for commit 375c1da. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added queue performance metrics to the monitoring dashboard, including latency tracking and historical data.
    • Metrics history is retained for up to one week for easier trend analysis.
    • Improved metrics handling during application startup and shutdown.
  • Bug Fixes

    • Improved reliability when collecting and displaying queue metrics.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e99c9319-532a-4774-b734-e9eb105c9453

📥 Commits

Reviewing files that changed from the base of the PR and between a135f1a and f28ab2b.

📒 Files selected for processing (1)
  • packages/backend/src/api.ts

Walkthrough

The backend upgrades Bull Board, adds Redis-backed metrics history, configures BullMQ worker metric retention for one week, and updates API startup and shutdown ordering.

Changes

Metrics integration

Layer / File(s)Summary
Worker metrics retention
packages/backend/src/jobManager.ts, packages/backend/src/jobManager.test.ts
Workers retain one week of native BullMQ metrics. Tests verify the maxDataPoints configuration.
Bull Board metrics lifecycle
packages/backend/package.json, packages/backend/src/api.ts, packages/backend/src/index.ts
Bull Board uses Redis-backed metrics history. The API starts and stops metrics recording and disposes metrics resources before Redis shutdown.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
participant Server
participant Api
participant BullBoard
participant RedisMetricsHistory
participant BullMQMetricsRecorder
Server->>Api: initialize API server
Api->>BullBoard: register queue adapters and history provider
Api->>RedisMetricsHistory: configure Redis-backed history
Api->>BullMQMetricsRecorder: start recording
Server->>Api: dispose API
Api->>BullMQMetricsRecorder: stop recording
Api->>RedisMetricsHistory: disconnect history provider
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: adding Bull Board metrics history to the backend.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bull-board-metrics

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

CodeRabbit couldn't update its existing comment. The review summary may be out of date.

Error details
No server is currently available to service your request. Sorry about that. Please try resubmitting your request and contact us if the problem persists.

@github-actions

github-actionsBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2171
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.13(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo (livebook-dev/codemirror-lang-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
khroma2.1.0UNKNOWNMITGitHub repo (fabiospampinato/khroma, GitHub license API: MIT), confirmed by MIT "license" file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo (livebook-dev/lezer-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
map-stream0.1.0UNKNOWNMITGitHub repo (dominictarr/map-stream, GitHub license API: MIT), confirmed by MIT LICENCE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
memorystream0.3.1UNKNOWNMITextracted from object: legacy "licenses": [{"type":"MIT","url":"..."}] field in the npm registry manifest; confirmed by MIT LICENSE file in the published npm tarball
pause-stream0.0.11["MIT", "Apache2"]MIT OR Apache-2.0extracted from array license field ["MIT","Apache2"] in the npm registry manifest; LICENSE file in the published npm tarball states "Dual Licensed MIT and Apache 2" and contains both full texts, so "Apache2" normalizes to Apache-2.0
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file referenced by "SEE LICENSE IN LICENSE" in the published npm tarball: Apache License 2.0 grant (Copyright 2020 PostHog / Hiberly, Inc.). A trailing MIT notice applies only to specific expo/expo-derived files, so the package license is Apache-2.0
valid-url1.0.9UNKNOWNMITMIT LICENSE file in the published npm tarball (verbatim MIT text, Copyright (c) 2013 Odysseas Tsatalos and oDesk Corporation); GitHub repo ogt/valid-url reports NOASSERTION (no metadata) and npmjs.com page blocked automated fetch (HTTP 403)

@brendan-kellam
brendan-kellam merged commit 41d90a4 into mainAug 17, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bull-board-metrics branch August 17, 2026 21:05
@github-actionsgithub-actionsBot mentioned this pull request Aug 17, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

bullBoardAdapter.setBasePath('/admin/queues');
const queueAdapters = jobManager
.getQueues()
.map(queue => new BullMQAdapter(queue));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bull Board loses read-only mode

High Severity

BullMQAdapter instances are created without readOnlyMode: true, so /admin/queues becomes a writable Bull Board. The prior board blocked retries, cleans, pauses, and other mutations; this endpoint still has no auth middleware, so anyone who can reach the worker API can alter job queues. That conflicts with the PR’s “read-only Bull Board” intent.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend): add Bull Board metrics history - #1604

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics
Aug 17, 2026
Merged

feat(backend): add Bull Board metrics history#1604
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • upgrade Bull Board packages from 6.11.2 to 9.0.0
  • enable one week of native BullMQ metrics and record long-retention metrics in Redis
  • expose history and latency charts in the read-only Bull Board and stop the recorder cleanly

Validation

  • yarn workspace @sourcebot/backend build
  • yarn workspace @sourcebot/backend test --run

Note

Medium Risk
Major dependency upgrade (Bull Board 6→9, Express 5 for bull-board only) plus new Redis-backed metrics writers; shutdown order changed but scoped to observability and lifecycle.

Overview
Upgrades Bull Board from 6.11.2 to 9.0.0 and adds @bull-board/metrics so the read-only /admin/queues UI can show queue history and latency charts backed by Redis.

The API wires a RedisMetricsHistoryProvider and MetricsRecorder (shared Redis connection, latency errors logged per queue), starts recording at boot, and stops the recorder / disconnects the history provider on shutdown. Graceful shutdown now disposes the API before stopping workers and closing Redis.

BullMQ workers retain one week of native metrics (MetricsTime.ONE_WEEK / 10,080 data points), with a unit test asserting that worker option.

Reviewed by Cursor Bugbot for commit 375c1da. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added queue performance metrics to the monitoring dashboard, including latency tracking and historical data.
    • Metrics history is retained for up to one week for easier trend analysis.
    • Improved metrics handling during application startup and shutdown.
  • Bug Fixes

    • Improved reliability when collecting and displaying queue metrics.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e99c9319-532a-4774-b734-e9eb105c9453

📥 Commits

Reviewing files that changed from the base of the PR and between a135f1a and f28ab2b.

📒 Files selected for processing (1)
  • packages/backend/src/api.ts

Walkthrough

The backend upgrades Bull Board, adds Redis-backed metrics history, configures BullMQ worker metric retention for one week, and updates API startup and shutdown ordering.

Changes

Metrics integration

Layer / File(s)Summary
Worker metrics retention
packages/backend/src/jobManager.ts, packages/backend/src/jobManager.test.ts
Workers retain one week of native BullMQ metrics. Tests verify the maxDataPoints configuration.
Bull Board metrics lifecycle
packages/backend/package.json, packages/backend/src/api.ts, packages/backend/src/index.ts
Bull Board uses Redis-backed metrics history. The API starts and stops metrics recording and disposes metrics resources before Redis shutdown.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
participant Server
participant Api
participant BullBoard
participant RedisMetricsHistory
participant BullMQMetricsRecorder
Server->>Api: initialize API server
Api->>BullBoard: register queue adapters and history provider
Api->>RedisMetricsHistory: configure Redis-backed history
Api->>BullMQMetricsRecorder: start recording
Server->>Api: dispose API
Api->>BullMQMetricsRecorder: stop recording
Api->>RedisMetricsHistory: disconnect history provider
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: adding Bull Board metrics history to the backend.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bull-board-metrics

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

CodeRabbit couldn't update its existing comment. The review summary may be out of date.

Error details
No server is currently available to service your request. Sorry about that. Please try resubmitting your request and contact us if the problem persists.

@github-actions

github-actionsBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2171
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.13(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo (livebook-dev/codemirror-lang-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
khroma2.1.0UNKNOWNMITGitHub repo (fabiospampinato/khroma, GitHub license API: MIT), confirmed by MIT "license" file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo (livebook-dev/lezer-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
map-stream0.1.0UNKNOWNMITGitHub repo (dominictarr/map-stream, GitHub license API: MIT), confirmed by MIT LICENCE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
memorystream0.3.1UNKNOWNMITextracted from object: legacy "licenses": [{"type":"MIT","url":"..."}] field in the npm registry manifest; confirmed by MIT LICENSE file in the published npm tarball
pause-stream0.0.11["MIT", "Apache2"]MIT OR Apache-2.0extracted from array license field ["MIT","Apache2"] in the npm registry manifest; LICENSE file in the published npm tarball states "Dual Licensed MIT and Apache 2" and contains both full texts, so "Apache2" normalizes to Apache-2.0
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file referenced by "SEE LICENSE IN LICENSE" in the published npm tarball: Apache License 2.0 grant (Copyright 2020 PostHog / Hiberly, Inc.). A trailing MIT notice applies only to specific expo/expo-derived files, so the package license is Apache-2.0
valid-url1.0.9UNKNOWNMITMIT LICENSE file in the published npm tarball (verbatim MIT text, Copyright (c) 2013 Odysseas Tsatalos and oDesk Corporation); GitHub repo ogt/valid-url reports NOASSERTION (no metadata) and npmjs.com page blocked automated fetch (HTTP 403)

@brendan-kellam
brendan-kellam merged commit 41d90a4 into mainAug 17, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bull-board-metrics branch August 17, 2026 21:05
@github-actionsgithub-actionsBot mentioned this pull request Aug 17, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

bullBoardAdapter.setBasePath('/admin/queues');
const queueAdapters = jobManager
.getQueues()
.map(queue => new BullMQAdapter(queue));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bull Board loses read-only mode

High Severity

BullMQAdapter instances are created without readOnlyMode: true, so /admin/queues becomes a writable Bull Board. The prior board blocked retries, cleans, pauses, and other mutations; this endpoint still has no auth middleware, so anyone who can reach the worker API can alter job queues. That conflicts with the PR’s “read-only Bull Board” intent.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(backend): add Bull Board metrics history - #1604

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics
Aug 17, 2026
Merged

feat(backend): add Bull Board metrics history#1604
brendan-kellam merged 3 commits into
mainfrom
brendan/bull-board-metrics

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • upgrade Bull Board packages from 6.11.2 to 9.0.0
  • enable one week of native BullMQ metrics and record long-retention metrics in Redis
  • expose history and latency charts in the read-only Bull Board and stop the recorder cleanly

Validation

  • yarn workspace @sourcebot/backend build
  • yarn workspace @sourcebot/backend test --run

Note

Medium Risk
Major dependency upgrade (Bull Board 6→9, Express 5 for bull-board only) plus new Redis-backed metrics writers; shutdown order changed but scoped to observability and lifecycle.

Overview
Upgrades Bull Board from 6.11.2 to 9.0.0 and adds @bull-board/metrics so the read-only /admin/queues UI can show queue history and latency charts backed by Redis.

The API wires a RedisMetricsHistoryProvider and MetricsRecorder (shared Redis connection, latency errors logged per queue), starts recording at boot, and stops the recorder / disconnects the history provider on shutdown. Graceful shutdown now disposes the API before stopping workers and closing Redis.

BullMQ workers retain one week of native metrics (MetricsTime.ONE_WEEK / 10,080 data points), with a unit test asserting that worker option.

Reviewed by Cursor Bugbot for commit 375c1da. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added queue performance metrics to the monitoring dashboard, including latency tracking and historical data.
    • Metrics history is retained for up to one week for easier trend analysis.
    • Improved metrics handling during application startup and shutdown.
  • Bug Fixes

    • Improved reliability when collecting and displaying queue metrics.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e99c9319-532a-4774-b734-e9eb105c9453

📥 Commits

Reviewing files that changed from the base of the PR and between a135f1a and f28ab2b.

📒 Files selected for processing (1)
  • packages/backend/src/api.ts

Walkthrough

The backend upgrades Bull Board, adds Redis-backed metrics history, configures BullMQ worker metric retention for one week, and updates API startup and shutdown ordering.

Changes

Metrics integration

Layer / File(s)Summary
Worker metrics retention
packages/backend/src/jobManager.ts, packages/backend/src/jobManager.test.ts
Workers retain one week of native BullMQ metrics. Tests verify the maxDataPoints configuration.
Bull Board metrics lifecycle
packages/backend/package.json, packages/backend/src/api.ts, packages/backend/src/index.ts
Bull Board uses Redis-backed metrics history. The API starts and stops metrics recording and disposes metrics resources before Redis shutdown.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
participant Server
participant Api
participant BullBoard
participant RedisMetricsHistory
participant BullMQMetricsRecorder
Server->>Api: initialize API server
Api->>BullBoard: register queue adapters and history provider
Api->>RedisMetricsHistory: configure Redis-backed history
Api->>BullMQMetricsRecorder: start recording
Server->>Api: dispose API
Api->>BullMQMetricsRecorder: stop recording
Api->>RedisMetricsHistory: disconnect history provider
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely describes the primary change: adding Bull Board metrics history to the backend.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/bull-board-metrics

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

CodeRabbit couldn't update its existing comment. The review summary may be out of date.

Error details
No server is currently available to service your request. Sorry about that. Please try resubmitting your request and contact us if the problem persists.

@github-actions

github-actionsBot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2171
Resolved (non-standard)8
Unresolved0
Strong copyleft0
Weak copyleft28

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
@img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.13(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (8)
PackageVersionOriginalResolvedSource
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0GitHub repo (livebook-dev/codemirror-lang-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
khroma2.1.0UNKNOWNMITGitHub repo (fabiospampinato/khroma, GitHub license API: MIT), confirmed by MIT "license" file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
lezer-elixir1.1.2UNKNOWNApache-2.0GitHub repo (livebook-dev/lezer-elixir, GitHub license API: Apache-2.0), confirmed by Apache-2.0 LICENSE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
map-stream0.1.0UNKNOWNMITGitHub repo (dominictarr/map-stream, GitHub license API: MIT), confirmed by MIT LICENCE file in the published npm tarball; npmjs.com page blocked automated fetch (HTTP 403) and the registry manifest has no license field
memorystream0.3.1UNKNOWNMITextracted from object: legacy "licenses": [{"type":"MIT","url":"..."}] field in the npm registry manifest; confirmed by MIT LICENSE file in the published npm tarball
pause-stream0.0.11["MIT", "Apache2"]MIT OR Apache-2.0extracted from array license field ["MIT","Apache2"] in the npm registry manifest; LICENSE file in the published npm tarball states "Dual Licensed MIT and Apache 2" and contains both full texts, so "Apache2" normalizes to Apache-2.0
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file referenced by "SEE LICENSE IN LICENSE" in the published npm tarball: Apache License 2.0 grant (Copyright 2020 PostHog / Hiberly, Inc.). A trailing MIT notice applies only to specific expo/expo-derived files, so the package license is Apache-2.0
valid-url1.0.9UNKNOWNMITMIT LICENSE file in the published npm tarball (verbatim MIT text, Copyright (c) 2013 Odysseas Tsatalos and oDesk Corporation); GitHub repo ogt/valid-url reports NOASSERTION (no metadata) and npmjs.com page blocked automated fetch (HTTP 403)

@brendan-kellam
brendan-kellam merged commit 41d90a4 into mainAug 17, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/bull-board-metrics branch August 17, 2026 21:05
@github-actionsgithub-actionsBot mentioned this pull request Aug 17, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

bullBoardAdapter.setBasePath('/admin/queues');
const queueAdapters = jobManager
.getQueues()
.map(queue => new BullMQAdapter(queue));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bull Board loses read-only mode

High Severity

BullMQAdapter instances are created without readOnlyMode: true, so /admin/queues becomes a writable Bull Board. The prior board blocked retries, cleans, pauses, and other mutations; this endpoint still has no auth middleware, so anyone who can reach the worker API can alter job queues. That conflicts with the PR’s “read-only Bull Board” intent.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit f28ab2b. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam