Skip to content

admin: CI/security signals, honest Reach panel, releases pagination fix - #65

Merged
pacphi merged 2 commits into
mainfrom
feat/admin-health-signals
Jul 28, 2026
Merged

pacphi merged 2 commits into
mainfrom
feat/admin-health-signals

Conversation

@pacphi

@pacphi pacphi commented Jul 28, 2026

Copy link
Copy Markdown
Owner

Summary

  • Adds latest CI run status and open Dependabot alert count to the admin dashboard, in a new Project Health section.
  • Replaces the two Reach panel tiles that were permanently dead for this npm-only project ("bundle downloads", "newest release pulls" — GitHub release assets don't apply here) with real GitHub-native people signals: contributors and watching.
  • Fixes a bug where the releases fetch was capped at per_page=20, silently dropping older releases (this repo has 29; 9 were being missed).
  • Makes the existing npm mirror-inflation rationale (why npm downloads never appear as an absolute Reach number) an explicit, first-class note in the Gaps tab instead of a buried footnote.
  • Full rationale in docs/adr/0013-admin-build-security-signals-and-honest-reach.md.

Test plan

  • pnpm run check (typecheck, lint, markdownlint, build, full test suite) — all green, including 3 new edge-case tests (Dependabot 403 → unknown, no CI runs → not fabricated "passing", contributors fetch failure isolated).
  • Live smoke test against the real GitHub/npm APIs via ak x admin — confirmed releases now returns all 29, contributorsCount: 3, real CI run data, dependabotAlerts: 0.
  • Visual check of the new Project Health section and updated Reach tiles in a browser (not yet done in this session).

🤖 Generated with Claude Code

pacphi added 2 commits July 28, 2026 10:59
…tion fix

Adds latest CI run status and open Dependabot alert count to the admin
collector and a new Project Health section. Replaces the two Reach tiles
that were permanently dead for this npm-only project (bundle downloads,
newest release pulls — GitHub release assets don't apply) with real
GitHub-native people signals (contributors, watchers). Fixes a releases
fetch capped at per_page=20 that silently dropped older releases (repo
has 29). Makes the existing npm mirror-inflation exclusion from Reach an
explicit, first-class note instead of a footnote.

See docs/adr/0013 for the full rationale.
… names

The new "contributors" Reach tile counted GitHub's raw contributor list
verbatim, including the repo owner and dependabot[bot] — inconsistent
with buildPeople(), which already excludes both from contributors/
stargazers/forks elsewhere in this file. Verified live: contributorsCount
was reporting 3 (pacphi + dependabot[bot] + one real external
contributor) when the honest count is 1.

Also makes the 20 unnamed-but-dated-stargazer names clickable GitHub
profile links, matching every other person-card on the page instead of
rendering as plain "@login" text.
@pacphi
pacphi merged commit 6b60552 into main Jul 28, 2026
11 checks passed
@pacphi
pacphi deleted the feat/admin-health-signals branch July 28, 2026 18:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant