Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
88 commits
Select commit Hold shift + click to select a range
356b85c
fix(propdefs): always type $mcp_protocol_version as String
lucasheriques Sep 24, 2026
15928d3
fix(ci): read the split charts state file when rebuilding a flags canary
gustavohstrassburger Sep 25, 2026
f3197e3
fix(ci): read the split charts state file when rebuilding a flags canary
gustavohstrassburger Sep 25, 2026
c7ca688
Improve model table details
sakce Sep 28, 2026
0cb353b
Add table node detail stories
sakce Sep 28, 2026
090d2b3
Show downstream lineage in table stories
sakce Sep 28, 2026
a2929bb
fix(data-modeling): keep the table summary usable when a source load …
sakce Sep 28, 2026
ca4a98d
chore(data-modeling): document the model detail data quality tab
sakce Sep 28, 2026
4d22c37
Merge branch 'master' into posthog/improve-model-table-details
sakce Sep 28, 2026
f3c4e43
chore(data-modeling): pin the clock for the table node stories
sakce Sep 28, 2026
374115a
fix(ci): read depot hand-off with an app token
rnegron Sep 28, 2026
690a48c
fix(ci): report failed repo checks in the depot relay
rnegron Sep 28, 2026
9fe4048
fix(ci): keep retry advice for retryable failures
rnegron Sep 28, 2026
2e9cd4d
refactor(ci): harden relay check parsing
rnegron Sep 28, 2026
4c9006d
chore(ci): simplify relay parsing failures
rnegron Sep 28, 2026
64564a1
fix(ci): skip malformed relay check records
rnegron Sep 28, 2026
290b840
fix(marketing-analytics): share live attribution session resolution
jabahamondes Sep 28, 2026
8d0ae0a
Merge branch 'master' into codex/marketing-live-session-resolution
jabahamondes Sep 28, 2026
239dad3
Merge branch 'master' into codex/marketing-live-session-resolution
jabahamondes Sep 29, 2026
9cefbad
fix(data-deletion): skip flag_evaluations in immediate event removal
orian Sep 29, 2026
ffb01a2
fix(signals): keep the ranking sweep pause across deploys and log eac…
posthog[bot] Sep 29, 2026
6c52767
chore: warn when a new django model takes the deprecated uuidt key
dmarchuk Sep 29, 2026
2115761
Merge branch 'master' into posthog/improve-model-table-details
sakce Sep 29, 2026
7f4a3d2
chore(workflows): move viewsets to presentation/views
mayteio Sep 29, 2026
540cc84
chore(workflows): add facade contracts and capability functions
mayteio Sep 29, 2026
456d037
chore(workflows): route core and sibling callers through the facade
mayteio Sep 29, 2026
2aef2bc
chore(workflows): route search and outside test fixtures through the …
mayteio Sep 29, 2026
c356277
chore(workflows): seal workflows behind the tach interface
mayteio Sep 29, 2026
fcbfe4c
chore(workflows): move the boundary guidance to the edit sites
mayteio Sep 29, 2026
7118147
chore(workflows): keep the facade enum free of Django and defer new v…
mayteio Sep 29, 2026
5bae722
chore(workflows): fix import order, formatting and test-class baselin…
mayteio Sep 29, 2026
90e293c
chore(workflows): update timestamp guard for moved serializer
mayteio Sep 29, 2026
b425be6
style(workflows): format last-run test patch
mayteio Sep 29, 2026
57c3652
Merge branch 'master' into posthog/improve-model-table-details
sakce Sep 29, 2026
0def483
fix(signals): bound the memory of one inbox ranking sweep pass
posthog[bot] Sep 29, 2026
de2f47f
Fix Postgres keyset rollout after master update
Gilbert09 Sep 29, 2026
d3ce5e8
fix(data-modeling): show checks for PostHog tables
sakce Sep 29, 2026
c4a536c
Merge branch 'master' into posthog/improve-model-table-details
sakce Sep 29, 2026
ae360b4
Fix Postgres keyset rollout after master update
Gilbert09 Sep 29, 2026
d3f6552
Merge remote-tracking branch 'origin/master' into codex/marketing-liv…
jabahamondes Sep 29, 2026
38053d6
fix(marketing-analytics): isolate live resolution result caches
jabahamondes Sep 29, 2026
a9f423f
Merge branch 'master' into tom/dwh-postgres-keyset-gate
Gilbert09 Sep 29, 2026
8770020
Merge branch 'master' into tom/dwh-postgres-keyset-gate
Gilbert09 Sep 29, 2026
ebd6d17
feat(warehouse-sources): add four missing float tables
Gilbert09 Sep 29, 2026
10d5ecf
feat(data-warehouse): add freshchat roles, conversations and messages…
Gilbert09 Sep 29, 2026
19b115d
fix(data-deletion): drop skipped targets before resolving placements
orian Sep 29, 2026
2f5ae35
Merge remote-tracking branch 'origin/master' into codex/marketing-liv…
jabahamondes Sep 29, 2026
33ce929
fix(warehouse-sources): harden the float report window iterator
Gilbert09 Sep 29, 2026
d3fbd27
Merge branch 'master' into tom/dwh-postgres-keyset-gate
Gilbert09 Sep 29, 2026
eda2711
chore(data-warehouse): declare the freshchat endpoint config frozen
Gilbert09 Sep 29, 2026
768335d
chore(data-modeling): format generated kea types in node detail logic
sakce Sep 29, 2026
c9f1d30
Merge branch 'master' into posthog/improve-model-table-details
sakce Sep 29, 2026
5a83c25
Merge branch 'master' into pawel/fix/immediate-deletion-skip-flag-eva…
orian Sep 29, 2026
2c0f737
chore(workflows): align refresh_hog_flows with master before merge
mayteio Sep 29, 2026
8466eee
chore(workflows): align refresh_hog_flows test with master before merge
mayteio Sep 29, 2026
6315e90
Merge branch 'master' into posthog/isolate-workflows-facade
mayteio Sep 29, 2026
2e4a6e6
chore(workflows): move refresh_hog_flows back into the workflows product
mayteio Sep 29, 2026
a33981d
chore: fold the uuidt base-class check into the existing uuid7 rule
dmarchuk Sep 29, 2026
074b87f
fix(data-imports): recover account-property staging from a vacuumed d…
Gilbert09 Sep 29, 2026
6723bde
chore(visual): update storybook baselines
posthog[bot] Sep 29, 2026
ee56df7
fix(warehouse-sources): harden Float report requests
Gilbert09 Sep 29, 2026
6587a16
fix(data-imports): satisfy mypy on the new logger mock assertion
Gilbert09 Sep 29, 2026
178fead
feat(ci): mirror depot's relay checks with an app token
rnegron Sep 28, 2026
ff04520
fix(ci): prefer the mirrored relay checks
rnegron Sep 28, 2026
d24c8a2
refactor(ci): share mirror check names
rnegron Sep 28, 2026
e3b3f6e
fix(ci): use the mirror verdict when depot reads fail
rnegron Sep 28, 2026
405157a
fix(data-warehouse): disable resume for Freshchat message chains
Gilbert09 Sep 29, 2026
ca653de
fix(ci): pick the relay check by attempt across apps
rnegron Sep 29, 2026
dae196c
chore(signals): run the ranking sweep only on the self-driving fleet
andrewm4894 Sep 29, 2026
29931ac
Merge remote-tracking branch 'origin/master' into posthog-self-drivin…
andrewm4894 Sep 29, 2026
e649b6c
Merging 356b85c2c1e7b4b0ef34bf52ae63800dff843ea5 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
f2b4adf
Merging 6723bde8b0b52f5a8c717ebd8cc59eb6ef89eee5 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
66297f6
Merging 405157a85d34e01cc2bf7322949ec6de58a3d768 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
2edb875
Merging d3fbd27e9b7c293d9f847cb3756bce451304c050 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
45faed2
Merging 2f5ae35ab4e2a1c725c450a9efc0a893108ad519 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
90fa0b6
Merging e649b6cbf81a0821ff9ad4777b085f7d48b841ce into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
f61426a
Merging 45faed272407caf65679dc1b3a3baea16629fbd3 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
cd45d14
Merging f3197e32bf78c7e8a7626c1b2a9cd42e4e3b0867 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
a2b798c
Merging ca653dea8b2921670390fc9566c2ff93a24bbdd9 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
ddc733e
Merging 2e4a6e61114e3b74160ae21528fff0e7307f41fe into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
ead2c6e
Merging ee56df736408e00475ce31f6aa1f1d7497e8067c into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
48be58a
Merging ead2c6ec3abe1e02bd5018304b43685f45bb2946 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
c26cab5
Merging a33981d408ec4951db8b21a8912261e1d1f70d89 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
d1eac28
Merging 5a83c251f0618212560ee0fd9711651fb8296735 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
ba699d4
Merging dae196c0c4ce98ac577e781d11efde5e5c31e915 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
07ad98f
Merging 6587a1663e5ca7f7439c525f9793242980f4e044 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
3db2fb2
Merging 07ad98faf1e15495e8b1d4b8283497265ca94a1f into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
80297b1
Merging 29931acd08349839ab490c26d288efa8888fbf63 into trunk-temp/pr-1…
trunk-io[bot] Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .agents/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -196,7 +196,7 @@ An app or admin page takes the matching list in `CSPMiddleware`.
On PostHog Cloud, the app policy's `script-src` and `connect-src` name each PostHog host instead of `*.posthog.com`.
A script or request that goes to another PostHog subdomain needs its host in the lists that `CSPMiddleware` passes to `narrowed_app_policy()`.
Local runs, E2E runs and self-hosted installs keep the wildcards, so a missing host breaks only production.
A canvas artifact takes `artifact_csp()` in `products/canvas/backend/contract.py`, and a workflow message asset takes the header its endpoint sets in `products/workflows/backend/api/hog_flow.py`.
A canvas artifact takes `artifact_csp()` in `products/canvas/backend/contract.py`, and a workflow message asset takes the header its endpoint sets in `products/workflows/backend/presentation/views/hog_flow.py`.
`CSPMiddleware` returns a view-set header untouched, so widening the app policy does nothing for those two.
Say why the source is needed in a comment either way, then run `posthog/test/test_csp_middleware.py`.
The `csp-header-outside-csp-middleware` semgrep rule blocks a `Content-Security-Policy` header set anywhere else.
Expand Down
57 changes: 56 additions & 1 deletion .depot/workflows/ci-backend.yml
Original file line number Diff line number Diff line change
Expand Up @@ -233,10 +233,21 @@ jobs:
outputs:
handed_off: ${{ steps.handoff.outputs.handed_off }}
steps:
# Depot's ambient token can come from an installation spent for the hour. It answers 403,
# and the wait would decline a real hand-off. The same token posts the relay's checks.
- name: Mint hand-off token
id: handoff-token
if: contains(fromJSON('["pull_request", "workflow_dispatch", "api"]'), github.event_name) && github.event.pull_request.head.repo.fork != true
continue-on-error: true
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
with:
client-id: ${{ secrets.GH_APP_POSTHOG_TESTS_APP_ID }}
private-key: ${{ secrets.GH_APP_POSTHOG_TESTS_PRIVATE_KEY }}
permission-checks: write
- name: Wait for the hand-off check from GitHub Actions
id: handoff
env:
GH_TOKEN: ${{ github.token }}
GH_TOKEN: ${{ steps.handoff-token.outputs.token || github.token }}
REPO: ${{ github.repository }}
EVENT: ${{ github.event_name }}
IS_FORK: ${{ github.event.pull_request.head.repo.fork == true }}
Expand Down Expand Up @@ -297,6 +308,25 @@ jobs:
fi
fi
echo "handed_off=$handed_off" >> "$GITHUB_OUTPUT"
# Mirrors Depot's own checks for .github/scripts/ci_backend_relay.py (see MIRROR_APP_ID).
# A declined event also gets the gate's skipped check, as Depot posts it.
- name: Post the hand-off checks for the relay
if: github.event_name == 'pull_request' && steps.handoff-token.outputs.token != ''
continue-on-error: true
env:
GH_TOKEN: ${{ steps.handoff-token.outputs.token }}
REPO: ${{ github.repository }}
SHA: ${{ github.event.pull_request.head.sha }}
WAIT_CHECK: Backend CI on Depot / Wait for GitHub Actions to hand off backend tests (PR ${{ github.event.pull_request.number }}, event ${{ github.event.pull_request.updated_at }})
GATE_CHECK: Backend CI on Depot / Django Tests Pass on Depot
HANDED_OFF: ${{ steps.handoff.outputs.handed_off }}
run: |
post() {
gh api "repos/$REPO/check-runs" --method POST -f name="$1" -f head_sha="$SHA" \
-f status=completed -f conclusion="$2" -f details_url="$DEPOT_JOB_URL" --silent
}
post "$WAIT_CHECK" success
[ "$HANDED_OFF" = true ] || post "$GATE_CHECK" skipped
# Job to decide if we should run backend ci
# See .github/actions/paths-filter/README.md for filter semantics
changes:
Expand Down Expand Up @@ -4163,6 +4193,7 @@ jobs:
done

- name: Check dependency results
id: verdict
run: |
# Per-test failure rollup, emitted from THIS step because GitHub only
# auto-expands the failed step in the log view. Best-effort via `|| true`
Expand Down Expand Up @@ -4264,6 +4295,30 @@ jobs:
check_required_result "Snapshot commit job" "${{ needs.handle-snapshots.result }}"

echo "All backend and product checks passed."

# A separate checks:write token, minted in a job that runs no pull request code.
- name: Mint gate check token
id: gate-token
if: ${{ always() && github.event_name == 'pull_request' }}
continue-on-error: true
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
with:
client-id: ${{ secrets.GH_APP_POSTHOG_TESTS_APP_ID }}
private-key: ${{ secrets.GH_APP_POSTHOG_TESTS_PRIVATE_KEY }}
permission-checks: write
# Mirrors Depot's own check for .github/scripts/ci_backend_relay.py (see MIRROR_APP_ID).
- name: Post the gate check for the relay
if: ${{ always() && steps.gate-token.outputs.token != '' }}
continue-on-error: true
env:
GH_TOKEN: ${{ steps.gate-token.outputs.token }}
REPO: ${{ github.repository }}
SHA: ${{ github.event.pull_request.head.sha }}
GATE_CHECK: Backend CI on Depot / Django Tests Pass on Depot
CONCLUSION: ${{ job.status == 'cancelled' && 'cancelled' || (steps.verdict.outcome == 'success' && 'success' || 'failure') }}
run: |
gh api "repos/$REPO/check-runs" --method POST -f name="$GATE_CHECK" \
-f head_sha="$SHA" -f status=completed -f conclusion="$CONCLUSION" -f details_url="$DEPOT_JOB_URL" --silent
test-selection-verdict:
needs: [django, turbo-tests, changes, turbo-discover]
name: Test selection verdict
Expand Down
3 changes: 2 additions & 1 deletion .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -93,7 +93,8 @@ products/isolation_baseline.txt @PostHog/team-devex
# stay out, because a mistake there is visible rather than silent.
products/cdp/backend/api/** @PostHog/team-workflows
products/cdp/backend/models/** @PostHog/team-workflows
products/workflows/backend/api/** @PostHog/team-workflows
products/workflows/backend/facade/** @PostHog/team-workflows
products/workflows/backend/presentation/** @PostHog/team-workflows
products/workflows/backend/models/** @PostHog/team-workflows
products/messaging/backend/api/** @PostHog/team-workflows
products/messaging/backend/models/** @PostHog/team-workflows
Expand Down
Loading
Loading