Skip to content

chore: remove langfuse integration - #1536

Merged
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742
Aug 5, 2026
Merged

chore: remove langfuse integration#1536
brendan-kellam merged 4 commits into
mainfrom
claude/issue-1453-20260804-1742

Conversation

@brendan-kellam

@brendan-kellam brendan-kellam commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Sourcebot no longer uses Langfuse, so this removes the integration entirely.

Fixes #1453

Changes

  • Server instrumentation (packages/web/src/instrumentation.ts): removed the langfuse-vercel LangfuseExporter registration. This was the only consumer of @vercel/otel's registerOTel, so @vercel/otel is dropped as well.
  • Browser feedback (answerCard.tsx): removed the LangfuseWeb client and its .score(...) call, plus the now-unused traceId prop and its pass-through in chatThreadListItem.tsx. PostHog feedback capture and the submitFeedback server action are unchanged.
  • AI SDK telemetry (agent.ts): dropped the langfuseTraceId metadata key. The experimental_telemetry block itself is left in place, still gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED.
  • Env vars: removed LANGFUSE_SECRET_KEY from env.server.ts, and NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL from env.client.ts and the Dockerfile build args.
  • Deps: dropped langfuse, langfuse-vercel, and @vercel/otel from packages/web/package.json and pruned the corresponding yarn.lock entries.

metadata.traceId on assistant messages is kept - it is still produced by agent.ts and consumed by the PostHog analytics paths (skillAnalytics, askMcpAnalytics).

Follow-up required

  • .github/workflows/_build-cloud.yml still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as build args (lines 123-124). I cannot modify workflow files, so those two lines need to be removed manually (and the matching repo vars deleted). Docker only warns on unknown build args, so the build will not break in the meantime.
  • Add the PR link to the new CHANGELOG entry.
  • yarn.lock was hand-pruned (no network/yarn in this job) - worth confirming with a local yarn install.

Generated with Claude Code


Note

Low Risk
Removal of unused third-party telemetry with no changes to auth, data handling, or core chat execution paths; Sentry and PostHog feedback paths remain.

Overview
Removes the Langfuse observability integration end-to-end now that Sourcebot no longer uses it.

Server startup no longer registers OpenTelemetry with langfuse-vercel or @vercel/otel; Sentry instrumentation remains unchanged.

Chat UI drops the browser LangfuseWeb client and thumbs-up/down scoring tied to Langfuse traces. Feedback still goes through submitFeedback and PostHog (wa_chat_feedback_submitted).

Ask agent still generates and stores metadata.traceId for PostHog and other analytics, but AI SDK telemetry no longer passes langfuseTraceId in experimental_telemetry metadata (telemetry remains gated on SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED).

Configuration and build remove LANGFUSE_SECRET_KEY, NEXT_PUBLIC_LANGFUSE_* from env schemas and Dockerfile build args. Dependencies langfuse, langfuse-vercel, and @vercel/otel are removed from the web package and lockfile.

CHANGELOG documents the removal under unreleased.

Reviewed by Cursor Bugbot for commit 3c66c74. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Bug Fixes

    • Chat feedback continues to work without external trace recording.
    • Error reporting remains available through Sentry.
  • Chores

    • Removed the Langfuse telemetry and tracing integration.
    • Removed related configuration, dependencies, and environment variables.
    • Documented the integration removal in the unreleased changelog.

Sourcebot no longer uses Langfuse, so drop the integration entirely:

- Remove the `langfuse-vercel` `LangfuseExporter` registration from
  `instrumentation.ts`. This was the only consumer of `@vercel/otel`'s
  `registerOTel`, so `@vercel/otel` is dropped as well.
- Remove the browser-side `LangfuseWeb` feedback score from `answerCard.tsx`,
  along with the now-unused `traceId` prop. `metadata.traceId` is still
  produced and consumed by the PostHog analytics paths.
- Drop the `langfuseTraceId` key from the AI SDK `experimental_telemetry`
  metadata. The telemetry block itself is left in place, gated on
  `SOURCEBOT_TELEMETRY_PII_COLLECTION_ENABLED` as before.
- Remove `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and
  `NEXT_PUBLIC_LANGFUSE_BASE_URL` from the env schemas and the Dockerfile.

Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@brendan-kellam, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 3 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c4a4ec-f9ba-49f1-a250-9390870dc67d

📥 Commits

Reviewing files that changed from the base of the PR and between 0994e4d and 3c66c74.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • packages/web/package.json
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx

Walkthrough

The PR removes Langfuse from build configuration, environment schemas, dependencies, server instrumentation, agent telemetry, and chat feedback handling. Sentry request error handling remains configured.

Changes

Langfuse integration removal

Layer / File(s) Summary
Configuration and dependency cleanup
CHANGELOG.md, Dockerfile, packages/shared/src/env.client.ts, packages/shared/src/env.server.ts, packages/web/package.json
Removed Langfuse build arguments, environment variables, schema entries, production dependencies, and changelog references.
Telemetry registration cleanup
packages/web/src/instrumentation.ts, packages/web/src/ee/features/chat/agent.ts
Removed Langfuse exporter registration and trace metadata. Sentry request error handling remains exported.
Chat feedback cleanup
packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx, packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
Removed Langfuse client setup, trace ID props, and feedback scoring. Local feedback state handling remains.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The PR removes Langfuse instead of implementing the JS SDK v5 migration required by issue #1453. Update the linked issue or implement the migration requirements from #1453, including SDK replacement, trace IDs, and feedback scoring.
✅ Passed checks (4 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The changes consistently target Langfuse integration removal and related configuration, dependencies, telemetry, feedback, and documentation.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary change: removing the Langfuse integration.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/issue-1453-20260804-1742

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@CHANGELOG.md`:
- Around line 10-11: Complete the Langfuse removal by deleting the
NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker build
arguments and their corresponding repository variables from the cloud build
workflow. Keep the CHANGELOG removal entry only once the workflow no longer
references these configuration values.
- Around line 10-11: Update the Langfuse removal entry under “Removed” in
CHANGELOG.md to end with the current pull request link, using the required
[`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b294857-d900-4f0f-9f1d-64538efe4b6d

📥 Commits

Reviewing files that changed from the base of the PR and between 5824c1b and 6e0f646.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (9)
  • CHANGELOG.md
  • Dockerfile
  • packages/shared/src/env.client.ts
  • packages/shared/src/env.server.ts
  • packages/web/package.json
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/answerCard.tsx
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • packages/web/src/instrumentation.ts
💤 Files with no reviewable changes (7)
  • packages/web/package.json
  • packages/shared/src/env.client.ts
  • packages/web/src/instrumentation.ts
  • packages/web/src/ee/features/chat/agent.ts
  • packages/web/src/ee/features/chat/components/chatThread/chatThreadListItem.tsx
  • Dockerfile
  • packages/shared/src/env.server.ts

Comment thread CHANGELOG.md Outdated
Comment on lines +10 to +11
### Removed
- Removed the Langfuse integration, along with the `langfuse` and `langfuse-vercel` dependencies and the `LANGFUSE_SECRET_KEY`, `NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY`, and `NEXT_PUBLIC_LANGFUSE_BASE_URL` environment variables.

@coderabbitai coderabbitai Bot Aug 4, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Complete the Langfuse configuration cleanup before claiming removal.

.github/workflows/_build-cloud.yml:118-128 still passes NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL as Docker build arguments. Remove those arguments and repository variables, or update this entry to state that the cleanup is incomplete.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@CHANGELOG.md` around lines 10 - 11, Complete the Langfuse removal by deleting
the NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY and NEXT_PUBLIC_LANGFUSE_BASE_URL Docker
build arguments and their corresponding repository variables from the cloud
build workflow. Keep the CHANGELOG removal entry only once the workflow no
longer references these configuration values.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add the pull request link to this entry.

The Unreleased changelog guidelines require each entry to end with the current pull request link in [ #id ](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@CHANGELOG.md` around lines 10 - 11, Update the Langfuse removal entry under
“Removed” in CHANGELOG.md to end with the current pull request link, using the
required [`#id`](https://github.com/sourcebot-dev/sourcebot/pull/<id>) format.

Source: Coding guidelines

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claude implement this feedback

@claude claude Bot Aug 5, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude finished @brendan-kellam's task in 1m 12s —— View job


CodeRabbit feedback

  • Gather context / read CHANGELOG + workflow file
  • Add PR link to the CHANGELOG entry — done in 0994e4d (pushed)
  • Remove Langfuse build args from _build-cloud.yml — attempted, blocked by permissions (see below)

1. CHANGELOG PR link ✅

CHANGELOG.md:11 now ends with the required link:

... environment variables. [#1536](https://github.com/sourcebot-dev/sourcebot/pull/1536)

2. Langfuse build args in .github/workflows/_build-cloud.yml ⚠️

I made the edit locally and it applies cleanly, but the push was rejected:

! [remote rejected] refusing to allow a GitHub App to create or update workflow
  `.github/workflows/_build-cloud.yml` without `workflows` permission

I'm unable to modify files in .github/workflows due to GitHub App permission restrictions. More detail in the FAQ.

The change needed is deleting lines 123-124:

             NEXT_PUBLIC_SENTRY_BACKEND_DSN=${{ vars.NEXT_PUBLIC_SENTRY_BACKEND_DSN }}
-            NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY=${{ vars.NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY }}
-            NEXT_PUBLIC_LANGFUSE_BASE_URL=${{ vars.NEXT_PUBLIC_LANGFUSE_BASE_URL }}
             SENTRY_ORG=${{ vars.SENTRY_ORG }}

Plus deleting the matching NEXT_PUBLIC_LANGFUSE_PUBLIC_KEY / NEXT_PUBLIC_LANGFUSE_BASE_URL repository variables in Settings → Actions → Variables.

I left the CHANGELOG entry as a plain removal statement rather than adding an "incomplete cleanup" caveat (CodeRabbit's alternative) — the two leftover build args are now unknown to the Dockerfile, so Docker only warns and the effective behavior is that Langfuse is fully removed. Once you delete those lines, no CHANGELOG edit is needed.

grep -r LANGFUSE over the repo confirms those two workflow lines are the only remaining references.
Branch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipped: comment is from another GitHub bot.

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2196
Resolved (non-standard) 17
Unresolved 0
Strong copyleft 0
Weak copyleft 28

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.12 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (17)
Package Version Original Resolved Source
@sentry/cli 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-darwin 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-linux-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
@sentry/cli-win32-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry API confirms license 'FSL-1.1-MIT' for this exact version; Functional Source License 1.1 (MIT future license) is a real license but is NOT a registered SPDX identifier
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 4.0.1
khroma 2.1.0 UNKNOWN MIT shipped license file in node_modules (MIT text, (c) 2019-present Fabio Spampinato); GitHub repo fabiospampinato/khroma
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 shipped LICENSE file in node_modules (full Apache-2.0 text); corroborated by npm registry API, which declares Apache-2.0 for 1.1.3
map-stream 0.1.0 UNKNOWN MIT shipped LICENCE file in node_modules (MIT text, (c) 2011 Dominic Tarr); corroborated by npm registry API, which declares MIT for 0.0.7
memorystream 0.3.1 UNKNOWN MIT extracted from object: package.json legacy licenses array [{type:'MIT',url:...}]; confirmed by shipped LICENSE file (MIT text)
pause-stream 0.0.11 MIT,Apache2 (MIT OR Apache-2.0) extracted from object: package.json license array ['MIT','Apache2']; shipped LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js 1.369.0 SEE LICENSE IN LICENSE (Apache-2.0 AND MIT) shipped LICENSE file in node_modules: Apache-2.0 grant for the work, plus MIT for vendored sentry-javascript/metro/expo portions; npm registry API declares '(Apache-2.0 AND MIT)' for later versions
valid-url 1.0.9 UNKNOWN MIT shipped LICENSE file in node_modules (MIT text, (c) 2013 Odysseas Tsatalos and oDesk Corporation)

@brendan-kellam
brendan-kellam merged commit f52ce7a into main Aug 5, 2026
12 of 13 checks passed
@brendan-kellam
brendan-kellam deleted the claude/issue-1453-20260804-1742 branch August 5, 2026 01:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate Langfuse integration from langfuse-vercel to JS SDK v5

1 participant