DevPulse

Health analytics for GitHub projects.
DevPulse imports a repository's contribution history — pull requests, reviews,
issues, comments, forks, releases — and turns it into the picture that is hard
to get from the GitHub UI: who is actually carrying the project, whether
activity is growing or thinning, how long reviews take, and where the bus factor
sits. Optionally it runs the result past an LLM for a written summary.
This is a reference implementation, not a product. Apache-2.0, self-hostable,
maintained on a best-effort basis. There are no plans, no pricing, and no SLA.
See CONTRIBUTING.md for what that means
in practice.
A demo instance runs at devpulse.thingz.io. It is
this code with the maintainer's data in it, not a commercial service — useful
for seeing the output before running your own.
Running it locally
You need Go (the version in go.mod), Docker, and make. You do not need a
Google Cloud account or any credential from the maintainer.
git clone https://github.com/thingzio/devpulse && cd devpulse
make db-up # local Postgres via docker compose
make server # run the dashboard on :8080
make import # run the import worker once (needs GITHUB_TOKEN)
Then open http://localhost:8080.
To run the full quality gate — the same one CI runs:
make qualify # coverage, lint, govulncheck, integration, e2e
make help lists every target.
The local Postgres binds port 5432. DevTrace and DevRadar do the same, so
only run one of the three stacks at a time or you will get a confusing bind
failure.
How it works
Two binaries with independent lifecycles:
cmd/devpulse-site/ HTTP server: dashboard, OAuth, webhooks, data API, /admin
cmd/devpulse-import/ Batch import worker, run on a schedule
pkg/importer/ Sharded import pipeline with goroutine workers
pkg/plan/ Per-account limits, to keep a shared instance responsive
pkg/data/postgres/ PostgreSQL store, migrations, row-level security
pkg/tenant/ Accounts, sessions, GitHub App installations
infra/run/ Terraform for the Cloud Run reference deployment
Tenant isolation is enforced in the database with PostgreSQL row-level security
rather than in application code: each request acquires a dedicated connection
and sets app.tenant_id, and the policies do the rest. Import runs as a
separate job so a slow backfill cannot affect request latency.
Configuration
Everything is environment variables. DATABASE_URL is the only one required to
boot.
| Variable |
Purpose |
DATABASE_URL |
PostgreSQL connection URI — required |
BASE_URL |
Public base URL of this instance |
GITHUB_TOKEN |
Personal access token, enough for the import worker alone |
GITHUB_OAUTH_CLIENT_ID / _SECRET |
GitHub OAuth app, for sign-in |
GITHUB_APP_ID / GITHUB_APP_KEY_PATH |
GitHub App, for installation tokens |
DEVPULSE_ADMIN_USERS |
Comma-separated GitHub usernames granted /admin |
ANTHROPIC_API_KEY |
Optional; enables LLM-generated insights |
DEVPULSE_DEBUG |
true for debug-level logging |
Self-hosters bring their own keys, so AI cost scales to whoever runs the
instance. The full list is in docs/DEVELOPMENT.md.
Running a full instance requires registering your own GitHub App — App
private keys are per-instance and cannot be shared. See
docs/BOOTSTRAP.md. A plain GITHUB_TOKEN is enough to
exercise the import worker without one.
Deploying
docs/BOOTSTRAP.md walks through the Terraform in
infra/run/, which provisions the whole stack on Google Cloud — Cloud Run,
Cloud SQL, Secret Manager, scheduling. It is turnkey but opinionated toward GCP;
it is the maintainer's reference deployment, not the only way to run this.
Documentation
Contributing
See CONTRIBUTING.md. Documentation fixes are especially
welcome and are the easiest first contribution.
Security reports go through
GitHub Security Advisories,
not public issues — see SECURITY.md.
License
Apache 2.0. See NOTICE for attribution.