Skip to content

BED-9989 Collect selected app installation repositories - #81

Open
jaredcatkinson wants to merge 9 commits into
mainfrom
feature/BED-9989-selected-app-installation-repos
Open

jaredcatkinson wants to merge 9 commits into
mainfrom
feature/BED-9989-selected-app-installation-repos

Conversation

@jaredcatkinson

@jaredcatkinson jaredcatkinson commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Organization GitHub App installations with repository_selection: selected previously had no repository access edges. This change queries the enterprise organization-installation repositories API and adds GH_CanAccess edges for granted repositories found in the collected repository inventory. Installations set to all keep their existing behavior. Missing permission skips selected-repository edges, and a rate limit stops further selected-installation lookups for that collection.

The collecting enterprise app needs Enterprise organization installations: read or Enterprise organization installation repositories: read. The README and GH_AppInstallation description document the behavior and permission.

Validation: 379 tests passed; Ruff passed. In a live collection, the selected installation gained the expected edge to its one granted repository (0 before, 1 after).

Depends on #80. Until BED-9987 merges, this PR's diff against main also includes its classic PAT inventory commits. The BED-9989 change is commit 7c45ad5.

Summary by CodeRabbit

  • New Features
    • Added inventory of classic personal access tokens, including ownership, scope, status, and recorded organization authorizations.
    • Added graph navigation to find classic tokens by enterprise, organization, and owner, plus a saved search for expired classic and fine-grained tokens.
    • Added collection of selected-repository access for eligible GitHub App installations.
  • Documentation
    • Expanded guidance on permissions, inventory collection, export reuse, rate limits, and data handling.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 036b0193-1d77-457f-929b-d36b664be4fd
📥 Commits

Reviewing files that changed from the base of the PR and between 700f2db and 7c45ad5.

📒 Files selected for processing (28)
  • README.md
  • descriptions/edges/GH_AuthorizedForOrganization.md
  • descriptions/edges/GH_Contains.md
  • descriptions/edges/GH_HasPersonalAccessToken.md
  • descriptions/nodes/GH_AppInstallation.md
  • descriptions/nodes/GH_ClassicPersonalAccessToken.md
  • descriptions/nodes/GH_Enterprise.md
  • descriptions/nodes/GH_Organization.md
  • descriptions/nodes/GH_User.md
  • extension/saved_searches/README.md
  • extension/saved_searches/expired-pats.json
  • extension/schema.json
  • src/openhound_github/helpers.py
  • src/openhound_github/kinds/edges.py
  • src/openhound_github/kinds/nodes.py
  • src/openhound_github/lookup.py
  • src/openhound_github/models/__init__.py
  • src/openhound_github/models/app_installation.py
  • src/openhound_github/models/classic_personal_access_token.py
  • src/openhound_github/models/enterprise_member.py
  • src/openhound_github/models/org.py
  • src/openhound_github/models/user.py
  • src/openhound_github/resources/enterprise.py
  • src/openhound_github/resources/organization.py
  • src/openhound_github/source.py
  • tests/test_app_installation_repo_access.py
  • tests/test_classic_personal_access_tokens.py
  • tests/test_helpers.py

Included review availability: This review used your included allowance. 2 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


Walkthrough

This change adds enterprise classic personal access token inventory and selected-repository access collection for GitHub App installations. It adds graph models, relationships, navigation, documentation, and tests for both features.

Changes

Classic PAT Inventory

Layer / File(s) Summary
Credential export collection and parsing
src/openhound_github/helpers.py, src/openhound_github/resources/enterprise.py, tests/test_classic_personal_access_tokens.py, tests/test_helpers.py
Enterprise resources create or reuse credential exports, download and parse CSV data, and handle export errors. Tests cover export reuse, fallback credentials, rate limits, invalid data, and download failures.
Classic PAT modeling and graph relationships
src/openhound_github/models/classic_personal_access_token.py, src/openhound_github/models/enterprise_member.py, src/openhound_github/models/org.py, src/openhound_github/models/user.py, src/openhound_github/kinds/*, src/openhound_github/lookup.py, src/openhound_github/models/__init__.py, tests/test_classic_personal_access_tokens.py
Classic PAT rows become graph assets with enterprise, owner, and organization authorization edges. User and organization queries include classic PATs, and cached lookups resolve graph IDs.
Classic PAT schema, navigation, and documentation
extension/schema.json, extension/saved_searches/*, descriptions/edges/*, descriptions/nodes/*, README.md
Graph descriptions and navigation include classic PAT nodes and relationships. The expired-token search includes classic PATs, and the README documents inventory collection and export behavior.

Selected Installation Repository Access

Layer / File(s) Summary
Repository access collection and edge mapping
src/openhound_github/resources/organization.py, src/openhound_github/source.py, src/openhound_github/models/app_installation.py, descriptions/nodes/GH_AppInstallation.md, README.md
The organization resource fetches selected installation repositories and stops further collection after rate limiting. The model resolves repository nodes before creating access edges. Documentation describes permissions and collection behavior.
Repository access validation
tests/test_app_installation_repo_access.py
Tests cover pagination, installations with all repositories selected, failed later pages, rate-limit stopping, and repository resolution by database ID and organization.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant EnterpriseResource
  participant CredentialExportAPI
  participant CSVDownload
  participant ClassicPATModel
  EnterpriseResource->>CredentialExportAPI: create or poll export
  CredentialExportAPI-->>EnterpriseResource: export status and download URL
  EnterpriseResource->>CSVDownload: fetch CSV
  CSVDownload-->>EnterpriseResource: CSV rows
  EnterpriseResource->>ClassicPATModel: create assets from classic PAT rows
  ClassicPATModel-->>EnterpriseResource: token nodes and graph edges
Loading

Merge Risk: 🔵 Low · up to 7c45a

Repeated GitHub rate limits can delay an enterprise collection before credential inventory is skipped. This is a bounded operational risk rather than a merge blocker.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 7.59% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 79 functions across 16 files. (12 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: collecting repositories for selected GitHub App installations. It is concise and specific.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 7.59% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 79 functions across 16 files. (12 skipped: 12 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks the export trail,
Then gathers rows from paths of hail.
Classic tokens join the graph,
Selected repos follow their path.
The rabbit files each edge with care,
Then hops away through README air.

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant