Track the open-source projects you care about — GitHub releases, pull requests and issues, plus community chatter — condensed into one digest card per repository per day.
It is a harness, not an LLM product. It shells out to the claude or codex CLI you already have installed, so the reasoning runs on your own subscription. No API keys are collected and nothing is hosted.
┌─ vercel/next.js ─────────────────────────── 2026-07-27 ─┐
│ • Multiple canary/stable releases shipped, alongside a │
│ Cache Components validation change. [E6 E7 E56] │
│ • Work moved Cache Components dev validation onto a │
│ dedicated worker thread. [E39 E40 E41 E43 E44] │
│ • App Router transitions intermittently never commit. │
│ [E11 E1 E36 E37] │
│ ── Interpretation (not sourced) ─────────────────────── │
│ ~ The volume of worker-thread refactor PRs landing │
│ together points to a coordinated internal effort. │
│ 33 releases · 79 PRs · 19 issues · 1 signal │
└─────────────────────────────────────────────────────────┘
npx supertrackingRequires Node >= 22.13 (node:sqlite was behind a flag before that); the launcher checks and tells you if not. Data lives in ~/.supertracking/db.sqlite, outside the package directory.
Optional but recommended — without a token you share the unauthenticated 60 requests/hour limit:
export GITHUB_TOKEN=ghp_...For summaries, install and log into either CLI:
npm i -g @anthropic-ai/claude-code # then run: claude → /login
npm i -g @openai/codex # then run: codex loginWithout one, GitHub ingest and the raw event browser still work — only summaries are unavailable.
- You paste a GitHub URL. The repository is validated against the API and stored locally.
- You press Refresh. Releases, pull requests and issues are pulled and upserted into local SQLite.
- For each repository with activity, the harness builds a numbered, closed catalog of what it ingested and hands it to your CLI, which web-searches for community discussion and writes the digest.
- The response is validated. A bullet may only cite ids the harness itself minted — an invented reference fails validation instead of rendering as evidence.
Grounding is enforced, not requested. Every bullet cites E{n} (an ingested event), C{n} (a fact the harness computed, e.g. "34 days since the last release"), or W{n} (an index into the model's own returned search results). Anything else is a schema error. C refs exist because a model forced to produce sourced bullets on a quiet day will otherwise attach a plausible-but-unsupporting E ref — which passes a naive closed-world check while being ungrounded.
Judgement gets a separate box. The interpretation array holds 0–2 bullets the model explicitly cannot source. It renders separately and never counts toward the 3–5 summary bullets. Without it, "every bullet must be cited" quietly pressures the model into false citations.
Cost is the real constraint, not latency. A 15-repo refresh takes ~72 s wall clock and ~$4.50 of notional usage. So calls are capped at one per repository per refresh, repositories with no activity in the window are never sent, and a repository whose digest already succeeded with no material change is skipped. sync_run records the budget and a SQL CHECK enforces it.
"Materially changed" is not "was written." ON CONFLICT DO UPDATE fires whether or not a value changed, and GitHub's since for issues is inclusive — so the boundary item returns on every refresh. Defined naively, any repository with recent activity would burn a call forever.
Failures stay recoverable. A parse error writes an error digest, and the skip predicate keys on success, not existence — otherwise that repository-day would be unreachable until midnight. Failed cards get a Regenerate button.
docs/conformance/ holds raw recorded output from real CLI calls. The rule behind it: CLI behaviour is established by a recorded real call, never by reading --help. That rule exists because reading --help produced four defects that would have shipped a product where every card read "parse error" while every planned test passed.
Among what those calls established:
- Neither CLI accepts the obvious JSON Schema.
clauderejects a$schemadraft-2020-12 reference;codexrejectsconstwithout a siblingtype. One document satisfies both after two edits. - Web search fires on both —
--allowedTools WebSearchfor claude, top-levelcodex --search exec(codex exec --searchis a hard argv error). - The logged-out failures are structurally opposite: claude returns a JSON envelope with
is_error: true,subtype: "success"and an empty stderr; codex returns no JSON at all, only a401on stderr after five internal retries. - On claude, config isolation and OAuth are coupled —
--bareandCLAUDE_CONFIG_DIReach suppress yourCLAUDE.mdand your login. Running from an empty cwd is the best available compromise.
- Web search is not deterministic. The same code path returned four signals on one run and zero on another. Digests are still correct without signals, but an empty community section does not mean there was no chatter.
- codex returns signals without citing them — it fills
signalsbut emits noWrefs, so provenance badges have nothing to attach on that provider. - The signal host allowlist is conservative and drops findings from hosts not on it.
- No automated test suite yet. Everything above was verified by running the app against real repositories.
- Korean is UI-only. The digest is always generated in English; a translation path is designed but not implemented.
- Refresh is manual by design. There is no scheduler.
MIT