Skip to main content

StandupBot

Generate standup updates from recent git activity with a local Ollama model or Groq's free cloud tier.

Tests codecov Python 3.10+ License: MIT

What is new (unreleased)

Since 0.2.4: a full security/correctness audit (private-IP redaction, a config-mutation bug that could leak an API key across process calls, a broken Linux systemd unit, and a few other fixes), plus a follow-up fix for missing secret-detection patterns (GitHub tokens, AWS keys, Slack tokens, LLM API keys, credentialed URIs) reported via #2. See CHANGELOG.md for the full list.

Quick Start

# Install dependencies
pip install -e .

# Configure StandupBot
standup --setup

# Generate a standup
standup

For Ollama, install and pull a model first:

ollama pull llama3

Providers

Provider Cost Privacy Best for
Ollama Free Fully local Private, offline workflows
Groq Free tier Cloud Fast generation without local model setup

Groq API keys should be supplied through GROQ_API_KEY when possible.

Core Commands

# Standard generation
standup
standup --hours 48
standup --week
standup --provider groq

# Output options
standup --copy
standup --slack
standup --raw
standup --template slack
standup --verbose

# Cache and filtering controls
standup --no-cache
standup --no-filter

# Maintenance
standup doctor
standup usage
standup logs
standup logs --tail 50
standup logs --clear
standup models
standup templates
standup history
standup history --limit 25
standup history --clear
standup history --clear --days 30
standup warm-up
standup warm-up --install-startup
standup warm-up --uninstall-startup
standup --maintenance

Templates

Built-in templates:

  • default
  • slack
  • minimal
  • detailed
  • jira

You can also define custom templates in config. StandupBot extracts yesterday, today, and blockers from the LLM output, then renders the final format with these variables:

  • {yesterday}
  • {today}
  • {blockers}
  • {date}
  • {time}
  • {commit_count}
  • {repos}
  • {provider}
  • {author_email}

Config

StandupBot reads ~/.standup.json.

{
  "repos": [
    "/path/to/repo1",
    "/path/to/repo2"
  ],
  "author_email": "you@example.com",
  "hours_lookback": 24,
  "tone": "casual",
  "slack_webhook_url": "",
  "provider": {
    "name": "ollama",
    "ollama": {
      "base_url": "http://localhost:11434",
      "model": "llama3"
    },
    "groq": {
      "api_key": "",
      "model": "llama-3.1-8b-instant"
    }
  },
  "rate_limit": {
    "cooldown_minutes": 30,
    "max_calls_per_day": 10,
    "enabled": true
  },
  "quality": {
    "enabled": true,
    "min_score": 0,
    "show_breakdown": false
  },
  "noise_filter_enabled": true,
  "template": "default",
  "custom_templates": {
    "my_format": "Done: {yesterday} | Doing: {today} | Help needed: {blockers}"
  },
  "auto_warm_up": false
}

Caching and History

Every generated standup is stored locally in ~/.standup_history.db.

  • Cache keys are based on a SHA256 fingerprint of sorted commit hashes.
  • Cache reuse is limited to the same day, tone, and provider.
  • The database stores standup text, provider metadata, repo names, lookback hours, and quality score.
  • Raw commit messages are not stored in the database.

Quality Scoring

After generation, StandupBot can score the standup from 0-100 and show a colored badge.

  • Green: 80+
  • Yellow: 60-79
  • Red: below 60

When quality.min_score is above zero, StandupBot retries low-quality outputs up to two times with refined guidance.

Warm-Up

Use standup warm-up to pre-load the configured model before your first real run.

  • Ollama: sends a minimal warm-up request to keep the selected model ready in memory.
  • Groq: runs a lightweight availability ping.
  • auto_warm_up can trigger a silent warm-up when the model has not been used recently.

Security

StandupBot treats config, git metadata, templates, provider responses, and local storage as hostile inputs until proven otherwise.

  • ~/.standup.json, ~/.standup_usage.json, ~/.standup_history.db, and ~/.standup.log use restricted permissions on Unix/macOS.
  • Commit messages are scanned for common secret formats — passwords/tokens/API keys, private IPs, internal hostnames, bearer tokens, GitHub PATs, LLM provider keys, AWS access keys, Slack tokens, and credentialed URIs — and redacted before they reach a prompt, storage, or the terminal.
  • Repo paths go through explicit path-safety checks to block traversal tricks, network paths, and unsafe symlinks.
  • Commit messages and LLM responses are length-capped before they reach prompts, storage, or terminal rendering.
  • Custom templates only substitute a fixed allowlist of variables and reject Python-style format syntax.
  • All history database queries are parameterized, and stored standup text is sanitized before persistence.
  • User-facing exception messages are sanitized so file paths, emails, and API-key-shaped values are not echoed back to the terminal.
  • standup doctor now checks log health, DB size, schema version, WAL mode, file permissions, and full config validity.

Development

python -m pytest tests/ -q

If your environment restricts Python temp directories or __pycache__ writes, set a writable --basetemp or PYTHONDONTWRITEBYTECODE=1 while testing.

License

MIT

Metadata

Release files for standup-bot 0.2.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for standup-bot 0.2.7
File Size Uploaded
standup_bot-0.2.7.tar.gz 88.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for standup-bot 0.2.7
File Interpreter ABI Platform
standup_bot-0.2.7-py3-none-any.whl Python 3 none any Details

Total release size: 148.6 kB

Release files / standup_bot-0.2.7.tar.gz

Download URL standup_bot-0.2.7.tar.gz
Size 88.7 kB
Tags Source
SHA-256 checksum
How to use checksums
17f2cdfdf11a8abfdc83213903ed77b5c42bb01188efff4be55fb3c176d0148b
BLAKE2b-256 checksum
How to use checksums
2ac602c28ffb7c4dfebc1de01c3c8dce9a7bb1298950e4124e4a2246fae4fe0e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.

Transparency log

Release files / standup_bot-0.2.7-py3-none-any.whl

Download URL standup_bot-0.2.7-py3-none-any.whl
Size 59.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dda4e7cd983fb543e29f78e959fd575ad521996d4636650bb4695d1f4106d69c
BLAKE2b-256 checksum
How to use checksums
496285afe37f6ce6ae0396411c3d5c871d9c1a74c40ef0af7ed532230096d74a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.7 This release

2 release files

0.2.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page