114 API operations with no telemetry found in Langfuse
The same five checks, pointed at a service rather than a library — the open-source LLM observability platform a great many LangChain apps are already wired into. The answers come back almost inverted: the check that found nothing in LangChain does most of the work here, and the ones that carried that report have nothing to say about this one.
- Repository
- langfuse/langfuse
- Commit
- ea3c905cd535fb7d54c008ed8ea89d6f3ba684b9
- Subject
- fix: enforce OTLP ingestion request body limits (#16487)
- Scanned
- 2026-08-25 · 2,755 source files · ebb 0.1.0
This is an independent analysis of a public repository. Foretop is not affiliated with or endorsed by the repository owner.
What Ebb, telltale, charter and lading found
Ebb, telltale, charter and lading are the checks you can install and re-run yourself today. Each one's scope, its result, and — below — every line it matched.
| Check | Scope | Results | Outcome |
|---|---|---|---|
| ebb | whole repo | 1,978 | Model IDs matched against the bundled retirement registry. |
| telltale | web/public/generated/api/openapi.yml | 2,948 | 114 documented operations checked against every Prometheus alert rule, OTel Collector pipeline and Grafana dashboard committed to this repo. |
| charter | repo root | — | No .mcp.json or .cursor/mcp.json in the repo — no agent configuration is declared here, so there is nothing to hold a capability baseline against. |
| lading | repo root | — | No uv.lock anywhere in the repo. Langfuse is TypeScript (2,740 .ts files against 5 .py), and lading reads uv.lock only — a documented gap in the tool, not a clean bill of health for the dependency tree. |
Every result, grouped and filterable
Deduplicated into real issue groups, never one row per raw occurrence. Filter by check, deadline, provider or context, or search — every filter is reflected in the URL, so a filtered view is a link you can share.
No telemetry configuration (Prometheus alert rules, an OTel Collector config, or a Grafana dashboard) was found anywhere in this repository. This does not prove the hosted service is unmonitored — only that none is declared here.
3 issue groups across 46 occurrences · 4,934 scanned
Act now claude-3-5-haiku-20241022 Act now · retired 2026-02-19 · configuration reference 5 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| configuration | .github/workflows/claude-code-security-review.yml:57 | claude-3-5-haiku-20241022 |
| unknown | packages/shared/src/server/llm/types.ts:402 | claude-3-5-haiku-20241022 |
| configuration | worker/src/constants/default-model-prices.json:1915 | claude-3-5-haiku-20241022 |
| configuration | worker/src/constants/default-model-prices.json:1916 | claude-3-5-haiku-20241022 |
| configuration | worker/src/constants/default-model-prices.json:1916 | claude-3-5-haiku-20241022 |
Act now claude-opus-4-1-20250805 Act now · retired 2026-08-05 · configuration reference 3 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| configuration | .github/workflows/claude-code-security-review.yml:68 | claude-opus-4-1-20250805 |
| unknown | packages/shared/src/server/llm/types.ts:395 | claude-opus-4-1-20250805 |
| configuration | worker/src/constants/default-model-prices.json:3319 | claude-opus-4-1-20250805 |
Act now gemini-2.0-flash Act now · retired 2026-06-01 · configuration reference 38 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:84 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:89 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:176 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:234 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:337 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:350 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:448 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:453 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:519 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:553 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:651 | gemini-2.0-flash |
| configuration | packages/shared/scripts/seeder/utils/framework-traces/google-adk-2025-08-28.json:664 | gemini-2.0-flash |
| unknown | packages/shared/src/server/llm/types.ts:426 | gemini-2.0-flash |
| unknown | packages/shared/src/server/llm/types.ts:450 | gemini-2.0-flash |
| unknown | packages/shared/src/server/llm/types.ts:451 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/adapters/gemini.test.ts:200 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:90 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:144 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:325 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:327 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:362 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:362 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:362 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:362 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:380 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:382 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:417 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:417 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:417 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/framework-traces/google-adk-2025-08-28.trace.json:417 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/integration.test.ts:201 | gemini-2.0-flash |
| test_fixture | worker/src/__tests__/chatml/integration.test.ts:252 | gemini-2.0-flash |
| configuration | worker/src/constants/default-model-prices.json:2267 | gemini-2.0-flash |
| configuration | worker/src/constants/default-model-prices.json:2268 | gemini-2.0-flash |
| configuration | worker/src/constants/default-model-prices.json:2897 | gemini-2.0-flash |
| configuration | worker/src/constants/default-model-prices.json:2898 | gemini-2.0-flash |
| configuration | worker/src/constants/default-model-prices.json:2917 | gemini-2.0-flash |
| configuration | worker/src/constants/default-model-prices.json:2918 | gemini-2.0-flash |
Who else processes your data
undertow is the one check here that never looks at a repository. It reads the vendor's own published subprocessor page and turns it into a structured list you can diff on the next run — 8 entries, extracted from the live page.
- Requested
- https://langfuse.com/security/subprocessors
- Resolved to
- https://clickhouse.com/legal/agreements/langfuse-subprocessors
The URL is Langfuse's own. It now redirects to ClickHouse's legal site, which is the finding: ClickHouse acquired Langfuse, so the legal entity processing data ingested into Langfuse Cloud changed. A redirect is exactly the kind of quiet change a screenshot diff would show as noise and a person would skim past.
| Subprocessor | Service | Region | Effective |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure provider | — | 2026-08-10 |
| AWS Bedrock | Generative AI services | — | 2026-08-10 |
| Salesforce, Inc. | Customer support case management, messaging services (Slack) | United States of America | 2026-08-10 |
| Pylon Labs, Inc. | Customer support chat platform | United States of America | 2026-08-10 |
| Google LLC (Workspace) | Email and office applications | United States of America | 2026-08-10 |
| Waypoint Tech Inc. | Support knowledge management | United States of America | 2026-08-10 |
| Github, Inc. | Support escalations | United States of America | 2026-08-10 |
| kapa.ai, Inc. | Support deflection with AI | United States of America | 2026-08-10 |
And the 1,780 we could not answer
1,780 of ebb's 1,978 results are ?unknown — model strings that are real references but are not in the retirement registry, so no deadline can be claimed for them. They are reported as unknown, not quietly dropped and not counted as clear. They are visible in the Review tab above, not hidden below the fold.
If a tool showed you only the 198 it could resolve and said nothing about the other 1,780 strings it walked past, you would have no way to know the difference between "checked and fine" and "never looked".
The same five checks, elsewhere
What a suite is for: the answers come back in a different shape for every codebase, and which checks have nothing to say is itself information.
Preview: what Undertow observed
Undertow is still in development. It is not publicly installable, and nothing below can be reproduced by a reader today — it is shown because a check that cannot see something has to say so, including here. Ebb, telltale, charter and lading, above, are all available now.
| Check | Scope | Observations | Outcome |
|---|---|---|---|
| undertow | langfuse.com/security/subprocessors | 8 | One real vendor page, fetched live and extracted into a structured subprocessor list. |
Run it on yours
Same command, same registry, no account and no upload — detection is local and only results ever leave your machine.
Results above are a snapshot at
commit ea3c905, taken 2026-08-25. Both
projects move quickly; re-running it today may return something different, which is
rather the point.