Fixes https://github.com/twentyhq/core-team-issues/issues/1956 **Problem** Within an app, the `.yarn/releases/` folder contains executable Yarn binaries that run when executing any yarn command (`.yarnrc` file indicates yarn path to be `.yarn/releases/yarn-4.9.2.cjs `.) This is a supply chain attack vector: a malicious actor could submit a PR with a compromised `yarn-4.9.2.cjs binary`, which would execute arbitrary code on developers' machines or CI systems. **Fix** Actually, thanks to Corepack, we don't need to store and execute this binary. Corepack can be seen as the manager of a package manager: in `package.json` we indicate a packageManager version like `"packageManager": "yarn@4.9.2"`, and when executing `yarn` Corepack will securely fetch the verified version from npm, avoiding the risk of executing a compromised binary committed to the repository. This was already in our app's package.json template but we were not using it! We can now - remove the folder containing the binary from our app template base-application (that is scaffolded when creating an app through cli), `.yarn/releases/`, and remove `yarnPath: .yarn/releases/yarn-4.9.2.cjs` from its .yarnrc - remove them from the community apps that were already published in the repo - add .yarn to gitignore **Tested** This has been tested and works for app created in the repo, outside the repo, and existing apps in the repo
Twenty CRM Activity Reporter ��
A TypeScript-based reporting bot that summarizes activity from your Twenty CRM workspace and sends daily/periodic reports to Slack, Discord, and WhatsApp. Meet Kylian Mbaguette, your friendly CRM activity reporter!
Features
- 🧑💻 People & Company Tracking: Summarizes newly created people and companies
- 🎯 Opportunity Monitoring: Reports on new opportunities created, broken down by stage
- ✅ Task Analytics:
- Tracks task creation
- Calculates on-time completion rates
- Identifies team members with the most overdue tasks (the "slackers")
- 🔔 Multi-Platform Notifications: Send reports to Slack, Discord, and/or WhatsApp
- ⏰ Configurable Time Range: Look back any number of days
Prerequisites
- Node.js (v14 or higher recommended)
- TypeScript
- A Twenty CRM account with API access
- Optional: Slack webhook, Discord webhook, and/or WhatsApp Business API access
Installing dependencies
# Install dependencies
yarn install
Environment Variables
| Variable | Required | Description |
|---|---|---|
TWENTY_API_KEY |
✅ Yes | Your Twenty CRM API key |
DAYS_AGO |
✅ Yes | Number of days to look back for the report |
SLACK_HOOK_URL |
❌ No | Slack incoming webhook URL |
DISCORD_WEBHOOK_URL |
❌ No | Discord webhook URL |
FB_GRAPH_TOKEN |
❌ No | Facebook Graph API token for WhatsApp |
WHATSAPP_RECIPIENT_PHONE_NUMBER |
❌ No | WhatsApp recipient phone number (with country code) |
Project Structure
.
├── index.ts # Main entry point
├── people-creation-summariser.ts # Summarizes people/company creation
├── opportunity-creation-summariser.ts # Summarizes opportunity creation
├── task-creation-summariser.ts # Summarizes task creation & completion
├── senders.ts # Handles sending to Slack/Discord/WhatsApp
├── utils.ts # API request utility
└── README.md
How It Works
- Data Collection: The bot queries the Twenty CRM API for activities within the specified time range
- Analysis:
- Counts new people and companies
- Categorizes opportunities by stage
- Calculates task completion rates and identifies overdue tasks
- Reporting: Formats the data into friendly messages
- Distribution: Sends reports to configured platforms (Slack, Discord, WhatsApp)
Report Format
Each report includes:
Bonjour! 🥖 Je m'appelle Kylian Mbaguette. Over the last X days:
🧑💻 People & Companies
- X People and Y Companies were added
🎯 Opportunities
- X Opportunities were added: Y in NEW, Z in PROPOSAL
📋 Tasks
- X Tasks were created
- Y% Tasks were completed on time
- [Name] slacked the most with Z Tasks overdue
API Integration
This bot uses the Twenty CRM REST API. The following endpoints are used:
GET /people- Fetch people dataGET /opportunities- Fetch opportunity dataGET /tasks- Fetch task dataGET /workspaceMembers/{id}- Fetch workspace member details
Notes
- The "slacker" detection is lighthearted and identifies team members with the most overdue tasks
- At least one messaging platform must be configured for the bot to send reports
- The bot uses ISO date format (YYYY-MM-DD) for date filtering
- Task completion percentage only considers incomplete tasks (excludes already completed tasks from the calculation)
Troubleshooting
Issue: No messages being sent
- Solution: Ensure at least one messaging platform is configured with valid credentials
Issue: API authentication errors
- Solution: Verify your
TWENTY_API_KEYis correct and has necessary permissions
Issue: WhatsApp messages not sending
- Solution: Ensure both
FB_GRAPH_TOKENandWHATSAPP_RECIPIENT_PHONE_NUMBERare set correctly
Contributing
Built with ❤️ and 🥖 by Azmat, Ali and Mike from 9dots