From 1b4fbb032ba7956174c3edf2a42cb49b6cd14de4 Mon Sep 17 00:00:00 2001 From: sneak Date: Sun, 4 Oct 2026 02:25:34 +0000 Subject: [PATCH] Add make add-dependency and make tidy (closes #45) No entrypoint could change yarn.lock or go.mod: script/bootstrap installs with --frozen-lockfile, so adding a package meant running yarn by hand. make add-dependency PACKAGE=@ shims to the new script/add-dependency: yarn add --dev, then yarn install --frozen-lockfile. make tidy shims to the new script/tidy, go mod tidy in backend/; a Go module is added by importing it, or moved by editing its require line, then make tidy. script/bootstrap is unchanged. Model: opus-5-5 --- Makefile | 10 +++++++++- README.md | 7 +++++++ TODO.md | 8 ++++++++ script/add-dependency | 30 ++++++++++++++++++++++++++++++ script/tidy | 13 +++++++++++++ 5 files changed, 67 insertions(+), 1 deletion(-) create mode 100755 script/add-dependency create mode 100755 script/tidy diff --git a/Makefile b/Makefile index 3369fb9..29d7600 100644 --- a/Makefile +++ b/Makefile @@ -1,5 +1,5 @@ .PHONY: bootstrap setup dev build test lint fmt fmt-check check \ - frontend-check frontend-viewport-test docker hooks + add-dependency tidy frontend-check frontend-viewport-test docker hooks # Standard targets are thin shims; the implementations live in script/ # per the scripts-to-rule-them-all pattern (see the Entrypoints section @@ -34,6 +34,14 @@ fmt-check: check: @script/check +# make add-dependency PACKAGE=@. PACKAGE reaches the +# script through the environment, so the shell never reads it as code. +add-dependency: + @script/add-dependency "$$PACKAGE" + +tidy: + @script/tidy + # The frontend tests and format check, for Dockerfile's frontend stage, # which has neither Go nor Docker. Use check everywhere else. frontend-check: diff --git a/README.md b/README.md index b4e4de7..a963e6a 100644 --- a/README.md +++ b/README.md @@ -58,6 +58,13 @@ halves, so the root `make check` fails if either one is broken. We provide: - `script/fmt` — format all files (writes): prettier, then gofmt over `backend/` - `script/fmt-check` — check formatting (read-only): prettier, then gofmt - `script/check` — run test, lint, and fmt-check +- `script/add-dependency` — add a frontend package, or move one to another + version: `make add-dependency PACKAGE=@` runs `yarn add --dev`, + which changes `package.json` and `yarn.lock` together, then + `yarn install --frozen-lockfile` +- `script/tidy` — run `go mod tidy` in `backend/`: to add a Go module, import it + and run `make tidy`; to move one to another version, edit its `require` line + in `backend/go.mod`, then run `make tidy` - `script/frontend-test` — run the unit tests in `test/unit/` with Node's built-in test runner, through the `test` script in `package.json`, and if any fails, run them again listing every test, and fail; then the production build. diff --git a/TODO.md b/TODO.md index 5f4e5c6..12cf93b 100644 --- a/TODO.md +++ b/TODO.md @@ -23,6 +23,14 @@ latest run passes. # Completed Steps +- 2026-10-04: a dependency can be added without running yarn or go by hand + (issue #45): `make add-dependency PACKAGE=@` shims to the new + `script/add-dependency`, which runs `yarn add --dev`, so `package.json` and + `yarn.lock` change together, then `yarn install --frozen-lockfile`; the same + command moves a package to another version. `make tidy` shims to the new + `script/tidy`, which runs `go mod tidy` in `backend/`: a Go module is added by + importing it, or moved by editing its `require` line, then `make tidy`. + `script/bootstrap` still installs with `--frozen-lockfile` - 2026-10-04: the backend serves Prometheus metrics (issue #94). With `METRICS_USERNAME` and `METRICS_PASSWORD` both set, it records request duration and response size through `go-http-metrics` and serves them, with diff --git a/script/add-dependency b/script/add-dependency new file mode 100755 index 0000000..7a4230c --- /dev/null +++ b/script/add-dependency @@ -0,0 +1,30 @@ +#!/bin/sh +# script/add-dependency: add a frontend package, or move one to another +# version, with yarn add, which changes package.json and yarn.lock +# together; then install from yarn.lock with --frozen-lockfile, as +# script/bootstrap does, to show it installs as written. --dev because +# no frontend package is needed when the page runs: it ships as the +# built dist/. +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +usage() { + echo "usage: make add-dependency PACKAGE=@" >&2 + exit 2 +} + +main() { + # Exactly one package. A value beginning with - would reach yarn as + # an option; yarn would quietly drop all but the first of several + # packages given in one value. + [ "$#" -eq 1 ] || usage + case "$1" in + "" | -* | *[[:space:]]*) usage ;; + esac + cd "$ROOT" + yarn add --dev "$1" + yarn install --frozen-lockfile +} + +main "$@" diff --git a/script/tidy b/script/tidy new file mode 100755 index 0000000..fadf4cd --- /dev/null +++ b/script/tidy @@ -0,0 +1,13 @@ +#!/bin/sh +# script/tidy: run go mod tidy in backend/, which adds the modules the +# Go sources import, drops those they no longer do, and updates go.sum. +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +main() { + cd "$ROOT/backend" + go mod tidy +} + +main "$@"