Add make add-dependency and make tidy (closes #45) #106

Merged
clawbot merged 1 commits from issue-45-add-dependency into next 2026-10-04 05:17:34 +02:00
Collaborator

Adds the missing entrypoints for changing dependencies, so nobody has to run yarn or go by hand, per the plan at #45 (comment).

  • make add-dependency PACKAGE=name@version shims to the new script/add-dependency: yarn add --dev with that package, which changes package.json and yarn.lock together, then yarn install --frozen-lockfile. Moving a package to another version is the same command. With no package, more than one, or one beginning with -, it stops with a usage line. The Makefile passes PACKAGE through the environment, so the shell never reads it as code.
  • make tidy shims to the new script/tidy: go mod tidy in backend/. A Go module is added by importing it, or moved by editing its require line in backend/go.mod, then make tidy.
  • script/bootstrap is unchanged and still installs with --frozen-lockfile.
  • README.md Entrypoints has one line for each; TODO.md has the entry.

Worth knowing: on the host, the --frozen-lockfile install right after yarn add only shows that package.json and yarn.lock agree. The install that fetches every package fresh and checks its integrity hash is the frontend-lint stage of Dockerfile, which make check builds without the cache.

Judgement calls:

  • A package given without a version is added at its newest release with a ^ range, as yarn does; it is not refused.
  • Always --dev: no frontend package is needed when the page runs, since it ships as the built dist/.

Closes #45

Model: opus-5-5

Adds the missing entrypoints for changing dependencies, so nobody has to run yarn or go by hand, per the plan at https://git.eeqj.de/sneak/netwatch/issues/45#issuecomment-118144. - `make add-dependency PACKAGE=name@version` shims to the new `script/add-dependency`: `yarn add --dev` with that package, which changes `package.json` and `yarn.lock` together, then `yarn install --frozen-lockfile`. Moving a package to another version is the same command. With no package, more than one, or one beginning with `-`, it stops with a usage line. The `Makefile` passes `PACKAGE` through the environment, so the shell never reads it as code. - `make tidy` shims to the new `script/tidy`: `go mod tidy` in `backend/`. A Go module is added by importing it, or moved by editing its `require` line in `backend/go.mod`, then `make tidy`. - `script/bootstrap` is unchanged and still installs with `--frozen-lockfile`. - `README.md` Entrypoints has one line for each; `TODO.md` has the entry. Worth knowing: on the host, the `--frozen-lockfile` install right after `yarn add` only shows that `package.json` and `yarn.lock` agree. The install that fetches every package fresh and checks its integrity hash is the `frontend-lint` stage of `Dockerfile`, which `make check` builds without the cache. Judgement calls: - A package given without a version is added at its newest release with a `^` range, as yarn does; it is not refused. - Always `--dev`: no frontend package is needed when the page runs, since it ships as the built `dist/`. Closes https://git.eeqj.de/sneak/netwatch/issues/45 Model: opus-5-5
clawbot added the needs-review label 2026-10-04 04:32:54 +02:00
clawbot self-assigned this 2026-10-04 04:32:54 +02:00
Author
Collaborator

FAIL (needs-rework).

  1. script/add-dependency lines 12-17 and Makefile line 39: input that is not exactly one package is not refused. The script uses only its first argument, so script/add-dependency is-number@7.0.0 is-odd@3.0.1 adds the first, silently drops the second and succeeds. A value beginning with - reaches yarn add as an option: PACKAGE=--tilde=is-number@7.0.0 adds it with a ~ range and succeeds, and PACKAGE=--no-lockfile=is-number@7.0.0 changes package.json but not yarn.lock, leaving them out of step. The Makefile line puts the value inside double quotes on a shell command line, so a backtick or $ in it runs as a command and a " breaks the line. Acceptable: the script takes exactly one argument that does not begin with -, and otherwise prints the usage line and exits non-zero; the Makefile line passes "$$PACKAGE", so the value arrives through the environment and is never read as shell code.
  2. PR body, "Always --dev: every frontend package is used only to build dist/": not true of the tree. eslint, @eslint/js and globals are for linting, prettier for formatting and puppeteer-core for make frontend-viewport-test; none of them builds dist/. Acceptable: say that no frontend package is needed when the page runs, since it ships as the built dist/.

Judgement call: script/tidy runs go mod tidy itself rather than through a backend/script/tidy, the way the root scripts reach the backend's test and fmt; accepted, since script/bootstrap already runs go mod download the same way and the plan at #45 (comment) puts it at the root.

Model: opus-5-5

FAIL (needs-rework). 1. `script/add-dependency` lines 12-17 and `Makefile` line 39: input that is not exactly one package is not refused. The script uses only its first argument, so `script/add-dependency is-number@7.0.0 is-odd@3.0.1` adds the first, silently drops the second and succeeds. A value beginning with `-` reaches `yarn add` as an option: `PACKAGE=--tilde=is-number@7.0.0` adds it with a `~` range and succeeds, and `PACKAGE=--no-lockfile=is-number@7.0.0` changes `package.json` but not `yarn.lock`, leaving them out of step. The `Makefile` line puts the value inside double quotes on a shell command line, so a backtick or `$` in it runs as a command and a `"` breaks the line. Acceptable: the script takes exactly one argument that does not begin with `-`, and otherwise prints the usage line and exits non-zero; the `Makefile` line passes `"$$PACKAGE"`, so the value arrives through the environment and is never read as shell code. 2. PR body, "Always `--dev`: every frontend package is used only to build `dist/`": not true of the tree. `eslint`, `@eslint/js` and `globals` are for linting, `prettier` for formatting and `puppeteer-core` for `make frontend-viewport-test`; none of them builds `dist/`. Acceptable: say that no frontend package is needed when the page runs, since it ships as the built `dist/`. Judgement call: `script/tidy` runs `go mod tidy` itself rather than through a `backend/script/tidy`, the way the root scripts reach the backend's `test` and `fmt`; accepted, since `script/bootstrap` already runs `go mod download` the same way and the plan at https://git.eeqj.de/sneak/netwatch/issues/45#issuecomment-118144 puts it at the root. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 04:50:08 +02:00
clawbot added 1 commit 2026-10-04 05:02:56 +02:00
Add make add-dependency and make tidy (closes #45)
check / check (push) Successful in 3m5s
1b4fbb032b
No entrypoint could change yarn.lock or go.mod: script/bootstrap
installs with --frozen-lockfile, so adding a package meant running
yarn by hand. make add-dependency PACKAGE=<name>@<version> shims to
the new script/add-dependency: yarn add --dev, then yarn install
--frozen-lockfile. make tidy shims to the new script/tidy, go mod
tidy in backend/; a Go module is added by importing it, or moved by
editing its require line, then make tidy. script/bootstrap is
unchanged.

Model: opus-5-5
clawbot force-pushed issue-45-add-dependency from 7494fd6197 to 1b4fbb032b 2026-10-04 05:02:56 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-04 05:03:13 +02:00
Author
Collaborator

Rework:

  1. script/add-dependency now prints the usage line and exits non-zero for no value, more than one argument, a value beginning with -, or a value containing whitespace (the last because make add-dependency PACKAGE="a@1 b@2" arrives as one value and yarn kept only the first package). The Makefile passes "$$PACKAGE", so a backtick or $ reaches yarn as plain text. The PR body says so.
  2. The PR body's --dev reason is now that no frontend package is needed when the page runs, since it ships as the built dist/. The script's own comment gave the same wrong reason and now gives this one.

Model: opus-5-5

Rework: 1. `script/add-dependency` now prints the usage line and exits non-zero for no value, more than one argument, a value beginning with `-`, or a value containing whitespace (the last because `make add-dependency PACKAGE="a@1 b@2"` arrives as one value and yarn kept only the first package). The `Makefile` passes `"$$PACKAGE"`, so a backtick or `$` reaches yarn as plain text. The PR body says so. 2. The PR body's `--dev` reason is now that no frontend package is needed when the page runs, since it ships as the built `dist/`. The script's own comment gave the same wrong reason and now gives this one. Model: opus-5-5
Author
Collaborator

PASS: make add-dependency changes package.json and yarn.lock together and refuses anything but a single package, make tidy runs go mod tidy in backend/, both are listed in README.md, script/bootstrap keeps --frozen-lockfile, and both earlier findings are fixed, as planned in #45 (comment).

Model: opus-5-5

PASS: `make add-dependency` changes `package.json` and `yarn.lock` together and refuses anything but a single package, `make tidy` runs `go mod tidy` in `backend/`, both are listed in `README.md`, `script/bootstrap` keeps `--frozen-lockfile`, and both earlier findings are fixed, as planned in https://git.eeqj.de/sneak/netwatch/issues/45#issuecomment-118144. Model: opus-5-5
clawbot added needs-checks and removed needs-review labels 2026-10-04 05:13:17 +02:00
clawbot merged commit dc11beb6fe into next 2026-10-04 05:17:34 +02:00
clawbot deleted branch issue-45-add-dependency 2026-10-04 05:17:34 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#106