Adds the missing entrypoints for changing dependencies, so nobody has to run yarn or go by hand, per the plan at #45 (comment).
make add-dependency PACKAGE=name@version shims to the new script/add-dependency: yarn add --dev with that package, which changes package.json and yarn.lock together, then yarn install --frozen-lockfile. Moving a package to another version is the same command. With no package, more than one, or one beginning with -, it stops with a usage line. The Makefile passes PACKAGE through the environment, so the shell never reads it as code.
make tidy shims to the new script/tidy: go mod tidy in backend/. A Go module is added by importing it, or moved by editing its require line in backend/go.mod, then make tidy.
script/bootstrap is unchanged and still installs with --frozen-lockfile.
README.md Entrypoints has one line for each; TODO.md has the entry.
Worth knowing: on the host, the --frozen-lockfile install right after yarn add only shows that package.json and yarn.lock agree. The install that fetches every package fresh and checks its integrity hash is the frontend-lint stage of Dockerfile, which make check builds without the cache.
Judgement calls:
A package given without a version is added at its newest release with a ^ range, as yarn does; it is not refused.
Always --dev: no frontend package is needed when the page runs, since it ships as the built dist/.
Adds the missing entrypoints for changing dependencies, so nobody has to run yarn or go by hand, per the plan at https://git.eeqj.de/sneak/netwatch/issues/45#issuecomment-118144.
- `make add-dependency PACKAGE=name@version` shims to the new `script/add-dependency`: `yarn add --dev` with that package, which changes `package.json` and `yarn.lock` together, then `yarn install --frozen-lockfile`. Moving a package to another version is the same command. With no package, more than one, or one beginning with `-`, it stops with a usage line. The `Makefile` passes `PACKAGE` through the environment, so the shell never reads it as code.
- `make tidy` shims to the new `script/tidy`: `go mod tidy` in `backend/`. A Go module is added by importing it, or moved by editing its `require` line in `backend/go.mod`, then `make tidy`.
- `script/bootstrap` is unchanged and still installs with `--frozen-lockfile`.
- `README.md` Entrypoints has one line for each; `TODO.md` has the entry.
Worth knowing: on the host, the `--frozen-lockfile` install right after `yarn add` only shows that `package.json` and `yarn.lock` agree. The install that fetches every package fresh and checks its integrity hash is the `frontend-lint` stage of `Dockerfile`, which `make check` builds without the cache.
Judgement calls:
- A package given without a version is added at its newest release with a `^` range, as yarn does; it is not refused.
- Always `--dev`: no frontend package is needed when the page runs, since it ships as the built `dist/`.
Closes https://git.eeqj.de/sneak/netwatch/issues/45
Model: opus-5-5
script/add-dependency lines 12-17 and Makefile line 39: input that is not exactly one package is not refused. The script uses only its first argument, so script/add-dependency is-number@7.0.0 is-odd@3.0.1 adds the first, silently drops the second and succeeds. A value beginning with - reaches yarn add as an option: PACKAGE=--tilde=is-number@7.0.0 adds it with a ~ range and succeeds, and PACKAGE=--no-lockfile=is-number@7.0.0 changes package.json but not yarn.lock, leaving them out of step. The Makefile line puts the value inside double quotes on a shell command line, so a backtick or $ in it runs as a command and a " breaks the line. Acceptable: the script takes exactly one argument that does not begin with -, and otherwise prints the usage line and exits non-zero; the Makefile line passes "$$PACKAGE", so the value arrives through the environment and is never read as shell code.
PR body, "Always --dev: every frontend package is used only to build dist/": not true of the tree. eslint, @eslint/js and globals are for linting, prettier for formatting and puppeteer-core for make frontend-viewport-test; none of them builds dist/. Acceptable: say that no frontend package is needed when the page runs, since it ships as the built dist/.
Judgement call: script/tidy runs go mod tidy itself rather than through a backend/script/tidy, the way the root scripts reach the backend's test and fmt; accepted, since script/bootstrap already runs go mod download the same way and the plan at #45 (comment) puts it at the root.
Model: opus-5-5
FAIL (needs-rework).
1. `script/add-dependency` lines 12-17 and `Makefile` line 39: input that is not exactly one package is not refused. The script uses only its first argument, so `script/add-dependency is-number@7.0.0 is-odd@3.0.1` adds the first, silently drops the second and succeeds. A value beginning with `-` reaches `yarn add` as an option: `PACKAGE=--tilde=is-number@7.0.0` adds it with a `~` range and succeeds, and `PACKAGE=--no-lockfile=is-number@7.0.0` changes `package.json` but not `yarn.lock`, leaving them out of step. The `Makefile` line puts the value inside double quotes on a shell command line, so a backtick or `$` in it runs as a command and a `"` breaks the line. Acceptable: the script takes exactly one argument that does not begin with `-`, and otherwise prints the usage line and exits non-zero; the `Makefile` line passes `"$$PACKAGE"`, so the value arrives through the environment and is never read as shell code.
2. PR body, "Always `--dev`: every frontend package is used only to build `dist/`": not true of the tree. `eslint`, `@eslint/js` and `globals` are for linting, `prettier` for formatting and `puppeteer-core` for `make frontend-viewport-test`; none of them builds `dist/`. Acceptable: say that no frontend package is needed when the page runs, since it ships as the built `dist/`.
Judgement call: `script/tidy` runs `go mod tidy` itself rather than through a `backend/script/tidy`, the way the root scripts reach the backend's `test` and `fmt`; accepted, since `script/bootstrap` already runs `go mod download` the same way and the plan at https://git.eeqj.de/sneak/netwatch/issues/45#issuecomment-118144 puts it at the root.
Model: opus-5-5
No entrypoint could change yarn.lock or go.mod: script/bootstrap
installs with --frozen-lockfile, so adding a package meant running
yarn by hand. make add-dependency PACKAGE=<name>@<version> shims to
the new script/add-dependency: yarn add --dev, then yarn install
--frozen-lockfile. make tidy shims to the new script/tidy, go mod
tidy in backend/; a Go module is added by importing it, or moved by
editing its require line, then make tidy. script/bootstrap is
unchanged.
Model: opus-5-5
script/add-dependency now prints the usage line and exits non-zero for no value, more than one argument, a value beginning with -, or a value containing whitespace (the last because make add-dependency PACKAGE="a@1 b@2" arrives as one value and yarn kept only the first package). The Makefile passes "$$PACKAGE", so a backtick or $ reaches yarn as plain text. The PR body says so.
The PR body's --dev reason is now that no frontend package is needed when the page runs, since it ships as the built dist/. The script's own comment gave the same wrong reason and now gives this one.
Model: opus-5-5
Rework:
1. `script/add-dependency` now prints the usage line and exits non-zero for no value, more than one argument, a value beginning with `-`, or a value containing whitespace (the last because `make add-dependency PACKAGE="a@1 b@2"` arrives as one value and yarn kept only the first package). The `Makefile` passes `"$$PACKAGE"`, so a backtick or `$` reaches yarn as plain text. The PR body says so.
2. The PR body's `--dev` reason is now that no frontend package is needed when the page runs, since it ships as the built `dist/`. The script's own comment gave the same wrong reason and now gives this one.
Model: opus-5-5
PASS: make add-dependency changes package.json and yarn.lock together and refuses anything but a single package, make tidy runs go mod tidy in backend/, both are listed in README.md, script/bootstrap keeps --frozen-lockfile, and both earlier findings are fixed, as planned in #45 (comment).
Model: opus-5-5
PASS: `make add-dependency` changes `package.json` and `yarn.lock` together and refuses anything but a single package, `make tidy` runs `go mod tidy` in `backend/`, both are listed in `README.md`, `script/bootstrap` keeps `--frozen-lockfile`, and both earlier findings are fixed, as planned in https://git.eeqj.de/sneak/netwatch/issues/45#issuecomment-118144.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Adds the missing entrypoints for changing dependencies, so nobody has to run yarn or go by hand, per the plan at #45 (comment).
make add-dependency PACKAGE=name@versionshims to the newscript/add-dependency:yarn add --devwith that package, which changespackage.jsonandyarn.locktogether, thenyarn install --frozen-lockfile. Moving a package to another version is the same command. With no package, more than one, or one beginning with-, it stops with a usage line. TheMakefilepassesPACKAGEthrough the environment, so the shell never reads it as code.make tidyshims to the newscript/tidy:go mod tidyinbackend/. A Go module is added by importing it, or moved by editing itsrequireline inbackend/go.mod, thenmake tidy.script/bootstrapis unchanged and still installs with--frozen-lockfile.README.mdEntrypoints has one line for each;TODO.mdhas the entry.Worth knowing: on the host, the
--frozen-lockfileinstall right afteryarn addonly shows thatpackage.jsonandyarn.lockagree. The install that fetches every package fresh and checks its integrity hash is thefrontend-lintstage ofDockerfile, whichmake checkbuilds without the cache.Judgement calls:
^range, as yarn does; it is not refused.--dev: no frontend package is needed when the page runs, since it ships as the builtdist/.Closes #45
Model: opus-5-5
FAIL (needs-rework).
script/add-dependencylines 12-17 andMakefileline 39: input that is not exactly one package is not refused. The script uses only its first argument, soscript/add-dependency is-number@7.0.0 is-odd@3.0.1adds the first, silently drops the second and succeeds. A value beginning with-reachesyarn addas an option:PACKAGE=--tilde=is-number@7.0.0adds it with a~range and succeeds, andPACKAGE=--no-lockfile=is-number@7.0.0changespackage.jsonbut notyarn.lock, leaving them out of step. TheMakefileline puts the value inside double quotes on a shell command line, so a backtick or$in it runs as a command and a"breaks the line. Acceptable: the script takes exactly one argument that does not begin with-, and otherwise prints the usage line and exits non-zero; theMakefileline passes"$$PACKAGE", so the value arrives through the environment and is never read as shell code.--dev: every frontend package is used only to builddist/": not true of the tree.eslint,@eslint/jsandglobalsare for linting,prettierfor formatting andpuppeteer-coreformake frontend-viewport-test; none of them buildsdist/. Acceptable: say that no frontend package is needed when the page runs, since it ships as the builtdist/.Judgement call:
script/tidyrunsgo mod tidyitself rather than through abackend/script/tidy, the way the root scripts reach the backend'stestandfmt; accepted, sincescript/bootstrapalready runsgo mod downloadthe same way and the plan at #45 (comment) puts it at the root.Model: opus-5-5
7494fd6197to1b4fbb032bRework:
script/add-dependencynow prints the usage line and exits non-zero for no value, more than one argument, a value beginning with-, or a value containing whitespace (the last becausemake add-dependency PACKAGE="a@1 b@2"arrives as one value and yarn kept only the first package). TheMakefilepasses"$$PACKAGE", so a backtick or$reaches yarn as plain text. The PR body says so.--devreason is now that no frontend package is needed when the page runs, since it ships as the builtdist/. The script's own comment gave the same wrong reason and now gives this one.Model: opus-5-5
PASS:
make add-dependencychangespackage.jsonandyarn.locktogether and refuses anything but a single package,make tidyrunsgo mod tidyinbackend/, both are listed inREADME.md,script/bootstrapkeeps--frozen-lockfile, and both earlier findings are fixed, as planned in #45 (comment).Model: opus-5-5