Repository navigation
Commit 60cb277
committed
policy: address review — drop the .ts contradiction, ban Deno, pin bunx
Review feedback from codacy-production and coderabbitai on the policy wave.
Three substantive points, all accepted:
1. ".ts CONTRADICTION" (codacy, MEDIUM, raised on most of the wave). The Bun row
said "Executes .ts directly, no build step" in a file whose BANNED table bans
TypeScript. True of Bun, but it reads as licence to write new TypeScript.
Reworded to compiled ESM/JS, with an explicit note that Bun's native .ts
support does NOT license new TypeScript.
2. "DENO MISSING FROM BANNED" (codacy, raised repeatedly). The wave removed Deno
from ALLOWED but never added it to BANNED, so the ruling was only half
expressed. Added | Deno | Bun |.
3. "UNPINNED bunx" (coderabbitai, Security & Privacy). A bare `bunx <tool>` can
fetch a package outside package.json/bun.lock, and can start Node via a
shebang - both contrary to estate SHA-pinning doctrine and the Node ban.
Guidance now requires a declared devDependency plus
`bunx --no-install --bun <tool>`.
NOT taken: "a npm-compatible" (LanguageTool is wrong, "an" is correct before a
vowel sound); "--frozen-lockfile is redundant" (correct - no change needed, and
none made); the Nix->Guix point (real, but a separate ruling, deliberately not
folded into a Deno/Bun change).1 parent 359d08c commit 60cb277
1 file changed
Lines changed: 3 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
| 43 | + | |
43 | 44 | | |
44 | 45 | | |
45 | 46 | | |
| |||
74 | 75 | | |
75 | 76 | | |
76 | 77 | | |
77 | | - | |
| 78 | + | |
78 | 79 | | |
79 | 80 | | |
80 | 81 | | |
| |||
0 commit comments