Commit bac441f
committed
policy: address review — drop the .ts contradiction, ban Deno, pin bunx
Review feedback from codacy-production and coderabbitai on the policy wave.
Three substantive points, all accepted:
1. ".ts CONTRADICTION" (codacy, MEDIUM, raised on most of the wave). The Bun row
said "Executes .ts directly, no build step" in a file whose BANNED table bans
TypeScript. OWNER RULING: TypeScript "should not exist at all", so advertising
Bun's TypeScript capability is wrong regardless of whether it is true. Every
.ts reference is removed from the row, including "JS/TS" in its label.
2. "DENO MISSING FROM BANNED" (codacy, raised repeatedly). The wave removed Deno
from ALLOWED but never added it to BANNED, so the ruling was only half
expressed. Added | Deno | Bun |.
3. "UNPINNED bunx" (coderabbitai, Security & Privacy). A bare `bunx <tool>` can
fetch a package outside package.json/bun.lock, and can start Node via a
shebang - both contrary to estate SHA-pinning doctrine and the Node ban.
Guidance now requires a declared devDependency plus
`bunx --no-install --bun <tool>`.
NOT taken: "a npm-compatible" (LanguageTool is wrong, "an" is correct before a
vowel sound); "--frozen-lockfile is redundant" (correct - no change needed, and
none made); the Nix->Guix point (real, but a separate ruling, deliberately not
folded into a Deno/Bun change).1 parent 60cb277 commit bac441f
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| |||
0 commit comments