Skip to content

Commit bac441f

Browse files
committed
policy: address review — drop the .ts contradiction, ban Deno, pin bunx
Review feedback from codacy-production and coderabbitai on the policy wave. Three substantive points, all accepted: 1. ".ts CONTRADICTION" (codacy, MEDIUM, raised on most of the wave). The Bun row said "Executes .ts directly, no build step" in a file whose BANNED table bans TypeScript. OWNER RULING: TypeScript "should not exist at all", so advertising Bun's TypeScript capability is wrong regardless of whether it is true. Every .ts reference is removed from the row, including "JS/TS" in its label. 2. "DENO MISSING FROM BANNED" (codacy, raised repeatedly). The wave removed Deno from ALLOWED but never added it to BANNED, so the ruling was only half expressed. Added | Deno | Bun |. 3. "UNPINNED bunx" (coderabbitai, Security & Privacy). A bare `bunx <tool>` can fetch a package outside package.json/bun.lock, and can start Node via a shebang - both contrary to estate SHA-pinning doctrine and the Node ban. Guidance now requires a declared devDependency plus `bunx --no-install --bun <tool>`. NOT taken: "a npm-compatible" (LanguageTool is wrong, "an" is correct before a vowel sound); "--frozen-lockfile is redundant" (correct - no change needed, and none made); the Nix->Guix point (real, but a separate ruling, deliberately not folded into a Deno/Bun change).
1 parent 60cb277 commit bac441f

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎.claude/CLAUDE.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ project metadata (a2ml is TOML-flavoured, not Guile Scheme):
2121
| Language/Tool | Use Case | Notes |
2222
|---------------|----------|-------|
2323
| **AffineScript** | Primary application code | Compiles to JS/WASM, linear/affine type system |
24-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. Bun's native `.ts` execution does **not** license new TypeScript (see BANNED). |
24+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
2525
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
2626
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
2727
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |

0 commit comments

Comments
 (0)