Skip to content

Commit d371e81

Browse files
committed
policy: address review — drop the .ts contradiction, ban Deno, pin bunx
Review feedback from codacy-production and coderabbitai on the policy wave. Three substantive points, all accepted: 1. ".ts CONTRADICTION" (codacy, MEDIUM, raised on most of the wave). The Bun row said "Executes .ts directly, no build step" in a file whose BANNED table bans TypeScript. OWNER RULING: TypeScript "should not exist at all", so advertising Bun's TypeScript capability is wrong regardless of whether it is true. Every .ts reference is removed from the row, including "JS/TS" in its label. 2. "DENO MISSING FROM BANNED" (codacy, raised repeatedly). The wave removed Deno from ALLOWED but never added it to BANNED, so the ruling was only half expressed. Added | Deno | Bun |. 3. "UNPINNED bunx" (coderabbitai, Security & Privacy). A bare `bunx <tool>` can fetch a package outside package.json/bun.lock, and can start Node via a shebang - both contrary to estate SHA-pinning doctrine and the Node ban. Guidance now requires a declared devDependency plus `bunx --no-install --bun <tool>`. NOT taken: "a npm-compatible" (LanguageTool is wrong, "an" is correct before a vowel sound); "--frozen-lockfile is redundant" (correct - no change needed, and none made); the Nix->Guix point (real, but a separate ruling, deliberately not folded into a Deno/Bun change).
1 parent 9015e59 commit d371e81

26 files changed

Lines changed: 78 additions & 52 deletions

File tree

‎asdf-acceleration-middleware/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -25,6 +25,7 @@
2525
| Banned | Replacement |
2626
|--------|-------------|
2727
| TypeScript | AffineScript |
28+
| Deno | Bun |
2829
| Node.js | Bun |
2930
| npm | Bun |
3031
| pnpm/yarn | Bun |
@@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech).
5758

5859
- **Primary**: Guix (guix.scm)
5960
- **Fallback**: Guix (flake.guix)
60-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
61+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6162

6263
### Security Requirements
6364

‎asdf-ada-plugin/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -25,6 +25,7 @@
2525
| Banned | Replacement |
2626
|--------|-------------|
2727
| TypeScript | AffineScript |
28+
| Deno | Bun |
2829
| Node.js | Bun |
2930
| npm | Bun |
3031
| pnpm/yarn | Bun |
@@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech).
5758

5859
- **Primary**: Guix (guix.scm)
5960
- **Fallback**: Guix (flake.guix)
60-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
61+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6162

6263
### Security Requirements
6364

‎asdf-augmenters/asdf-acceleration-middleware/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -25,6 +25,7 @@
2525
| Banned | Replacement |
2626
|--------|-------------|
2727
| TypeScript | AffineScript |
28+
| Deno | Bun |
2829
| Node.js | Bun |
2930
| npm | Bun |
3031
| pnpm/yarn | Bun |
@@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech).
5758

5859
- **Primary**: Guix (guix.scm)
5960
- **Fallback**: Guix (flake.guix)
60-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
61+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6162

6263
### Security Requirements
6364

‎asdf-augmenters/asdf-control-tower/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -25,6 +25,7 @@
2525
| Banned | Replacement |
2626
|--------|-------------|
2727
| TypeScript | AffineScript |
28+
| Deno | Bun |
2829
| Node.js | Bun |
2930
| npm | Bun |
3031
| pnpm/yarn | Bun |
@@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech).
5758

5859
- **Primary**: Guix (guix.scm)
5960
- **Fallback**: Guix (flake.guix)
60-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
61+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6162

6263
### Security Requirements
6364

‎asdf-augmenters/asdf-ghjk/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -25,6 +25,7 @@
2525
| Banned | Replacement |
2626
|--------|-------------|
2727
| TypeScript | AffineScript |
28+
| Deno | Bun |
2829
| Node.js | Bun |
2930
| npm | Bun |
3031
| pnpm/yarn | Bun |
@@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech).
5758

5859
- **Primary**: Guix (guix.scm)
5960
- **Fallback**: Guix (flake.guix)
60-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
61+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6162

6263
### Security Requirements
6364

‎asdf-augmenters/asdf-metaiconic-plugin/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -25,6 +25,7 @@
2525
| Banned | Replacement |
2626
|--------|-------------|
2727
| TypeScript | AffineScript |
28+
| Deno | Bun |
2829
| Node.js | Bun |
2930
| npm | Bun |
3031
| pnpm/yarn | Bun |
@@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech).
5758

5859
- **Primary**: Guix (guix.scm)
5960
- **Fallback**: Guix (flake.guix)
60-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
61+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6162

6263
### Security Requirements
6364

‎asdf-augmenters/asdf-plugin-collection/plugins/ada/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -25,6 +25,7 @@
2525
| Banned | Replacement |
2626
|--------|-------------|
2727
| TypeScript | AffineScript |
28+
| Deno | Bun |
2829
| Node.js | Bun |
2930
| npm | Bun |
3031
| pnpm/yarn | Bun |
@@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech).
5758

5859
- **Primary**: Guix (guix.scm)
5960
- **Fallback**: Guix (flake.guix)
60-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
61+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6162

6263
### Security Requirements
6364

‎asdf-augmenters/asdf-plugin-collection/plugins/cobol/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -26,6 +26,7 @@
2626
| Banned | Replacement |
2727
|--------|-------------|
2828
| TypeScript | AffineScript |
29+
| Deno | Bun |
2930
| Node.js | Bun |
3031
| npm | Bun |
3132
| pnpm/yarn | Bun |
@@ -58,7 +59,7 @@ Both are FOSS with independent governance (no Big Tech).
5859

5960
- **Primary**: Guix (guix.scm)
6061
- **Fallback**: Guix (flake.guix)
61-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
62+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6263

6364
### Security Requirements
6465

‎asdf-augmenters/asdf-plugin-collection/plugins/metaiconic/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -25,6 +25,7 @@
2525
| Banned | Replacement |
2626
|--------|-------------|
2727
| TypeScript | AffineScript |
28+
| Deno | Bun |
2829
| Node.js | Bun |
2930
| npm | Bun |
3031
| pnpm/yarn | Bun |
@@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech).
5758

5859
- **Primary**: Guix (guix.scm)
5960
- **Fallback**: Guix (flake.guix)
60-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
61+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6162

6263
### Security Requirements
6364

‎asdf-augmenters/asdf-plugin-collection/plugins/security/.claude/CLAUDE.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
| Language/Tool | Use Case | Notes |
88
|---------------|----------|-------|
99
| **AffineScript** | Primary application code | Compiles to JS, type-safe |
10-
| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
10+
| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. |
1111
| **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools |
1212
| **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI |
1313
| **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like |
@@ -26,6 +26,7 @@
2626
| Banned | Replacement |
2727
|--------|-------------|
2828
| TypeScript | AffineScript |
29+
| Deno | Bun |
2930
| Node.js | Bun |
3031
| npm | Bun |
3132
| pnpm/yarn | Bun |
@@ -58,7 +59,7 @@ Both are FOSS with independent governance (no Big Tech).
5859

5960
- **Primary**: Guix (guix.scm)
6061
- **Fallback**: Guix (flake.guix)
61-
- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx <tool>` for one-off tooling
62+
- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang.
6263

6364
### Security Requirements
6465

0 commit comments

Comments
 (0)