Skip to content

fix(just): drop duplicate guix-shell recipe so the Justfile parses - #358

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/justfile-duplicate-guix-shell
Oct 7, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/justfile-duplicate-guix-shell

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

The Justfile on main does not parse, so no just recipe in this repo can run:

error: recipe `guix-shell` first defined on line 1055 is redefined on line 1063

The Nix eradication (593427b, 2026-08-23) turned the old nix-shell fallback into a second guix-shell recipe that tests for a nonexistent flake.guix. This PR deletes that dead duplicate and keeps the real recipe, guix shell -D -f build/guix.scm.

Changes

  • Justfile: removes the 4-line "fallback" guix-shell recipe (comment, header, body, blank line).

Type of change

Bug fix (build tooling).

📌 New pins

Head SHA: fcab795. No action, lockfile or container pins are added or changed.

RSR Quality Checklist

Required

  • Tests pass: just --list now parses and lists 107 recipes. On main it fails with the error above.
  • Code is formatted: the removal leaves the surrounding spacing intact.
  • Linter is clean: no new warnings.
  • No banned language patterns. Removing a dead guix develop/flake.guix reference is a step toward this.
  • No unsafe blocks. Not applicable.
  • No banned functions. Not applicable.
  • SPDX headers: unchanged.
  • No secrets.

As Applicable

  • .machine_readable/*. Not applicable.
  • Documentation. Not applicable: no recipe was documented as "fallback".
  • New dependencies. Not applicable.
  • ABI/FFI. Not applicable.

Testing

  • Control: just --justfile <main's Justfile> --list → error: recipe guix-shell … is redefined on line 1063.
  • After the change: just --list → rc 0, just --summary → 107 recipes.
  • No workflow runs just. The only just hit under .github/workflows is prose in a comment. So CI cannot have caught this, and it does not exercise the fix either.

Pre-existing red checks (deferred, not introduced here)

🤖 Generated with Claude Code

https://claude.ai/code/session_019j8She9eTFx54r6aL6sCHP

The Nix eradication (593427b) turned the old nix-shell fallback into a
second guix-shell recipe that tests for a nonexistent 'flake.guix'. just
rejects a redefined recipe, so no recipe in this Justfile could run.
Keep the real recipe (guix shell -D -f build/guix.scm).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019j8She9eTFx54r6aL6sCHP
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 7, 2026 11:37
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 31 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 70460ec4-4b97-43be-bc42-ff4f0cedc42e
📥 Commits

Reviewing files that changed from the base of the PR and between 4d77913 and fcab795.

📒 Files selected for processing (1)
  • Justfile
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 7dd5897 into main Oct 7, 2026
57 of 59 checks passed
@hyperpolymath
hyperpolymath deleted the fix/justfile-duplicate-guix-shell branch October 7, 2026 11:38
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 113 issues detected

Severity Count
🔴 Critical 10
🟠 High 18
🟡 Medium 85

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `sonarqube` in build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sonarqube"
  },
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "reason": "Job `deploy` in pages-deploy.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/pages-deploy.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "deploy"
  },
  {
    "reason": "Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.",
    "type": "secret_action_without_presence_gate",
    "file": ".github/workflows/instant-sync.yml",
    "action": "peter-evans/repository-dispatch",
    "rule_module": "workflow_audit",
    "severity": "high",
    "fix_recipe": "add_secret_presence_gate"
  },
  {
    "reason": "codeql.yml does not list `language: actions` in its matrix, but the repo has workflow files. CodeQL's `actions` language scans workflow YAML for injection and other CI/CD-specific weaknesses — every repo with workflows benefits. Add an entry to `matrix.include` with `language: actions` + `build-mode: none`.",
    "type": "codeql_missing_actions_language",
    "file": ".github/workflows/codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "fix_recipe": "add_codeql_actions_language"
  },
  {
    "line": 39,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 46,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 32,
    "reason": "job in .github/workflows/build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/build.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/container-publish.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/container-publish.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant