Skip to content

fix(rules): JS lockfile advice follows Bun-first runtime policy - #890

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/js-runtime-bun-advice
Sep 30, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
fix/js-runtime-bun-advice

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

lib/rules/root_hygiene.ex still told repos to "use Deno" and marked bun.lockb and pnpm-lock.yaml high / delete. That is the inverse of standards/docs/JS-RUNTIME-POLICY.adoc:

  • The runtime order is Bun > pnpm > npm.
  • Deno was banned on 2026-09-22 ("deno is over, we're prioritising bun, and using bunx").
  • Bun lockfiles are "permitted and expected".

A dispatch acting on the old rule would delete a tier-1 lockfile.

File Before After
bun.lock / bun.lockb high, delete ("Bun banned -- use Deno") not flagged
pnpm-lock.yaml high, delete low, flag (tier 2)
package-lock.json, yarn.lock, .npmrc banned, "use Deno" banned, "use Bun"
nodejs_detected reason "use Deno" "use Bun", cites the policy doc

npx_in_workflow already recommended bunx / bun run, so it needed no change.

Verification: mix test gives 1702 tests, 0 failures (242 :verisim_data excluded, as on main), and mix format --check-formatted is clean. There are new tests asserting that Bun lockfiles are never flagged and that pnpm is never a delete.

Not changed: test/fixtures/a2ml/rsr-criteria-v2.a2ml (5.1.6 "use Deno") mirrors the standards criteria SSOT. It should be fixed at the source, in standards.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65

root_hygiene still said "use Deno" for every banned lockfile and marked
bun.lockb (and pnpm-lock.yaml) high/delete, the inverse of standards
docs/JS-RUNTIME-POLICY.adoc: order Bun > pnpm > npm, Deno banned
2026-09-22, and bun.lock / bun.lockb "permitted and expected". A dispatch
acting on the old rule would delete a tier-1 runtime's lockfile.

- bun.lockb is no longer banned; bun.lock/bun.lockb are never flagged.
- pnpm-lock.yaml drops to a low-severity flag (tier 2, permitted where an
  upstream toolchain needs node_modules), never a delete.
- package-lock.json, yarn.lock, .npmrc stay banned; their remedy and the
  nodejs_detected reason now say Bun and cite the policy doc.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a60e2d40-e56c-4fa7-aaa8-a6d4ddfe374c

📥 Commits

Reviewing files that changed from the base of the PR and between 51bf019 and 28ab2e2.

📒 Files selected for processing (4)
  • lib/rules/cicd_rules.ex
  • lib/rules/root_hygiene.ex
  • test/root_hygiene_test.exs
  • test/rules/cicd_rules_rescript_npm_js_test.exs
 _______________________________________
< `NaN` is not a valid user experience. >
 ---------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • 🔴 Error committing to branch - (🔄 Check to retry)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) September 30, 2026 22:19
@hyperpolymath
hyperpolymath merged commit b329fd8 into main Sep 30, 2026
43 of 46 checks passed
@hyperpolymath
hyperpolymath deleted the fix/js-runtime-bun-advice branch September 30, 2026 22:21
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

❌ Failed to create Coding Agent finishing-touch task. Please try again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant