Skip to content

chore: Use pnpm instead of npm and npx in the gate, hooks and Squad skill - #252

Merged
mpaulosky merged 5 commits into
mainfrom
chore/pnpm-only-baseline
Oct 5, 2026
Merged

mpaulosky merged 5 commits into
mainfrom
chore/pnpm-only-baseline

Conversation

@mpaulosky

Copy link
Copy Markdown
Owner

Requested by Matthew · project thread

Why

Before: if markdownlint-cli2 isn't installed and pnpm isn't on PATH, scripts/gate.sh still has an npx fallback for Markdown lint. The pre-commit hook still mentions npm install -g, and the Squad tailwind-migration skill tells agents to run npm and npx.

After: nothing uses npm or npx. Without markdownlint-cli2, the gate lints with pnpm dlx. If pnpm is missing too, the gate stops with "Markdown lint needs pnpm: corepack enable pnpm, or pnpm add -g markdownlint-cli2". The pre-commit hint now suggests only pnpm add -g markdownlint-cli2, and the skill uses pnpm.

What changed

  • The first commit is the output of the repo-ci-baseline Template's apply.sh after mpaulosky/dotfiles#66 (chore: apply repo-ci-baseline Template). It overwrites scripts/gate.sh, .github/hooks/pre-commit and .github/hooks/tests/pre-push.test.sh. The hook tests now stub pnpm and check that npx is never called.
  • The same Apply brings in two earlier Template changes this repo didn't have yet:
    • .github/hooks/pre-push refuses to push a branch that is behind origin/main, and docs/PROCESS.md documents this.
    • .github/scripts/release_post.py and its tests keep code exactly as written in release posts.
  • The Apply also writes the Seed file docs/SECURITY.md, which this repo didn't have.
  • The second commit changes the Squad skill .github/skills/tailwind-migration/SKILL.md from npm install, npx and npm run to pnpm install, pnpm dlx and pnpm run. A later squad upgrade may put the npm text back.

Verification

  • I ran scripts/gate.sh on this branch in a fresh worktree. Lint and the Release build passed, and so did six of the seven test projects: Api.Tests.Integration, Api.Tests.Unit, Architecture, Shared.Tests.Unit, Web.Tests.Bunit and Web.Tests.Unit.
  • AppHost.Tests.E2E failed locally, with 36 of 54 tests failing. Without the TEST_ENV secret, which only CI supplies, the web app throws "Auth0:Domain configuration is missing". This PR changes no test or source file.
  • The pushed commits are the ones I gated, and origin/main hadn't moved since.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LiSLjmGJYMzJUH9kM6FyaF


Generated by Claude Code

claude added 2 commits October 5, 2026 18:17
Brings in dotfiles#66: the gate lints Markdown with pnpm dlx and never npx,
and fails when pnpm is missing; the pre-commit hint names pnpm only. Also
carries the Template's earlier pre-push up-to-date check and release-post
code-span fixes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LiSLjmGJYMzJUH9kM6FyaF
The Squad-generated skills and Copilot MCP config ran npm and npx. They now
use pnpm install, pnpm run, pnpm dlx, pnpm view and pnpm publish. Mentions of
the npm registry itself stay. A later squad upgrade may restore the npm text.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LiSLjmGJYMzJUH9kM6FyaF
Copilot AI balanced review requested due to automatic review settings October 5, 2026 18:36
@mpaulosky mpaulosky self-assigned this Oct 5, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Sandcastle path bypasses the freshness check, and the migration skill invokes an isolated, potentially incompatible Tailwind CLI.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Standardizes pnpm usage while applying baseline hook, security-documentation, and release-post hardening updates.

Changes:

  • Replaces npm/npx fallbacks with pnpm commands.
  • Adds branch freshness enforcement and security documentation.
  • Hardens release-post Markdown processing with extensive tests.
File Description
scripts/​gate.sh Uses pnpm for Markdown lint fallback.
docs/​SECURITY.md Adds the security policy.
docs/​PROCESS.md Documents branch freshness checks.
.github/​skills/​tailwind-migration/​SKILL.md Converts Tailwind commands to pnpm.
.github/​scripts/​release_post.py Sanitizes generated release content.
.github/​scripts/​tests/​test_release_post.py Adds sanitizer and link-processing tests.
.github/​hooks/​tests/​pre-push.test.sh Tests pnpm and branch freshness behavior.
.github/​hooks/​pre-push Adds the origin/main freshness check.
.github/​hooks/​pre-commit Updates the Markdown lint installation hint.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/hooks/pre-push
Comment thread .github/skills/tailwind-migration/SKILL.md Outdated
npx used the tailwindcss installed on the line before; pnpm dlx would fetch
a separate, possibly newer release. pnpm exec keeps the old behaviour.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LiSLjmGJYMzJUH9kM6FyaF
Copilot AI balanced review requested due to automatic review settings October 5, 2026 18:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Fence detection incorrectly treats non-ASCII whitespace as a valid closer, causing code content to be lost or reclassified.

Review effort: Balanced
Findings: None

Resolved since last review (2)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Reject non-ASCII whitespace after closing code fences

.github/​scripts/​release_post.py:462

closes_fence() uses info.strip(), so a closing fence followed by a non-breaking space is accepted even though CommonMark permits only ASCII spaces/tabs there. For example, sanitizing ```\na\n```<NBSP>\n<b> drops the apparent closer and moves/escapes <b> as prose instead of preserving both lines as code. Restrict the closer's trailing whitespace check to " \t" and add this case to the code-preservation tests.

Copilot AI balanced review requested due to automatic review settings October 5, 2026 18:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Both documentation changes are consistent, valid, and introduce no unresolved functional issues.

Review effort: Balanced
Findings: None

@github-actions github-actions Bot added the docs-only Changes only docs; CI skips the build and tests label Oct 5, 2026
Copilot AI balanced review requested due to automatic review settings October 5, 2026 19:06
@mpaulosky
mpaulosky enabled auto-merge (squash) October 5, 2026 19:06
@mpaulosky
mpaulosky merged commit ed0ed97 into main Oct 5, 2026
20 checks passed
@mpaulosky
mpaulosky deleted the chore/pnpm-only-baseline branch October 5, 2026 19:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The PR metadata claims absent changes, and the security document violates the numbered-list convention.

Review effort: Balanced
Findings: 2 Low severity

Open (2)

Comment on lines +65 to +66
pnpm install
pnpm exec tailwindcss init
Comment thread docs/SECURITY.md
Comment on lines +18 to +21
1. A description of the vulnerability and its impact
2. Steps to reproduce it
3. The affected release or commit
4. A suggested fix, if you have one
mpaulosky added a commit that referenced this pull request Oct 5, 2026
Automated release blog posts for #252, opened by the release workflow.
It holds every Release whose post isn't on main yet, rebuilt from main
on each run. The [skip-release] title marker keeps its merge from
starting another release.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs-only Changes only docs; CI skips the build and tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants