The hooks need no jq, and the prompt boundary retrieves against prompts #171

Merged
bvandeusen merged 4 commits from dev into main 2026-09-20 18:50:03 -04:00
Showing only changes of commit 7e653e16dc - Show all commits
+18 -8
View File
@@ -29,15 +29,25 @@ real Postgres), build (docker buildx).
Anything CI installs at job time that isn't in the image. Promotion
candidates if more than one project needs them.
- `jq` + `shellcheck` — apt-installed in the **plugin** job, which lints
the four Claude Code hook scripts and runs their fail-open smoke test.
Per `docs/process.md`'s decision checkpoint, single-consumer deps stay
- `shellcheck` — apt-installed in the **plugin** job, which lints the
Claude Code hook scripts and runs their fail-open smoke test. Per
`docs/process.md`'s decision checkpoint, single-consumer deps stay
per-job until a second consumer wants them; Scribe is the only one so
far. Both are small (jq ~1 MB, shellcheck ~20 MB) and would be
promotion candidates the moment another project lints shell.
**jq is load-bearing for the smoke test specifically**: every hook
starts with `command -v jq || exit 0`, so without it the test passes
while exercising nothing.
far. It is small (~20 MB) and would be a promotion candidate the moment
another project lints shell.
- `jq`**no longer installed anywhere, and should not be promoted.**
It was installed in two jobs, and this file used to record it as "load-
bearing for the smoke test specifically", because every hook opened
`command -v jq || exit 0` and the test would otherwise pass while
exercising nothing. That was the tail wagging the dog: the hooks ship to
users, jq is absent by default on macOS, the Debian/Ubuntu slim images,
Alpine and most CI containers, and a machine without it got no context,
no rules, no prior art and no process sync in silence. #4107 removed the
dependency rather than documenting it, so the smoke test now runs on a
bare image — which is the condition it was always meant to assert. The
hooks use only POSIX tools (awk, sed, tr, od, cut, head, tail, grep,
sort, date, printf) plus `git` and `curl`.
## Notes