The hooks need no jq, and the prompt boundary retrieves against prompts #171
+18
-8
@@ -29,15 +29,25 @@ real Postgres), build (docker buildx).
|
|||||||
Anything CI installs at job time that isn't in the image. Promotion
|
Anything CI installs at job time that isn't in the image. Promotion
|
||||||
candidates if more than one project needs them.
|
candidates if more than one project needs them.
|
||||||
|
|
||||||
- `jq` + `shellcheck` — apt-installed in the **plugin** job, which lints
|
- `shellcheck` — apt-installed in the **plugin** job, which lints the
|
||||||
the four Claude Code hook scripts and runs their fail-open smoke test.
|
Claude Code hook scripts and runs their fail-open smoke test. Per
|
||||||
Per `docs/process.md`'s decision checkpoint, single-consumer deps stay
|
`docs/process.md`'s decision checkpoint, single-consumer deps stay
|
||||||
per-job until a second consumer wants them; Scribe is the only one so
|
per-job until a second consumer wants them; Scribe is the only one so
|
||||||
far. Both are small (jq ~1 MB, shellcheck ~20 MB) and would be
|
far. It is small (~20 MB) and would be a promotion candidate the moment
|
||||||
promotion candidates the moment another project lints shell.
|
another project lints shell.
|
||||||
**jq is load-bearing for the smoke test specifically**: every hook
|
|
||||||
starts with `command -v jq || exit 0`, so without it the test passes
|
- `jq` — **no longer installed anywhere, and should not be promoted.**
|
||||||
while exercising nothing.
|
It was installed in two jobs, and this file used to record it as "load-
|
||||||
|
bearing for the smoke test specifically", because every hook opened
|
||||||
|
`command -v jq || exit 0` and the test would otherwise pass while
|
||||||
|
exercising nothing. That was the tail wagging the dog: the hooks ship to
|
||||||
|
users, jq is absent by default on macOS, the Debian/Ubuntu slim images,
|
||||||
|
Alpine and most CI containers, and a machine without it got no context,
|
||||||
|
no rules, no prior art and no process sync in silence. #4107 removed the
|
||||||
|
dependency rather than documenting it, so the smoke test now runs on a
|
||||||
|
bare image — which is the condition it was always meant to assert. The
|
||||||
|
hooks use only POSIX tools (awk, sed, tr, od, cut, head, tail, grep,
|
||||||
|
sort, date, printf) plus `git` and `curl`.
|
||||||
|
|
||||||
## Notes
|
## Notes
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user