From 2891c422ef460c82ab0732279a0965d7fecbacd0 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 26 Aug 2026 23:30:20 +0100 Subject: [PATCH 1/4] =?UTF-8?q?policy:=20Bun=20is=20tier=201,=20Deno=20is?= =?UTF-8?q?=20being=20removed=20=E2=80=94=20correct=20local=20CLAUDE.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Owner ruling 2026-08-26: "deno is to go and bun is the way we are going, put it first everywhere unless not possible and explain why if not". This file is what an agent reads FIRST and it listed Bun as BANNED with Deno as its replacement. Correcting hyperpolymath/standards (#655) fixes one copy of ~372 - agents read the local one. This is that local copy. ALLOWED **Deno** "Replaces Node/npm/bun" -> **Bun** tier 1 BANNED | Bun | Deno | -> row REMOVED BANNED Node.js / npm / pnpm/yarn -> Deno -> -> Bun rule "No package.json for runtime deps - use deno.json imports" -> Use package.json + bun.lock; a manifest is REQUIRED rule "No node_modules in production" -> bun install --production, pinned via bun.lock pkg JS deps: Deno -> JS deps: Bun (package.json + bun.lock), bunx WHY THE MANIFEST RULE MATTERS MOST. "No package.json for runtime deps" did not express a preference - it told repos not to declare their dependencies at all. hyperpolymath/ubicity imported zod and glob, shipped NO manifest of any kind, and could not build under ANY toolchain. Fixed in ubicity#107; the rule that caused it is fixed here. ALSO REPAIRED - blanking scars from the ReScript purge, which substituted the token with an EMPTY STRING rather than removing the text: | | AffineScript | -> | ReScript | AffineScript | 1. **No new files** ... -> **No new ReScript files** ... | **JavaScript** | Only where cannot | -> Only where AffineScript cannot Restoring the NAME in a policy table does not reintroduce the language. Same root cause as the rm -rf /lib found in wordpress-tools#62. Policy text only - no code, no workflows, no build files. 19 file(s). NOT FOLDED IN: "Fallback: Nix (flake.nix)" is stale (Guix superseded Nix per ADR-2026-STACK-MIGRATION) but that is a separate ruling; flagged, not changed. --- .claude/CLAUDE.md | 14 +++++++------- broad-spectrum/.claude/CLAUDE.md | 17 ++++++++--------- cicada/.claude/CLAUDE.md | 17 ++++++++--------- czech-file-knife/.claude/CLAUDE.md | 17 ++++++++--------- emergency-button/.claude/CLAUDE.md | 14 +++++++------- hybrid-automation-router/.claude/CLAUDE.md | 17 ++++++++--------- immutable-linux-auditor/.claude/CLAUDE.md | 17 ++++++++--------- monitoring/observatory/.claude/CLAUDE.md | 14 +++++++------- .../systems-observatory/.claude/CLAUDE.md | 17 ++++++++--------- nano-aider/.claude/CLAUDE.md | 17 ++++++++--------- nick-shells/.claude/CLAUDE.md | 17 ++++++++--------- observatory/.claude/CLAUDE.md | 14 +++++++------- panoptes/.claude/CLAUDE.md | 17 ++++++++--------- personal-sysadmin/.claude/CLAUDE.md | 14 +++++++------- recovery/emergency-room/.claude/CLAUDE.md | 14 +++++++------- recovery/operating-theatre/.claude/CLAUDE.md | 6 +++--- slopctl/.claude/CLAUDE.md | 17 ++++++++--------- total-recall/.claude/CLAUDE.md | 17 ++++++++--------- total-update/.claude/CLAUDE.md | 17 ++++++++--------- 19 files changed, 141 insertions(+), 153 deletions(-) diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index 21a20cf5..6af042dd 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -82,12 +82,12 @@ cargo build -p ambientops-clinician --all-features # Everything (slow) | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | .machine_readable/6a2/STATE.a2ml, .machine_readable/6a2/META.a2ml, .machine_readable/6a2/ECOSYSTEM.a2ml | | **Julia** | Batch scripts, data processing | Per RSR | @@ -102,8 +102,8 @@ cargo build -p ambientops-clinician --all-features # Everything (slow) | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | -| Node.js | Deno | Security-first runtime | -| npm/yarn/pnpm/bun | Deno | Deno manages deps | +| Node.js | Bun | Node-compatible; run the code, drop the runtime | +| npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | | **Python** | AffineScript/Rust/D/V | **Completely banned** (SaltStack abandoned) | | Java/Kotlin | Rust/Tauri | No JVM | @@ -127,8 +127,8 @@ Elixir is allowed **only for observability/event hubs**: ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Completely banned 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -137,7 +137,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/broad-spectrum/.claude/CLAUDE.md b/broad-spectrum/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/broad-spectrum/.claude/CLAUDE.md +++ b/broad-spectrum/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/cicada/.claude/CLAUDE.md b/cicada/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/cicada/.claude/CLAUDE.md +++ b/cicada/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/czech-file-knife/.claude/CLAUDE.md b/czech-file-knife/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/czech-file-knife/.claude/CLAUDE.md +++ b/czech-file-knife/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/emergency-button/.claude/CLAUDE.md b/emergency-button/.claude/CLAUDE.md index 2cd3009d..8110e346 100644 --- a/emergency-button/.claude/CLAUDE.md +++ b/emergency-button/.claude/CLAUDE.md @@ -29,12 +29,12 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -48,8 +48,8 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | -| Node.js | Deno | Security-first runtime | -| npm/yarn/pnpm/bun | Deno | Deno manages deps | +| Node.js | Bun | Node-compatible; run the code, drop the runtime | +| npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | | **Python** | AffineScript/Rust/D/V | **Completely banned** (SaltStack abandoned) | | Java/Kotlin | Rust/Tauri | No JVM | @@ -73,8 +73,8 @@ Elixir is allowed **only for observability/event hubs**: ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Completely banned 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -83,7 +83,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/hybrid-automation-router/.claude/CLAUDE.md b/hybrid-automation-router/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/hybrid-automation-router/.claude/CLAUDE.md +++ b/hybrid-automation-router/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/immutable-linux-auditor/.claude/CLAUDE.md b/immutable-linux-auditor/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/immutable-linux-auditor/.claude/CLAUDE.md +++ b/immutable-linux-auditor/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/monitoring/observatory/.claude/CLAUDE.md b/monitoring/observatory/.claude/CLAUDE.md index 2cd3009d..8110e346 100644 --- a/monitoring/observatory/.claude/CLAUDE.md +++ b/monitoring/observatory/.claude/CLAUDE.md @@ -29,12 +29,12 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -48,8 +48,8 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | -| Node.js | Deno | Security-first runtime | -| npm/yarn/pnpm/bun | Deno | Deno manages deps | +| Node.js | Bun | Node-compatible; run the code, drop the runtime | +| npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | | **Python** | AffineScript/Rust/D/V | **Completely banned** (SaltStack abandoned) | | Java/Kotlin | Rust/Tauri | No JVM | @@ -73,8 +73,8 @@ Elixir is allowed **only for observability/event hubs**: ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Completely banned 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -83,7 +83,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/monitoring/systems-observatory/.claude/CLAUDE.md b/monitoring/systems-observatory/.claude/CLAUDE.md index 40f3a7f4..8bb06ffb 100644 --- a/monitoring/systems-observatory/.claude/CLAUDE.md +++ b/monitoring/systems-observatory/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Python** | SaltStack only | No other Python permitted | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | @@ -39,10 +39,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python (general) | AffineScript/Rust | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -62,8 +61,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **Python only for SaltStack** - All other Python must be rewritten 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -72,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/nano-aider/.claude/CLAUDE.md b/nano-aider/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/nano-aider/.claude/CLAUDE.md +++ b/nano-aider/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/nick-shells/.claude/CLAUDE.md b/nick-shells/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/nick-shells/.claude/CLAUDE.md +++ b/nick-shells/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/observatory/.claude/CLAUDE.md b/observatory/.claude/CLAUDE.md index 2cd3009d..8110e346 100644 --- a/observatory/.claude/CLAUDE.md +++ b/observatory/.claude/CLAUDE.md @@ -29,12 +29,12 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -48,8 +48,8 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | -| Node.js | Deno | Security-first runtime | -| npm/yarn/pnpm/bun | Deno | Deno manages deps | +| Node.js | Bun | Node-compatible; run the code, drop the runtime | +| npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | | **Python** | AffineScript/Rust/D/V | **Completely banned** (SaltStack abandoned) | | Java/Kotlin | Rust/Tauri | No JVM | @@ -73,8 +73,8 @@ Elixir is allowed **only for observability/event hubs**: ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Completely banned 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -83,7 +83,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/panoptes/.claude/CLAUDE.md b/panoptes/.claude/CLAUDE.md index 0b98589e..cf102e3f 100644 --- a/panoptes/.claude/CLAUDE.md +++ b/panoptes/.claude/CLAUDE.md @@ -7,13 +7,13 @@ | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Python** | SaltStack only | No other Python permitted | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | @@ -26,10 +26,9 @@ | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python (general) | AffineScript/Rust | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -49,8 +48,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **Python only for SaltStack** - All other Python must be rewritten 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -59,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/personal-sysadmin/.claude/CLAUDE.md b/personal-sysadmin/.claude/CLAUDE.md index 2cd3009d..8110e346 100644 --- a/personal-sysadmin/.claude/CLAUDE.md +++ b/personal-sysadmin/.claude/CLAUDE.md @@ -29,12 +29,12 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -48,8 +48,8 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | -| Node.js | Deno | Security-first runtime | -| npm/yarn/pnpm/bun | Deno | Deno manages deps | +| Node.js | Bun | Node-compatible; run the code, drop the runtime | +| npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | | **Python** | AffineScript/Rust/D/V | **Completely banned** (SaltStack abandoned) | | Java/Kotlin | Rust/Tauri | No JVM | @@ -73,8 +73,8 @@ Elixir is allowed **only for observability/event hubs**: ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Completely banned 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -83,7 +83,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/recovery/emergency-room/.claude/CLAUDE.md b/recovery/emergency-room/.claude/CLAUDE.md index 2cd3009d..8110e346 100644 --- a/recovery/emergency-room/.claude/CLAUDE.md +++ b/recovery/emergency-room/.claude/CLAUDE.md @@ -29,12 +29,12 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -48,8 +48,8 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | -| Node.js | Deno | Security-first runtime | -| npm/yarn/pnpm/bun | Deno | Deno manages deps | +| Node.js | Bun | Node-compatible; run the code, drop the runtime | +| npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | | **Python** | AffineScript/Rust/D/V | **Completely banned** (SaltStack abandoned) | | Java/Kotlin | Rust/Tauri | No JVM | @@ -73,8 +73,8 @@ Elixir is allowed **only for observability/event hubs**: ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Completely banned 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -83,7 +83,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/recovery/operating-theatre/.claude/CLAUDE.md b/recovery/operating-theatre/.claude/CLAUDE.md index b44752bb..e99c6d84 100644 --- a/recovery/operating-theatre/.claude/CLAUDE.md +++ b/recovery/operating-theatre/.claude/CLAUDE.md @@ -75,8 +75,8 @@ Elixir is allowed **only for observability/event hubs**: ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Completely banned 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -85,7 +85,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/slopctl/.claude/CLAUDE.md b/slopctl/.claude/CLAUDE.md index bcc05102..d23bc88d 100644 --- a/slopctl/.claude/CLAUDE.md +++ b/slopctl/.claude/CLAUDE.md @@ -7,13 +7,13 @@ | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -25,10 +25,9 @@ | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -48,8 +47,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -58,7 +57,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/total-recall/.claude/CLAUDE.md b/total-recall/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/total-recall/.claude/CLAUDE.md +++ b/total-recall/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements diff --git a/total-update/.claude/CLAUDE.md b/total-update/.claude/CLAUDE.md index d154e65b..385ef2cd 100644 --- a/total-update/.claude/CLAUDE.md +++ b/total-update/.claude/CLAUDE.md @@ -20,13 +20,13 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | -| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | +| **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | **Nickel** | Configuration language | For complex configs | | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | **Julia** | Batch scripts, data processing | Per RSR | @@ -38,10 +38,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | @@ -61,8 +60,8 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports -3. **No node_modules in production** - Deno caches deps automatically +2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus @@ -71,7 +70,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements From 5ab24d8da7e018915133f4845a63921221f3da26 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 27 Aug 2026 00:20:16 +0100 Subject: [PATCH 2/4] =?UTF-8?q?policy:=20address=20review=20=E2=80=94=20dr?= =?UTF-8?q?op=20the=20.ts=20contradiction,=20ban=20Deno,=20pin=20bunx?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review feedback from codacy-production and coderabbitai on the policy wave. Three substantive points, all accepted: 1. ".ts CONTRADICTION" (codacy, MEDIUM, raised on most of the wave). The Bun row said "Executes .ts directly, no build step" in a file whose BANNED table bans TypeScript. OWNER RULING: TypeScript "should not exist at all", so advertising Bun's TypeScript capability is wrong regardless of whether it is true. Every .ts reference is removed from the row, including "JS/TS" in its label. 2. "DENO MISSING FROM BANNED" (codacy, raised repeatedly). The wave removed Deno from ALLOWED but never added it to BANNED, so the ruling was only half expressed. Added | Deno | Bun |. 3. "UNPINNED bunx" (coderabbitai, Security & Privacy). A bare `bunx ` can fetch a package outside package.json/bun.lock, and can start Node via a shebang - both contrary to estate SHA-pinning doctrine and the Node ban. Guidance now requires a declared devDependency plus `bunx --no-install --bun `. NOT taken: "a npm-compatible" (LanguageTool is wrong, "an" is correct before a vowel sound); "--frozen-lockfile is redundant" (correct - no change needed, and none made); the Nix->Guix point (real, but a separate ruling, deliberately not folded into a Deno/Bun change). --- .claude/CLAUDE.md | 5 +++-- broad-spectrum/.claude/CLAUDE.md | 5 +++-- cicada/.claude/CLAUDE.md | 5 +++-- czech-file-knife/.claude/CLAUDE.md | 5 +++-- emergency-button/.claude/CLAUDE.md | 5 +++-- hybrid-automation-router/.claude/CLAUDE.md | 5 +++-- immutable-linux-auditor/.claude/CLAUDE.md | 5 +++-- monitoring/observatory/.claude/CLAUDE.md | 5 +++-- monitoring/systems-observatory/.claude/CLAUDE.md | 5 +++-- nano-aider/.claude/CLAUDE.md | 5 +++-- nick-shells/.claude/CLAUDE.md | 5 +++-- observatory/.claude/CLAUDE.md | 5 +++-- panoptes/.claude/CLAUDE.md | 5 +++-- personal-sysadmin/.claude/CLAUDE.md | 5 +++-- recovery/emergency-room/.claude/CLAUDE.md | 5 +++-- recovery/operating-theatre/.claude/CLAUDE.md | 2 +- slopctl/.claude/CLAUDE.md | 5 +++-- total-recall/.claude/CLAUDE.md | 5 +++-- total-update/.claude/CLAUDE.md | 5 +++-- 19 files changed, 55 insertions(+), 37 deletions(-) diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index 6af042dd..abbd775b 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -82,7 +82,7 @@ cargo build -p ambientops-clinician --all-features # Everything (slow) | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | @@ -102,6 +102,7 @@ cargo build -p ambientops-clinician --all-features # Everything (slow) | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | +| Deno | Bun | Being removed per the 2026-08-26 ruling; migrate, or document why not | | Node.js | Bun | Node-compatible; run the code, drop the runtime | | npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | @@ -137,7 +138,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/broad-spectrum/.claude/CLAUDE.md b/broad-spectrum/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/broad-spectrum/.claude/CLAUDE.md +++ b/broad-spectrum/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/cicada/.claude/CLAUDE.md b/cicada/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/cicada/.claude/CLAUDE.md +++ b/cicada/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/czech-file-knife/.claude/CLAUDE.md b/czech-file-knife/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/czech-file-knife/.claude/CLAUDE.md +++ b/czech-file-knife/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/emergency-button/.claude/CLAUDE.md b/emergency-button/.claude/CLAUDE.md index 8110e346..f01c015e 100644 --- a/emergency-button/.claude/CLAUDE.md +++ b/emergency-button/.claude/CLAUDE.md @@ -29,7 +29,7 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | @@ -48,6 +48,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | +| Deno | Bun | Being removed per the 2026-08-26 ruling; migrate, or document why not | | Node.js | Bun | Node-compatible; run the code, drop the runtime | | npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | @@ -83,7 +84,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/hybrid-automation-router/.claude/CLAUDE.md b/hybrid-automation-router/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/hybrid-automation-router/.claude/CLAUDE.md +++ b/hybrid-automation-router/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/immutable-linux-auditor/.claude/CLAUDE.md b/immutable-linux-auditor/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/immutable-linux-auditor/.claude/CLAUDE.md +++ b/immutable-linux-auditor/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/monitoring/observatory/.claude/CLAUDE.md b/monitoring/observatory/.claude/CLAUDE.md index 8110e346..f01c015e 100644 --- a/monitoring/observatory/.claude/CLAUDE.md +++ b/monitoring/observatory/.claude/CLAUDE.md @@ -29,7 +29,7 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | @@ -48,6 +48,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | +| Deno | Bun | Being removed per the 2026-08-26 ruling; migrate, or document why not | | Node.js | Bun | Node-compatible; run the code, drop the runtime | | npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | @@ -83,7 +84,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/monitoring/systems-observatory/.claude/CLAUDE.md b/monitoring/systems-observatory/.claude/CLAUDE.md index 8bb06ffb..8a061d6a 100644 --- a/monitoring/systems-observatory/.claude/CLAUDE.md +++ b/monitoring/systems-observatory/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -39,6 +39,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -71,7 +72,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/nano-aider/.claude/CLAUDE.md b/nano-aider/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/nano-aider/.claude/CLAUDE.md +++ b/nano-aider/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/nick-shells/.claude/CLAUDE.md b/nick-shells/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/nick-shells/.claude/CLAUDE.md +++ b/nick-shells/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/observatory/.claude/CLAUDE.md b/observatory/.claude/CLAUDE.md index 8110e346..f01c015e 100644 --- a/observatory/.claude/CLAUDE.md +++ b/observatory/.claude/CLAUDE.md @@ -29,7 +29,7 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | @@ -48,6 +48,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | +| Deno | Bun | Being removed per the 2026-08-26 ruling; migrate, or document why not | | Node.js | Bun | Node-compatible; run the code, drop the runtime | | npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | @@ -83,7 +84,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/panoptes/.claude/CLAUDE.md b/panoptes/.claude/CLAUDE.md index cf102e3f..6387ec6f 100644 --- a/panoptes/.claude/CLAUDE.md +++ b/panoptes/.claude/CLAUDE.md @@ -7,7 +7,7 @@ | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -26,6 +26,7 @@ | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -58,7 +59,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/personal-sysadmin/.claude/CLAUDE.md b/personal-sysadmin/.claude/CLAUDE.md index 8110e346..f01c015e 100644 --- a/personal-sysadmin/.claude/CLAUDE.md +++ b/personal-sysadmin/.claude/CLAUDE.md @@ -29,7 +29,7 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | @@ -48,6 +48,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | +| Deno | Bun | Being removed per the 2026-08-26 ruling; migrate, or document why not | | Node.js | Bun | Node-compatible; run the code, drop the runtime | | npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | @@ -83,7 +84,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/recovery/emergency-room/.claude/CLAUDE.md b/recovery/emergency-room/.claude/CLAUDE.md index 8110e346..f01c015e 100644 --- a/recovery/emergency-room/.claude/CLAUDE.md +++ b/recovery/emergency-room/.claude/CLAUDE.md @@ -29,7 +29,7 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | @@ -48,6 +48,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | +| Deno | Bun | Being removed per the 2026-08-26 ruling; migrate, or document why not | | Node.js | Bun | Node-compatible; run the code, drop the runtime | | npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | @@ -83,7 +84,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/recovery/operating-theatre/.claude/CLAUDE.md b/recovery/operating-theatre/.claude/CLAUDE.md index e99c6d84..16475bfb 100644 --- a/recovery/operating-theatre/.claude/CLAUDE.md +++ b/recovery/operating-theatre/.claude/CLAUDE.md @@ -85,7 +85,7 @@ Elixir is allowed **only for observability/event hubs**: - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/slopctl/.claude/CLAUDE.md b/slopctl/.claude/CLAUDE.md index d23bc88d..d10c7f67 100644 --- a/slopctl/.claude/CLAUDE.md +++ b/slopctl/.claude/CLAUDE.md @@ -7,7 +7,7 @@ | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -25,6 +25,7 @@ | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -57,7 +58,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/total-recall/.claude/CLAUDE.md b/total-recall/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/total-recall/.claude/CLAUDE.md +++ b/total-recall/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements diff --git a/total-update/.claude/CLAUDE.md b/total-update/.claude/CLAUDE.md index 385ef2cd..467ab4c7 100644 --- a/total-update/.claude/CLAUDE.md +++ b/total-update/.claude/CLAUDE.md @@ -20,7 +20,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** | Primary application code | Compiles to JS, type-safe | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -38,6 +38,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | AffineScript | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -70,7 +71,7 @@ Both are FOSS with independent governance (no Big Tech). - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements From c26946302bfc1a5f5d3b957aff702056ddab173b Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 27 Aug 2026 04:40:32 +0100 Subject: [PATCH 3/4] docs(policy): ban ReScript explicitly and pin production installs Addresses the two live static-analysis findings on this PR. ReScript was absent from the BANNED table although canon bans it (destination AffineScript), so the table read as permitting it. Enforcement Rule 3 said `bun install --production` with no `--frozen-lockfile`, so a lockfile mismatch silently re-resolved instead of failing, which defeats the point of committing `bun.lock`. Enforcement Rule 1 is deliberately untouched: standards#655 records that collision as not resolvable unilaterally. Co-Authored-By: Claude Opus 5 --- .claude/CLAUDE.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index abbd775b..8c3dcebf 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -102,6 +102,7 @@ cargo build -p ambientops-clinician --all-features # Everything (slow) | Banned | Replacement | Reason | |--------|-------------|--------| | TypeScript | AffineScript | Type safety without JS baggage | +| ReScript | AffineScript | Type safety without JS baggage | | Deno | Bun | Being removed per the 2026-08-26 ruling; migrate, or document why not | | Node.js | Bun | Node-compatible; run the code, drop the runtime | | npm/yarn/pnpm | Bun | Bun manages deps | @@ -129,7 +130,7 @@ Elixir is allowed **only for observability/event hubs**: 1. **No new TypeScript files** - Convert existing TS to AffineScript 2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED -3. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` +3. **`bun install --production --frozen-lockfile` for production deps** - resolved from `package.json` and pinned via `bun.lock`; `--frozen-lockfile` makes a lockfile mismatch a build failure rather than a silent re-resolve 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Completely banned 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus From 4ecd7ac90f5ce7a1c5835b82990d7202b452ba6e Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 27 Aug 2026 05:20:58 +0100 Subject: [PATCH 4/4] =?UTF-8?q?policy:=20address=20review=20=E2=80=94=20dr?= =?UTF-8?q?op=20the=20.ts=20contradiction,=20ban=20Deno,=20pin=20bunx?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review feedback from codacy-production and coderabbitai on the policy wave. Three substantive points, all accepted: 1. ".ts CONTRADICTION" (codacy, MEDIUM, raised on most of the wave). The Bun row said "Executes .ts directly, no build step" in a file whose BANNED table bans TypeScript. OWNER RULING: TypeScript "should not exist at all", so advertising Bun's TypeScript capability is wrong regardless of whether it is true. Every .ts reference is removed from the row, including "JS/TS" in its label. 2. "DENO MISSING FROM BANNED" (codacy, raised repeatedly). The wave removed Deno from ALLOWED but never added it to BANNED, so the ruling was only half expressed. Added | Deno | Bun |. 3. "UNPINNED bunx" (coderabbitai, Security & Privacy). A bare `bunx ` can fetch a package outside package.json/bun.lock, and can start Node via a shebang - both contrary to estate SHA-pinning doctrine and the Node ban. Guidance now requires a declared devDependency plus `bunx --no-install --bun `. NOT taken: "a npm-compatible" (LanguageTool is wrong, "an" is correct before a vowel sound); "--frozen-lockfile is redundant" (correct - no change needed, and none made); the Nix->Guix point (real, but a separate ruling, deliberately not folded into a Deno/Bun change). --- recovery/operating-theatre/.claude/CLAUDE.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/recovery/operating-theatre/.claude/CLAUDE.md b/recovery/operating-theatre/.claude/CLAUDE.md index 16475bfb..f9d39640 100644 --- a/recovery/operating-theatre/.claude/CLAUDE.md +++ b/recovery/operating-theatre/.claude/CLAUDE.md @@ -29,7 +29,7 @@ The following files in `.machine_readable/` contain structured project metadata: | **D** | Driver/deployment layer | Adapters, execution, IO boundaries | | **V** | Verification layer | Policy, plan verification, schema conformance | | **AffineScript** | Primary application code | Compiles to JS, type-safe; AmbientOps primary | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS runtime & package management (tier 1) | Runs compiled ESM/JS; package.json + bun.lock | | **Rust** | Agent/verify boxes only | Isolated repos (`*-agent-rs/`, `*-verify-rs/`) | | **Elixir** | Observability/event hub only | NEVER source of truth | | **Gleam** | Backend services | Runs on BEAM or compiles to JS | @@ -48,8 +48,9 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | Reason | | ----------------- | ----------------- | ------------------------------------------- | | TypeScript | AffineScript | Type safety without JS baggage | -| Node.js | Deno | Security-first runtime | -| npm/yarn/pnpm/bun | Deno | Deno manages deps | +| Deno | Bun | Being removed per the 2026-08-26 ruling | +| Node.js | Bun | Node-compatible; run the code, drop runtime | +| npm/yarn/pnpm | Bun | Bun manages deps | | Go | Rust | Memory safety without GC | | **Python** | AffineScript/Rust/D/V | **Completely banned** (SaltStack abandoned) | | Java/Kotlin | Rust/Tauri | No JVM |