-
-
Notifications
You must be signed in to change notification settings - Fork 0
policy: Bun is tier 1, Deno is being removed — correct local CLAUDE.md #50
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
c2aaa14
db7f1ab
3f54c9d
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -11,13 +11,13 @@ Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk> | |||||||||||||||
| | Language/Tool | Use Case | Notes | | ||||||||||||||||
| |---------------|----------|-------| | ||||||||||||||||
| | **AffineScript** | Primary application code | Compiles to JS, type-safe | | ||||||||||||||||
| | **Deno** | Runtime & package management | Replaces Node/npm/bun | | ||||||||||||||||
| | **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | ||||||||||||||||
| | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | ||||||||||||||||
| | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | ||||||||||||||||
| | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | ||||||||||||||||
| | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | ||||||||||||||||
| | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | | ||||||||||||||||
| | **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | | ||||||||||||||||
| | **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | ||||||||||||||||
| | **Python** | SaltStack only | No other Python permitted | | ||||||||||||||||
| | **Nickel** | Configuration language | For complex configs | | ||||||||||||||||
| | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | ||||||||||||||||
|
|
@@ -30,10 +30,11 @@ Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk> | |||||||||||||||
| | Banned | Replacement | | ||||||||||||||||
| |--------|-------------| | ||||||||||||||||
| | TypeScript | AffineScript | | ||||||||||||||||
| | Node.js | Deno | | ||||||||||||||||
| | npm | Deno | | ||||||||||||||||
| | Bun | Deno | | ||||||||||||||||
| | pnpm/yarn | Deno | | ||||||||||||||||
| | ReScript | AffineScript | | ||||||||||||||||
| | Deno | Bun | | ||||||||||||||||
| | Node.js | Bun | | ||||||||||||||||
| | npm | Bun | | ||||||||||||||||
| | pnpm/yarn | Bun | | ||||||||||||||||
|
Comment on lines
+35
to
+37
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟡 MEDIUM RISK Suggestion: Since Deno is being removed as the tier 1 runtime and was previously the preferred choice, it should be explicitly added to the 'Banned' table with Bun as the replacement. This ensures that AI agents (like Claude) understand it is no longer permitted.
Suggested change
|
||||||||||||||||
| | Go | Rust | | ||||||||||||||||
| | Python (general) | AffineScript/Rust | | ||||||||||||||||
| | Java/Kotlin | Rust/Tauri/Dioxus | | ||||||||||||||||
|
|
@@ -53,8 +54,8 @@ Both are FOSS with independent governance (no Big Tech). | |||||||||||||||
| ### Enforcement Rules | ||||||||||||||||
|
|
||||||||||||||||
| 1. **No new TypeScript files** - Convert existing TS to AffineScript | ||||||||||||||||
| 2. **No package.json - use deno.json deps** - Use deno.json imports | ||||||||||||||||
| 3. **No node_modules in production** - Deno caches deps automatically | ||||||||||||||||
| 2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED | ||||||||||||||||
| 3. **`bun install --production --frozen-lockfile` for production deps** - resolved from `package.json` and pinned via `bun.lock`; `--frozen-lockfile` makes a lockfile mismatch a build failure rather than a silent re-resolve | ||||||||||||||||
| 4. **No Go code** - Use Rust instead | ||||||||||||||||
| 5. **Python only for SaltStack** - All other Python must be rewritten | ||||||||||||||||
| 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus | ||||||||||||||||
|
|
@@ -63,7 +64,7 @@ Both are FOSS with independent governance (no Big Tech). | |||||||||||||||
|
|
||||||||||||||||
| - **Primary**: Guix (guix.scm) | ||||||||||||||||
| - **Fallback**: Nix (flake.nix) | ||||||||||||||||
| - **JS deps**: Deno (deno.json imports) | ||||||||||||||||
| - **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang. | ||||||||||||||||
|
|
||||||||||||||||
| ### Security Requirements | ||||||||||||||||
|
|
||||||||||||||||
|
|
||||||||||||||||
| Original file line number | Diff line number | Diff line change | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -24,13 +24,13 @@ The following files in `.machine_readable/` contain structured project metadata: | |||||||||||||||
| | Language/Tool | Use Case | Notes | | ||||||||||||||||
| |---------------|----------|-------| | ||||||||||||||||
| | **AffineScript** | Primary application code | Compiles to JS, type-safe | | ||||||||||||||||
| | **Deno** | Runtime & package management | Replaces Node/npm/bun | | ||||||||||||||||
| | **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | ||||||||||||||||
| | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | ||||||||||||||||
| | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | ||||||||||||||||
| | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | | ||||||||||||||||
| | **Gleam** | Backend services | Runs on BEAM or compiles to JS | | ||||||||||||||||
| | **Bash/POSIX Shell** | Scripts, automation | Keep minimal | | ||||||||||||||||
| | **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Deno APIs | | ||||||||||||||||
| | **JavaScript** | Only where AffineScript cannot | MCP protocol glue, Bun APIs | | ||||||||||||||||
| | **Nickel** | Configuration language | For complex configs | | ||||||||||||||||
| | **Guile Scheme** | State/meta files | STATE.scm, META.scm, ECOSYSTEM.scm | | ||||||||||||||||
| | **Julia** | Batch scripts, data processing | Per RSR | | ||||||||||||||||
|
|
@@ -42,10 +42,11 @@ The following files in `.machine_readable/` contain structured project metadata: | |||||||||||||||
| | Banned | Replacement | | ||||||||||||||||
| |--------|-------------| | ||||||||||||||||
| | TypeScript | AffineScript | | ||||||||||||||||
| | Node.js | Deno | | ||||||||||||||||
| | npm | Deno | | ||||||||||||||||
| | Bun | Deno | | ||||||||||||||||
| | pnpm/yarn | Deno | | ||||||||||||||||
| | ReScript | AffineScript | | ||||||||||||||||
| | Deno | Bun | | ||||||||||||||||
| | Node.js | Bun | | ||||||||||||||||
| | npm | Bun | | ||||||||||||||||
| | pnpm/yarn | Bun | | ||||||||||||||||
|
Comment on lines
+47
to
+49
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win Update the dependency-install task to use Bun. The changed policy bans Change the task to Suggested task update- npm install
+ bun installAlso applies to: 67-68 🤖 Prompt for AI Agents
Comment on lines
+47
to
+49
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟡 MEDIUM RISK Suggestion: To ensure policy consistency across the project, add Deno to the 'Banned' list here as well.
Suggested change
|
||||||||||||||||
| | Go | Rust | | ||||||||||||||||
| | Python | Julia/Rust/AffineScript | | ||||||||||||||||
| | Java/Kotlin | Rust/Tauri/Dioxus | | ||||||||||||||||
|
|
@@ -65,8 +66,8 @@ Both are FOSS with independent governance (no Big Tech). | |||||||||||||||
| ### Enforcement Rules | ||||||||||||||||
|
|
||||||||||||||||
| 1. **No new TypeScript files** - Convert existing TS to AffineScript | ||||||||||||||||
| 2. **No package.json - use deno.json deps** - Use deno.json imports | ||||||||||||||||
| 3. **No node_modules in production** - Deno caches deps automatically | ||||||||||||||||
| 2. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED | ||||||||||||||||
| 3. **`bun install --production --frozen-lockfile` for production deps** - resolved from `package.json` and pinned via `bun.lock`; `--frozen-lockfile` makes a lockfile mismatch a build failure rather than a silent re-resolve | ||||||||||||||||
| 4. **No Go code** - Use Rust instead | ||||||||||||||||
| 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps | ||||||||||||||||
| 6. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus | ||||||||||||||||
|
|
@@ -75,7 +76,7 @@ Both are FOSS with independent governance (no Big Tech). | |||||||||||||||
|
|
||||||||||||||||
| - **Primary**: Guix (guix.scm) | ||||||||||||||||
| - **Fallback**: Nix (flake.nix) | ||||||||||||||||
| - **JS deps**: Deno (deno.json imports) | ||||||||||||||||
| - **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun <tool>` — a bare `bunx <tool>` can fetch an unpinned package and may start Node via its shebang. | ||||||||||||||||
|
|
||||||||||||||||
| ### Security Requirements | ||||||||||||||||
|
|
||||||||||||||||
|
|
||||||||||||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Update the stale
rsr-buildmanifest check.This policy now tells agents that
package.jsonis expected, butfogbinder/Justfile, Lines 628-632 still treats anypackage.jsonas a build failure. A project that follows this Bun guidance cannot passrsr-build. Change that check to requirepackage.jsonandbun.lockinstead of rejectingpackage.json.🧰 Tools
🪛 LanguageTool
[misspelling] ~14-~14: Use “a” instead of ‘an’ if the following word doesn’t start with a vowel sound, e.g. ‘a sentence’, ‘a university’.
Context: ...ESM/JS directly — no bundler step. Uses an npm-compatible
package.jsonplus `bun...(EN_A_VS_AN)
[misspelling] ~14-~14: This word is normally spelled as one.
Context: ...lus
bun.lock— both are expected, not anti-patterns. | | Rust | Performance-critical, s...(EN_COMPOUNDS_ANTI_PATTERNS)
🤖 Prompt for AI Agents