feat(stagecraft): prepare for publication: explicit specifiers, JSDoc, dependency audit (swamp-club #2947) #440
Loading…
Reference in a new issue
No description provided.
Delete branch "cue/2947-stagecraft-prepare-publication"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Prepares @swamp/stagecraft for publication (swamp-club #2947; also fixes #2850). This PR adds no manifest and publishes nothing. The manifest is on the branch
cue/2947-stagecraft-manifest, on top of this commit, and merges with the publish (#2820). The hand-off is in #2820's thread.Changes
swamp extension qualityrefused to score stagecraft: the swamp-club backend imported@std/pathby its import-map name. It now usesjsr:@std/path@1.1.4, andboundary_test.tsgains rule 6: production code names packages bynpm:orjsr:specifier.scripts/audit_deps.tsscansstagecraft/(#2850). Its first scan failed on two direct-dependency advisories, so preact goes to 10.27.3 (GHSA-36hm-qxxp-pg3m) and yaml to 2.8.3 (GHSA-48c2-rrv3-qjmp), with the studio page rebuilt.stagecraft/.DESIGN.mdrecords where the manifest is and why the studio page stays embedded rather than read throughctx.extensionFile(): an embedded page is served the same way from source, from an installed package and on a remote worker.swamp's extension checks (run against the manifest branch)
swamp extension fmt --check: passes.swamp extension quality: 12/12 client-earnable.repository-verified(0/2) is confirmed by the server on publish; the registry already verified this repository URL for software-factory.swamp extension push --dry-run: builds a 1.3 MB archive. There's no upgrade warning: a first version needs no upgrade entries.qualityandpushstop at swamp's eval safety check. It's a substring match that flags cel-js's.eval(interpreter method in the studio bundle, filed as swamp-club #2949. The results above come from a scratch copy with those calls rewritten, only to see what fails next. The token-count fields flagged as secrets are filed as #2952 (warning only).Packaged install
The dry-run archive was installed into a fresh, isolated repo by reproducing swamp's pulled layout (swamp has no install-from-archive command). All six model types loaded. A factory from the skill's
starterexample validated, with all 4 saved scenarios passing. The studio served and rendered in headless Chromium. A built-in tracker ticket was created, claimed and driven to its first human stop (plan-review, awaitingplan-approval). The summary report ran, and the skill arrived in.claude/skills/stagecraft. Nothing only worked from source.Found along the way: the registry renders the manifest description as an extension's readme, not README.md, so README links needed no change.
additionalFilesrefuses.png, sodocs/studio.pngdoesn't ship.Verification
Attestation
1586a277-0412-4fb5-9f68-22b919441979for51e817379c0807475982d1dfeb03013cdd0a09dc.53f58e3b-d3c4-40b2-a6a7-6be1bf8910a1: 13/14 passed, with the codegen idempotency step skipped because codegen is unchanged.af6f804e-a5ca-4af6-b643-76769afb9248: ci-security-review, code-review and adversarial-review all pass. Two low findings, both gaps in rule 6 that nothing hits today: a literal bare dynamicimport("…")isn't checked, and single-quoted specifiers aren't seen (deno fmtrewrites those to double quotes).🤖 Generated with Claude Code