feat(stagecraft): prepare for publication: explicit specifiers, JSDoc, dependency audit (swamp-club #2947) #440

Merged
seth merged 1 commit from cue/2947-stagecraft-prepare-publication into main 2026-10-02 15:52:28 +00:00
Owner

Prepares @swamp/stagecraft for publication (swamp-club #2947; also fixes #2850). This PR adds no manifest and publishes nothing. The manifest is on the branch cue/2947-stagecraft-manifest, on top of this commit, and merges with the publish (#2820). The hand-off is in #2820's thread.

Changes

  • Quality scoring. swamp extension quality refused to score stagecraft: the swamp-club backend imported @std/path by its import-map name. It now uses jsr:@std/path@1.1.4, and boundary_test.ts gains rule 6: production code names packages by npm: or jsr: specifier.
  • JSDoc on every exported symbol of the six model entry points and the report (24/24, from 7/23), for the registry's symbols-docs factor.
  • Dependency audit. scripts/audit_deps.ts scans stagecraft/ (#2850). Its first scan failed on two direct-dependency advisories, so preact goes to 10.27.3 (GHSA-36hm-qxxp-pg3m) and yaml to 2.8.3 (GHSA-48c2-rrv3-qjmp), with the studio page rebuilt.
  • The review prompts list stagecraft/.
  • The studio asset size test (already 800,000 bytes per generated module, under the registry's 976.6 KB limit) names the fix in its failure message. The app module is 751 KB after #2943's Board.
  • DESIGN.md records where the manifest is and why the studio page stays embedded rather than read through ctx.extensionFile(): an embedded page is served the same way from source, from an installed package and on a remote worker.

swamp's extension checks (run against the manifest branch)

  • swamp extension fmt --check: passes.
  • swamp extension quality: 12/12 client-earnable. repository-verified (0/2) is confirmed by the server on publish; the registry already verified this repository URL for software-factory.
  • swamp extension push --dry-run: builds a 1.3 MB archive. There's no upgrade warning: a first version needs no upgrade entries.
  • Blocker for #2820: on the real tree, both quality and push stop at swamp's eval safety check. It's a substring match that flags cel-js's .eval( interpreter method in the studio bundle, filed as swamp-club #2949. The results above come from a scratch copy with those calls rewritten, only to see what fails next. The token-count fields flagged as secrets are filed as #2952 (warning only).

Packaged install

The dry-run archive was installed into a fresh, isolated repo by reproducing swamp's pulled layout (swamp has no install-from-archive command). All six model types loaded. A factory from the skill's starter example validated, with all 4 saved scenarios passing. The studio served and rendered in headless Chromium. A built-in tracker ticket was created, claimed and driven to its first human stop (plan-review, awaiting plan-approval). The summary report ran, and the skill arrived in .claude/skills/stagecraft. Nothing only worked from source.

Found along the way: the registry renders the manifest description as an extension's readme, not README.md, so README links needed no change. additionalFiles refuses .png, so docs/studio.png doesn't ship.

Verification

Attestation 1586a277-0412-4fb5-9f68-22b919441979 for 51e817379c0807475982d1dfeb03013cdd0a09dc.

  • verify-build 53f58e3b-d3c4-40b2-a6a7-6be1bf8910a1: 13/14 passed, with the codegen idempotency step skipped because codegen is unchanged.
  • verify-reviews af6f804e-a5ca-4af6-b643-76769afb9248: ci-security-review, code-review and adversarial-review all pass. Two low findings, both gaps in rule 6 that nothing hits today: a literal bare dynamic import("…") isn't checked, and single-quoted specifiers aren't seen (deno fmt rewrites those to double quotes).

🤖 Generated with Claude Code

Prepares @swamp/stagecraft for publication (swamp-club #2947; also fixes #2850). **This PR adds no manifest and publishes nothing.** The manifest is on the branch `cue/2947-stagecraft-manifest`, on top of this commit, and merges with the publish (#2820). The hand-off is in #2820's thread. ## Changes - **Quality scoring.** `swamp extension quality` refused to score stagecraft: the swamp-club backend imported `@std/path` by its import-map name. It now uses `jsr:@std/path@1.1.4`, and `boundary_test.ts` gains rule 6: production code names packages by `npm:` or `jsr:` specifier. - **JSDoc** on every exported symbol of the six model entry points and the report (24/24, from 7/23), for the registry's symbols-docs factor. - **Dependency audit.** `scripts/audit_deps.ts` scans `stagecraft/` (#2850). Its first scan failed on two direct-dependency advisories, so preact goes to 10.27.3 (GHSA-36hm-qxxp-pg3m) and yaml to 2.8.3 (GHSA-48c2-rrv3-qjmp), with the studio page rebuilt. - The review prompts list `stagecraft/`. - The studio asset size test (already 800,000 bytes per generated module, under the registry's 976.6 KB limit) names the fix in its failure message. The app module is 751 KB after #2943's Board. - `DESIGN.md` records where the manifest is and why the studio page stays embedded rather than read through `ctx.extensionFile()`: an embedded page is served the same way from source, from an installed package and on a remote worker. ## swamp's extension checks (run against the manifest branch) - `swamp extension fmt --check`: passes. - `swamp extension quality`: **12/12** client-earnable. `repository-verified` (0/2) is confirmed by the server on publish; the registry already verified this repository URL for software-factory. - `swamp extension push --dry-run`: builds a 1.3 MB archive. There's no upgrade warning: a first version needs no upgrade entries. - **Blocker for #2820:** on the real tree, both `quality` and `push` stop at swamp's eval safety check. It's a substring match that flags cel-js's `.eval(` interpreter method in the studio bundle, filed as **swamp-club #2949**. The results above come from a scratch copy with those calls rewritten, only to see what fails next. The token-count fields flagged as secrets are filed as #2952 (warning only). ## Packaged install The dry-run archive was installed into a fresh, isolated repo by reproducing swamp's pulled layout (swamp has no install-from-archive command). All six model types loaded. A factory from the skill's `starter` example validated, with all 4 saved scenarios passing. The studio served and rendered in headless Chromium. A built-in tracker ticket was created, claimed and driven to its first human stop (plan-review, awaiting `plan-approval`). The summary report ran, and the skill arrived in `.claude/skills/stagecraft`. Nothing only worked from source. Found along the way: the registry renders the manifest **description** as an extension's readme, not README.md, so README links needed no change. `additionalFiles` refuses `.png`, so `docs/studio.png` doesn't ship. ## Verification Attestation `1586a277-0412-4fb5-9f68-22b919441979` for `51e817379c0807475982d1dfeb03013cdd0a09dc`. - verify-build `53f58e3b-d3c4-40b2-a6a7-6be1bf8910a1`: 13/14 passed, with the codegen idempotency step skipped because codegen is unchanged. - verify-reviews `af6f804e-a5ca-4af6-b643-76769afb9248`: ci-security-review, code-review and adversarial-review all pass. Two low findings, both gaps in rule 6 that nothing hits today: a literal bare dynamic `import("…")` isn't checked, and single-quoted specifiers aren't seen (`deno fmt` rewrites those to double quotes). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
feat(stagecraft): prepare for publication: explicit specifiers, JSDoc, dependency audit (swamp-club #2947)
All checks were successful
CI / Validate Attestation (pull_request) Successful in 1m1s
CI / Review Integrity (pull_request) Successful in 1m29s
51e817379c
Everything a published @swamp/stagecraft needs that can land on main
before the manifest does. The manifest itself stays on the branch
cue/2947-stagecraft-manifest until the publish (#2820), so nothing
publishes from this change.

- swamp extension quality refused to score the extension: the swamp-club
  backend imported @std/path by its import-map name. It now uses a jsr:
  specifier, and boundary_test gains rule 6, that production code names
  packages by npm: or jsr: specifier.
- JSDoc on the entry points' exported symbols, for the registry's
  symbols-docs factor (7 of 23 documented before, all 23 now).
- scripts/audit_deps.ts scans stagecraft/ (fixes swamp-club #2850). Its
  first scan found advisories against two direct dependencies, so preact
  goes to 10.27.3 (GHSA-36hm-qxxp-pg3m) and yaml to 2.8.3
  (GHSA-48c2-rrv3-qjmp), with the studio page rebuilt.
- The review prompts list stagecraft/ among the directories to review.
- The studio asset size test's message names the fix when a module
  outgrows its budget; DESIGN.md records where the manifest is and why
  the studio page stays embedded.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seth merged commit 824309c26f into main 2026-10-02 15:52:28 +00:00
seth deleted branch cue/2947-stagecraft-prepare-publication 2026-10-02 15:52:30 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
swamp-club/swamp-extensions!440
No description provided.