From 2bbcdeb5245bdc07a9c1b9100efa7a1d12d17825 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 26 Aug 2026 23:47:58 +0100 Subject: [PATCH 1/3] =?UTF-8?q?policy:=20Bun=20is=20tier=201,=20Deno=20is?= =?UTF-8?q?=20being=20removed=20=E2=80=94=20correct=20local=20CLAUDE.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Owner ruling 2026-08-26: "deno is to go and bun is the way we are going, put it first everywhere unless not possible and explain why if not". This file is what an agent reads FIRST and it listed Bun as BANNED with Deno as its replacement. Correcting hyperpolymath/standards (#655) fixes one copy of ~372 - agents read the local one. This is that local copy. ALLOWED **Deno** "Replaces Node/npm/bun" -> **Bun** tier 1 BANNED | Bun | Deno | -> row REMOVED BANNED Node.js / npm / pnpm/yarn -> Deno -> -> Bun rule "No package.json for runtime deps - use deno.json imports" -> Use package.json + bun.lock; a manifest is REQUIRED rule "No node_modules in production" -> bun install --production, pinned via bun.lock pkg JS deps: Deno -> JS deps: Bun (package.json + bun.lock), bunx WHY THE MANIFEST RULE MATTERS MOST. "No package.json for runtime deps" did not express a preference - it told repos not to declare their dependencies at all. hyperpolymath/ubicity imported zod and glob, shipped NO manifest of any kind, and could not build under ANY toolchain. Fixed in ubicity#107; the rule that caused it is fixed here. ALSO REPAIRED - blanking scars from the ReScript purge, which substituted the token with an EMPTY STRING rather than removing the text: | | AffineScript | -> | ReScript | AffineScript | 1. **No new files** ... -> **No new ReScript files** ... | **JavaScript** | Only where cannot | -> Only where AffineScript cannot Restoring the NAME in a policy table does not reintroduce the language. Same root cause as the rm -rf /lib found in wordpress-tools#62. Policy text only - no code, no workflows, no build files. 1 file(s). NOT FOLDED IN: "Fallback: Nix (flake.nix)" is stale (Guix superseded Nix per ADR-2026-STACK-MIGRATION) but that is a separate ruling; flagged, not changed. --- .claude/CLAUDE.md | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index 5480c191..ddc1ad67 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -49,7 +49,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** (`.affine`) | Primary application code | Affine types, dependent types, row polymorphism, extensible effects; compiles to Wasm | -| **Deno** | Runtime & package management | Replaces Node/npm/bun | +| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -76,10 +76,9 @@ The following files in `.machine_readable/` contain structured project metadata: | TypeScript | **AffineScript** | | (new files) | **AffineScript** (migration via #488) | | JavaScript (where the project has been meaningfully migrated to AffineScript) | **AffineScript** | -| Node.js | Deno | -| npm | Deno | -| Bun | Deno | -| pnpm/yarn | Deno | +| Node.js | Bun | +| npm | Bun | +| pnpm/yarn | Bun | | Go | Rust | | Python (general) | **AffineScript** / Rust / Julia | | Java/Kotlin | Rust / Tauri / Dioxus | @@ -102,9 +101,9 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Write new code in AffineScript (closed exemptions table below covers the residual `.d.ts` / Deno-test cases). -2. **No new files** - As of 2026-05-25 policy refresh; AffineScript is the go-forward. Existing `.res` files stay until migrated via #488. -3. **No package.json for runtime deps** - Use deno.json imports. -4. **No node_modules in production** - Deno caches deps automatically. +2. **No new ReScript files** - As of 2026-05-25 policy refresh; AffineScript is the go-forward. Existing `.res` files stay until migrated via #488. +3. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED +4. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` 5. **No Go code** - Use Rust instead. 6. **Python only for SaltStack** - All other Python must be rewritten. 7. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus. @@ -164,7 +163,7 @@ Do not "migrate", rewrite, or delete `formal/*.v` as if it were V-lang. - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Deno (deno.json imports) +- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling ### Security Requirements From 5d9e0faa61d7c09d59bc71114af977312a1fd47b Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 27 Aug 2026 00:19:55 +0100 Subject: [PATCH 2/3] =?UTF-8?q?policy:=20address=20review=20=E2=80=94=20dr?= =?UTF-8?q?op=20the=20.ts=20contradiction,=20ban=20Deno,=20pin=20bunx?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review feedback from codacy-production and coderabbitai on the policy wave. Three substantive points, all accepted: 1. ".ts CONTRADICTION" (codacy, MEDIUM, raised on most of the wave). The Bun row said "Executes .ts directly, no build step" in a file whose BANNED table bans TypeScript. OWNER RULING: TypeScript "should not exist at all", so advertising Bun's TypeScript capability is wrong regardless of whether it is true. Every .ts reference is removed from the row, including "JS/TS" in its label. 2. "DENO MISSING FROM BANNED" (codacy, raised repeatedly). The wave removed Deno from ALLOWED but never added it to BANNED, so the ruling was only half expressed. Added | Deno | Bun |. 3. "UNPINNED bunx" (coderabbitai, Security & Privacy). A bare `bunx ` can fetch a package outside package.json/bun.lock, and can start Node via a shebang - both contrary to estate SHA-pinning doctrine and the Node ban. Guidance now requires a declared devDependency plus `bunx --no-install --bun `. NOT taken: "a npm-compatible" (LanguageTool is wrong, "an" is correct before a vowel sound); "--frozen-lockfile is redundant" (correct - no change needed, and none made); the Nix->Guix point (real, but a separate ruling, deliberately not folded into a Deno/Bun change). --- .claude/CLAUDE.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index ddc1ad67..32848441 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -49,7 +49,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Language/Tool | Use Case | Notes | |---------------|----------|-------| | **AffineScript** (`.affine`) | Primary application code | Affine types, dependent types, row polymorphism, extensible effects; compiles to Wasm | -| **Bun** | JS/TS runtime & package management (tier 1) | Default for all new work. Executes `.ts` directly, no build step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | +| **Bun** | JS runtime & package management (tier 1) | Default for all new work. Runs compiled ESM/JS directly — no bundler step. Uses an npm-compatible `package.json` plus `bun.lock` — both are expected, not anti-patterns. | | **Rust** | Performance-critical, systems, WASM | Preferred for CLI tools | | **Tauri 2.0+** | Mobile apps (iOS/Android) | Rust backend + web UI | | **Dioxus** | Mobile apps (native UI) | Pure Rust, React-like | @@ -76,6 +76,7 @@ The following files in `.machine_readable/` contain structured project metadata: | TypeScript | **AffineScript** | | (new files) | **AffineScript** (migration via #488) | | JavaScript (where the project has been meaningfully migrated to AffineScript) | **AffineScript** | +| Deno | Bun | | Node.js | Bun | | npm | Bun | | pnpm/yarn | Bun | @@ -163,7 +164,7 @@ Do not "migrate", rewrite, or delete `formal/*.v` as if it were V-lang. - **Primary**: Guix (guix.scm) - **Fallback**: Guix (flake.guix) -- **JS deps**: Bun (`package.json` + `bun.lock`); `bunx ` for one-off tooling +- **JS deps**: Bun (`package.json` + `bun.lock`). Declare tooling as a devDependency and run `bunx --no-install --bun ` — a bare `bunx ` can fetch an unpinned package and may start Node via its shebang. ### Security Requirements From 1678d14118733a6dc858625338437f2fba33fe21 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 27 Aug 2026 06:39:15 +0100 Subject: [PATCH 3/3] docs(policy): ban ReScript explicitly and pin production installs Mirrors the TypeScript row's own replacement cell rather than assuming the literal string, so bold, qualified and extra-column table variants are all handled without reformatting the surrounding table. Enforcement Rule 1 is untouched: standards#655 records that collision as not resolvable unilaterally. Co-Authored-By: Claude Opus 5 --- .claude/CLAUDE.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index 32848441..db61169f 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -74,6 +74,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Banned | Replacement | |--------|-------------| | TypeScript | **AffineScript** | +| ReScript | **AffineScript** | | (new files) | **AffineScript** (migration via #488) | | JavaScript (where the project has been meaningfully migrated to AffineScript) | **AffineScript** | | Deno | Bun | @@ -104,7 +105,7 @@ Both are FOSS with independent governance (no Big Tech). 1. **No new TypeScript files** - Write new code in AffineScript (closed exemptions table below covers the residual `.d.ts` / Deno-test cases). 2. **No new ReScript files** - As of 2026-05-25 policy refresh; AffineScript is the go-forward. Existing `.res` files stay until migrated via #488. 3. **Use `package.json` + `bun.lock` for JS runtime deps** - Bun is npm-compatible; a manifest is REQUIRED -4. **`bun install --production` for production deps** - resolved from `package.json`, pinned via `bun.lock` +4. **`bun install --production --frozen-lockfile` for production deps** - resolved from `package.json` and pinned via `bun.lock`; `--frozen-lockfile` makes a lockfile mismatch a build failure rather than a silent re-resolve 5. **No Go code** - Use Rust instead. 6. **Python only for SaltStack** - All other Python must be rewritten. 7. **No Kotlin/Swift for mobile** - Use Tauri 2.0+ or Dioxus.