Skip to content

Commit a889398

Browse files
committed
fix: leave vale to the governance contract as well
The contract resolves vale through mise, which fronts aqua's registry of errata-ai's own release archives, so the pin is portable and a copy installed here is a second version to drift from it. The recipe keeps shellcheck alone: the ci.sh scripts that call it are project-owned, name it directly, and pin nothing, so no resolver stands behind it.
1 parent 882a975 commit a889398

2 files changed

Lines changed: 19 additions & 24 deletions

File tree

‎SPEC.md‎

Lines changed: 8 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -516,23 +516,22 @@ skips already-installed Flatpaks, and reassembles the userbox with
516516

517517
### Lint gates reachable on PATH §spec:lint-gates-on-path
518518

519-
`setup-user` installs `shellcheck` and `vale` into `~/.local/bin`.
519+
`setup-user` installs `shellcheck` into `~/.local/bin`.
520520

521521
Rationale: project `ci.sh` scripts and the governance skills guard these
522522
tools with `command -v` so a machine without them still runs. The guard
523523
skips silently, so a local run reports success where the remote gate
524524
would fail. Installing them makes a local check mean what it appears to
525525
mean.
526526

527-
No markdown linter is installed. The governance contract pins one and
528-
resolves it through `uvx`, so a copy installed here would be a second
529-
version to drift from the pin rather than a convenience.
527+
Neither `vale` nor a markdown linter is installed. The governance
528+
contract pins both and resolves them itself — `vale` through `mise`,
529+
which fronts aqua's registry of errata-ai's own release archives, and
530+
the markdown linter through `uvx`. A copy installed here is a second
531+
version to drift from that pin rather than a convenience.
530532

531-
`vale` is installed because nothing resolves it on demand: no registry
532-
ships it, and the PyPI package is a third-party repackage. The version
533-
here tracks upstream while a consuming project's CI may pin an older
534-
one, so the two can disagree; the contract script reports the version it
535-
ran for that reason.
533+
`shellcheck` has no such resolver: the `ci.sh` scripts that call it are
534+
project-owned, name it directly, and pin nothing.
536535

537536
### Systemd user unit for auto-assembly (chezmoi) §spec:userbox-auto-assembly
538537

‎build_files/tilefin.just‎

Lines changed: 11 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -95,27 +95,23 @@ setup-user image="":
9595
echo " chezmoi..."
9696
sh -c "$(curl -fsLS get.chezmoi.io)" -- -b "$HOME/.local/bin"
9797
fi
98-
# Lint gates. Project ci.sh scripts and the symphonize skills guard
99-
# these with `command -v`, so an absent tool is skipped in silence and
100-
# a local run reports success the remote gate would not
101-
# (§spec:lint-gates-on-path).
98+
# shellcheck only. Project ci.sh scripts call it by name and guard it
99+
# with `command -v`, so an absent copy is skipped in silence and a
100+
# local run reports a success the remote gate would not
101+
# (§spec:lint-gates-on-path). Nothing resolves it on demand for them.
102+
#
103+
# vale and the markdown linter are deliberately absent: the governance
104+
# contract pins both and resolves them itself, through mise and uvx. A
105+
# copy installed here is a second version to drift from that pin, not
106+
# a convenience.
102107
if echo "$NATIVE_TOOLS" | grep -qx "lint gates"; then
103-
echo " lint gates (shellcheck, vale)..."
104-
# Upstream release binaries. The PyPI repackages of shellcheck and
105-
# vale are third-party; upstream is one trust hop fewer.
108+
echo " lint gates (shellcheck)..."
109+
# Upstream release binary; the PyPI repackage is third-party.
106110
SC_URL=$(curl -fsSL https://api.github.com/repos/koalaman/shellcheck/releases/latest \
107111
| grep -oE 'https://[^"]*linux\.x86_64\.tar\.xz' | head -1)
108112
curl -fsSL "$SC_URL" | tar xJ -C /tmp
109113
install -Dm755 /tmp/shellcheck-*/shellcheck "$HOME/.local/bin/shellcheck"
110114
rm -rf /tmp/shellcheck-*
111-
VALE_URL=$(curl -fsSL https://api.github.com/repos/errata-ai/vale/releases/latest \
112-
| grep -oE 'https://[^"]*Linux_64-bit\.tar\.gz' | head -1)
113-
curl -fsSL "$VALE_URL" | tar xz -C /tmp vale
114-
install -Dm755 /tmp/vale "$HOME/.local/bin/vale"
115-
rm -f /tmp/vale
116-
# No markdown linter here on purpose: the governance contract pins
117-
# one and resolves it through uvx, so a copy installed per-machine
118-
# would only be a second version to drift.
119115
fi
120116
fi
121117

0 commit comments

Comments
 (0)