Repository navigation
Conversation
An environment variable read mid-file is configuration no signature admits to. beamte 0.2's env-read finds them structurally -- an invocation or access of the language's environment surface, so a mention in a comment or a string is not a finding -- and this rule runs it over every file straitjacket can parse, in the nine languages the surface table covers. Shell is deliberately not among them: $VAR is the language's own variable model. env-files names the files that ARE the configuration edge, where reads are licensed -- theme-files for the environment. Everywhere else a read is an error, not a property mapping: the rule is opt-in, and a repository that turned it on wants the read stopped, not mentioned. Enable with env-vars = true or --env-vars; opt-in for test-quality's reason, that the first scan of a language downloads its grammar. The pack cache moves to src/pack.rs, shared, so two rules meeting the same language in one scan JIT its grammar once between them; the finding and not-read formatting move to rules/beamte_findings.rs for the same reason. test-quality now reads beamte's new Rule::scope and holds file-scoped rules out of its default selection -- one read in a test file is one finding under one key -- and test-rules rejects a file-scoped rule by name, pointing at env-vars. beamte 0.2 is not on crates.io yet, so the requirement resolves through a [patch.crates-io] git entry carrying a drop-me note. Until the release, cargo publish --dry-run fails at manifest preparation -- beamte ^0.2 has no registry candidate -- which is the release ordering, not a defect here: publish beamte 0.2, delete the patch table, and the gate is whole again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WrSzGnURZoupdEfVdwk9pg
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
straitjacket | 7ae7b97 | Commit Preview URL Branch Preview URL |
Aug 30 2026, 08:05 PM |
|
…-config-2g6g2t # Conflicts: # CHANGELOG.md # src/main.rs # src/scanner.rs
beamte#21 merged and GitHub deleted the feature branch with it, so the [patch.crates-io] entry named a ref that is gone. A patch cargo cannot resolve fails the whole job at dependency resolution -- before fmt, clippy or a single test -- which is a worse failure than the publish dry-run this branch already expects. The default branch carries the merged env-read, so the patch points there and needs no ref to chase. It comes out entirely once 0.2.0 is on crates.io; the requirement above it is already written for the registry. Cargo.lock also picks up a windows-sys 0.59 -> 0.61 bump for several Windows-only transitive dependencies. That is the resolver on a newer toolchain rather than anything this change asks for, and it is left as cargo wrote it: reverting the references by hand would orphan the 0.61 entry and break --locked. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WrSzGnURZoupdEfVdwk9pg
The
|
A `[patch.crates-io]` entry naming a branch stops resolving the moment that branch is merged and deleted, and the failure lands on whoever pushes next rather than on whoever merged. That is how #63's CI broke: beamte's branch went away under a PR that had not changed, and cargo could not resolve the dependency before a single check ran. A merged commit stays reachable, so the rev survives the merge. The table is temporary either way -- `beamte = "0.3"` above it is already written for the registry, and this whole block goes when 0.3 publishes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WrSzGnURZoupdEfVdwk9pg
Runs beamte 0.2's
env-read— code reading the process environment where nothing declares it — over every file straitjacket can parse. The finding is beamte's (PowderworksCode/beamte#21); this side owns the grammar, the parse, the severity, and the piece that is policy rather than fact:env-files, the files that are the configuration edge, where reads are licensed. It istheme-filesfor the environment. Everywhere else a read is an error — the rule is opt-in, and a repository that turned it on wants the read stopped, not mentioned.Surface
env-vars = trueinstraitjacket.toml, or--env-vars. Opt-in fortest-quality's reason: the first scan of a language downloads its grammar. Nine languages (beamte's list exactly, asserted in a test); Shell deliberately not among them,$VARbeing the language's own variable model.env-files = [...]names the declared edge; matching isfile-size-exclude's, so one notion of "this path" covers both.env::var,environ,process.env) prefilter, so a file that cannot contain a read is never parsed.Structure
The pack cache moves to
src/pack.rs, shared, so two rules meeting the same language in one scan JIT its grammar once between them; finding/not-read formatting moves torules/beamte_findings.rsso the two beamte hosts cannot drift.test-qualityreads beamte's newRule::scopeand holds file-scoped rules out of its default selection — one read in a test file is one finding under one key — andtest-rulesrejects a file-scoped rule by name, pointing here.The release ordering (why the publish dry-run is red)
beamte 0.2 is not on crates.io yet, so
beamte = "0.2"resolves through a[patch.crates-io]git entry carrying a drop-me note. Every other gate is green locally — fmt, clippy-D warnings, 87 workspace tests (including a breadth test with one real environment read per language, through real packs), the musl release build, the self-scan, and the site's 96 docs-vs-manifest tests — butcargo publish --dry-runfails at manifest preparation:beamte ^0.2has no registry candidate. That is the ordering, not a defect here: merge and publish beamte 0.2, delete the patch table (three lines), and the gate is whole.First target: zmaril/sloth#46, where the rule found the scattered reads it was built for.
🤖 Generated with Claude Code
https://claude.ai/code/session_01WrSzGnURZoupdEfVdwk9pg