Maintenance¶
Linters¶
All linters available are listed below. The first verb is implied if no verb is specified at runtime. Verbs may accept
arguments of their own, for more information, run an individual lint script with --help. To run all scripts,
use lint_all.py.
| Name | Purpose | Verbs | Depends on |
|---|---|---|---|
lint_commit.py |
Lint commit names against unconv.toml |
run |
git |
lint_cargo.py |
Deny dependencies per deny.toml, check/format TOML files against taplo.toml |
check , apply, apply-all |
cargo-deny (deny dependencies), taplo (TOML formatting) |
lint_codeql.py |
Query Rust sources against maint/codeql/rust/*.ql |
check, apply, apply-all, run, run-all |
codeql, rustc |
lint_javascript.py |
Lint Javascript sources against eslint.config.mjs |
None | npx (part of Node.js), eslint (auto-retrieved by script) |
lint_markdown.py |
Lint Markdown documentation | None | pymarkdownlnt |
lint_nix.py |
Lint Nix sources against nixfmt's RFC 166 style |
check, apply, apply-all |
nixfmt, git |
lint_python.py |
Lint Python sources against [tool.ruff] options in pyproject.toml |
None | ruff |
lint_rust.py |
Lint Rust sources against rustfmt.toml |
None | cargo, rustfmt |
lint_semgrep.py |
Lint source code against maint/semgrep definitions |
None | semgrep |
lint_symlinks.py |
Lint symbolic links | None | git |
Generating lockfiles¶
Note
Lockfiles should only be generated with uv. Using other Python package managers like poetry are unsupported.
If pyproject.toml has been modified, it is recommended to regenerate the lockfile to ensure
dependencies are pinned.
Verifying bisectability¶
As a general rule of thumb, each commit must individually compile and pass linters. To help with this, we have a helper
script, git_filter.py that creates a temporary worktree and executes supplied commands for each
commit in a specified range so the worktree isn't blocked by the validation run.