Skip to content

docs: audit linting config; pin Ruff version and rule selection - #38

Open
canstralian wants to merge 2 commits into
mainfrom
claude/audit-linting-config-0dnDj
Open

canstralian wants to merge 2 commits into
mainfrom
claude/audit-linting-config-0dnDj

Conversation

@canstralian

@canstralian canstralian commented Jun 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Audit of every Python, shell, YAML, and TS lint surface in the repo, captured in docs/LINTING_AUDIT.md with 8 findings ranked by operational impact.
  • Applies the lowest-risk fixes: pins Ruff version + rule selection so CI behaviour stops drifting with each Ruff release. Preserves today's zero-issue baseline — no Python source touched.
  • Defers everything that's policy (CI workflow consolidation, ruff format adoption, stricter rule sets, yamllint) and documents each as a recommended follow-up.

What changed

File Change
pyproject.toml New. target-version = "py312", explicit select = ["E4","E7","E9","F"] (matches stock defaults), line-length = 100, extend-exclude for vectors/dashboard + distro.
requirements-dev.txt New. Pins ruff==0.15.8, pytest>=8,<9, pyyaml>=6,<7.
.editorconfig New. LF, final newline, 4-space Python, 2-space JS/TS/YAML/JSON/MD.
.github/workflows/lint.yml pip install ruff → pip install -r requirements-dev.txt.
.github/workflows/ci.yml pip install ruff pytest pyyaml → pip install -r requirements-dev.txt.
docs/LINTING_AUDIT.md The audit report.

Headline findings (full details in docs/LINTING_AUDIT.md)

  • F-1 / F-2 (High, determinism) — Ruff had no project config and no pinned version. A Ruff release could silently flip CI on an unrelated PR. Fixed in this PR.
  • F-3 (Medium) — lint.yml, ci.yml, tests.yml triplicate ruff / shellcheck / pytest. Not fixed — collapsing may break branch protection. Owner decision.
  • F-4 (Low) — ruff format --check . says 13 of 16 Python files would reformat. Not fixed — wants its own one-shot reformat commit.
  • F-5 (Low) — stricter rule selection (E,F,W,I,B,UP) would surface 60 findings, 37 auto-fixable. Not fixed — proposed 4-step phased adoption.
  • F-6 (Medium) — no YAML linter. Workflows and contracts ride on review-only validation. Recommend yamllint.
  • F-8 — .editorconfig missing. Fixed.

Test plan

  • ruff check . reports All checks passed! locally with the new pyproject.toml.
  • git diff shows no Python source changes.
  • CI Lint job green on this PR.
  • CI CI job green on this PR.
  • CI Tests job green on this PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_01RoWXAy79v3vxQ1CWjkGA9h


Generated by Claude Code

Summary by CodeRabbit

  • Documentation

    • Added a linting/audit document documenting current static-analysis status and recommended follow-ups.
  • Chores

    • Standardized repository formatting and linting configuration via new editor defaults and ruff settings.
    • Added pinned development dependencies for consistent local checks.
    • Updated CI lint/install steps to install tooling from the shared development dependency set.

Captures the current Python and shell lint surface, identifies
determinism gaps (no Ruff project config, unpinned tool versions, no
.editorconfig), and applies the lowest-risk fixes that preserve
today's zero-issue Ruff baseline:

- pyproject.toml pins target-version, line-length, an explicit rule
  selection matching today's stock defaults (E4/E7/E9/F), excludes
  for the dashboard subtree and the future distro/ build dir, and a
  formatter style block.
- requirements-dev.txt pins ruff==0.15.8, pytest>=8,<9, pyyaml>=6,<7.
- lint.yml and ci.yml install via requirements-dev.txt instead of
  ad-hoc pip install lines.
- .editorconfig declares LF line endings, final newline, indent rules.
- docs/LINTING_AUDIT.md documents findings (incl. CI workflow
  triplication and deferred stricter rule sets) and a phased follow-up.

No Python source files modified. No CI job added or removed. ruff
check . still reports zero issues after this commit.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RoWXAy79v3vxQ1CWjkGA9h
@coderabbitai

coderabbitai Bot commented Jun 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 7d37dae2-6fb0-444b-8162-611aa495ea77

📥 Commits

Reviewing files that changed from the base of the PR and between e780fc0 and 3fc7944.

📒 Files selected for processing (1)
  • docs/LINTING_AUDIT.md

📝 Walkthrough

Walkthrough

Adds repository-wide editor settings, pinned dev dependencies, Ruff configuration, CI/lint workflow install updates, and a linting audit document with findings and follow-up items.

Changes

Linting configuration and CI updates

Layer / File(s) Summary
Pinned dev dependencies and Ruff config
requirements-dev.txt, pyproject.toml
Adds pinned versions for Ruff, pytest, and PyYAML, plus Ruff target/version, exclusions, lint selection, and formatting defaults.
CI and lint workflow install commands
.github/workflows/ci.yml, .github/workflows/lint.yml
Switches both workflows to install from requirements-dev.txt.
Editor formatting rules
.editorconfig
Adds repository-wide line ending, whitespace, and indentation rules.
Linting audit documentation
docs/LINTING_AUDIT.md
Adds an audit document covering scope, baseline, findings, PR changes, and follow-up recommendations.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: a linting audit plus Ruff version and rule-set pinning.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/audit-linting-config-0dnDj

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request establishes a baseline linting configuration by adding an .editorconfig, a pyproject.toml for Ruff, a requirements-dev.txt file, and a comprehensive linting audit document. The review feedback correctly identifies two issues: first, the pinned Ruff version 0.15.8 does not exist on PyPI and will cause CI failures; second, the selected Ruff rules restrict PEP 8 checks much more than Ruff's actual stock defaults of ["E", "F"].

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread requirements-dev.txt
@@ -0,0 +1,3 @@
ruff==0.15.8

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The Ruff version 0.15.8 does not exist on PyPI. This will cause the CI installation step (pip install -r requirements-dev.txt) to fail with a No matching distribution found error. Please pin to a valid, existing version of Ruff, such as 0.5.8.

ruff==0.5.8

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This claim is incorrect — ruff==0.15.8 does exist on PyPI. Verified locally against the live PyPI index:

$ pip index versions ruff | head -2
ruff (0.15.20)
Available versions: 0.15.20, 0.15.19, 0.15.18, ..., 0.15.9, 0.15.8, 0.15.7, ...

$ pip install --dry-run --ignore-installed 'ruff==0.15.8'
Collecting ruff==0.15.8
  Downloading ruff-0.15.8-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.metadata (26 kB)
Would install ruff-0.15.8

Also verifiable at https://pypi.org/project/ruff/0.15.8/. 0.15.20 is the current latest; 0.5.8 is from mid-2024 and predates most of the rule stabilizations we'd want. Keeping the pin as ruff==0.15.8.


Generated by Claude Code

Comment thread pyproject.toml
]

[tool.ruff.lint]
select = ["E4", "E7", "E9", "F"]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Ruff's actual stock default rule selection is ["E", "F"] (which enables all E and F rules). Specifying ["E4", "E7", "E9", "F"] restricts the linter to a much smaller subset of PEP 8 rules (disabling E1xx, E2xx, E3xx, E5xx, etc.). If the goal is to match Ruff's stock defaults, please use ["E", "F"].

Suggested change
select = ["E4", "E7", "E9", "F"]
select = ["E", "F"]

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ruff's stock default select is ["E4", "E7", "E9", "F"], not ["E", "F"]. Verified empirically with ruff 0.15.8 against a file that exercises all E sub-categories:

$ ruff check --isolated --no-cache x.py       # no config, no --select
E711 Comparison to `None` should be `cond is None`
  --> x.py:5:6
Found 1 error.

$ ruff check --isolated --select E,F --no-cache x.py
E501 Line too long (95 > 88)
  --> x.py:3:89
E711 Comparison to `None` should be `cond is None`
  --> x.py:5:6
Found 2 errors.

The E501 line-too-long finding only appears when the selection is explicitly widened to ["E", "F"]. Under Ruff's stock defaults, the E5xx category is disabled, which is what the audit doc claims and what this PR's pyproject.toml codifies. See also https://docs.astral.sh/ruff/rules/#pycodestyle-e-w and https://docs.astral.sh/ruff/settings/#lint_select — the "Default value" listed for lint.select is ["E4", "E7", "E9", "F"].

Switching to ["E", "F"] would surface 16 new E501 findings in this repo (per the --select E,F,W,I,B,UP probe captured in docs/LINTING_AUDIT.md §3), so it's a policy change, not a determinism fix. Keeping the selection as-is.


Generated by Claude Code

Copy link
Copy Markdown
Owner Author

Note on two failing checks (not caused by this PR):

  • Semgrep · Security Audit — fails with semgrep ci: unknown option '--error'. The --error flag was removed from the Semgrep CLI. Fix belongs in .github/workflows/security.yml, not touched here.
  • CodeQL · Deep Static Analysis (python) — fails with Code Scanning could not process the submitted SARIF file: CodeQL analyses from advanced configurations cannot be processed when the default setup is enabled. The repo has both GitHub's CodeQL default setup and a custom .github/workflows/codeql.yml; they conflict. One of the two needs to be disabled repo-wide.

Both are pre-existing infrastructure issues unrelated to the lint config changes in this PR and should be tracked as their own follow-ups.


Generated by Claude Code

@canstralian
canstralian marked this pull request as ready for review July 1, 2026 08:15

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (2)
docs/LINTING_AUDIT.md (2)

97-97: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Use fully-qualified paths for all workflow file references.

F-3 and F-7 quote ci.yml and tests.yml without the .github/workflows/ prefix, while lint.yml and every other reference in the document (e.g., line 85, lines 181–182) use the full path. Standardize to .github/workflows/ci.yml and .github/workflows/tests.yml for consistency.

Also applies to: 159-159

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/LINTING_AUDIT.md` at line 97, The workflow file references in the audit
doc are inconsistent because ci.yml and tests.yml are not fully qualified like
lint.yml and the other entries. Update the references in the affected section to
use the same .github/workflows/ prefix, matching the naming used elsewhere in
docs/LINTING_AUDIT.md and the workflow file list.

26-26: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Add language specifiers to fenced code blocks.

Two code blocks are missing language identifiers, which triggers MD040 and degrades syntax highlighting.

  • Line 26: use text for the file list.
  • Line 43: use shell for the command transcript.
📝 Proposed fixes
-```
+```text
 adapters/airtable/scope_mapper.py
 ...
-```
+```shell
 $ ruff check .
 ...

Also applies to: 43-43

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/LINTING_AUDIT.md` at line 26, Add language identifiers to the fenced
code blocks in the LINTING_AUDIT content so Markdown linting passes and syntax
highlighting works. Update the code fence showing the file list to use the text
specifier, and update the command transcript fence to use shell; locate the
affected fences in the document around the existing markdown examples and apply
the same fix wherever those unlabeled blocks appear.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/LINTING_AUDIT.md`:
- Line 24: The Python source inventory in the linting audit is inconsistent
because the “16 files” count does not match the 13 files listed below it. Update
the summary in the audit document so the parenthetical count matches the actual
enumerated files, or add the missing three Python filenames to the inventory if
the count is correct.

---

Nitpick comments:
In `@docs/LINTING_AUDIT.md`:
- Line 97: The workflow file references in the audit doc are inconsistent
because ci.yml and tests.yml are not fully qualified like lint.yml and the other
entries. Update the references in the affected section to use the same
.github/workflows/ prefix, matching the naming used elsewhere in
docs/LINTING_AUDIT.md and the workflow file list.
- Line 26: Add language identifiers to the fenced code blocks in the
LINTING_AUDIT content so Markdown linting passes and syntax highlighting works.
Update the code fence showing the file list to use the text specifier, and
update the command transcript fence to use shell; locate the affected fences in
the document around the existing markdown examples and apply the same fix
wherever those unlabeled blocks appear.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 7d03729f-a379-44a2-a280-49899aebb8b8

📥 Commits

Reviewing files that changed from the base of the PR and between 3ecfc97 and e780fc0.

📒 Files selected for processing (6)
  • .editorconfig
  • .github/workflows/ci.yml
  • .github/workflows/lint.yml
  • docs/LINTING_AUDIT.md
  • pyproject.toml
  • requirements-dev.txt

Comment thread docs/LINTING_AUDIT.md Outdated
… workflow paths

Fixes on docs/LINTING_AUDIT.md raised in PR #38 review:

- Inventory count vs list mismatch: parenthetical said 16 files but the
  list enumerated 13. The 16 count is correct (ruff sees three
  __init__.py files too). Extended the list to include them and
  clarified as "13 modules + 3 __init__.py".
- Added language identifiers (text, console) to two fenced code blocks
  (MD040).
- Normalized workflow file references to their full
  .github/workflows/<name>.yml path in F-3, F-7, and the follow-up
  section for consistency with the rest of the doc.

No content change. ruff check . still reports zero issues.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RoWXAy79v3vxQ1CWjkGA9h
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants