test / unit + widget + golden + a11y (push) Successful in 1m30s
test / integration_test (xvfb) (push) Failing after 1m14s
test / bundle smoke (xvfb 5s) (push) Failing after 1m3s
test / daemon subprocess + web WASM smoke (push) Successful in 1m42s
Three sections instead of one flat list. `self:` carries clide's own MIT license (rendered first in the About screen so the user knows what they're running before the dependency list). `dependencies:` covers artefacts that actually ship in the binary — JetBrainsMono, JosefinSans, yaml. `dev_dependencies:` tracks build-time tooling (mocktail, alchemist, flutter_lints, lints, test) for audit completeness without polluting the user-facing About panel. Also backfilled the two root-package dev deps that were missed the first pass: `lints: 5.0.0` and `test: 1.25.8` (root pubspec, not app/). Root LICENSE mirrored into app/assets/LICENSE + declared as a bundled asset so the About screen can read it at runtime (Flutter can't reference paths above the package root). D-042 updated to describe the three-section split and the dev-vs- runtime distinction. Co-Authored-By: Claude <noreply@anthropic.com>
4.1 KiB
4.1 KiB
Tooling Decisions
Toolchain, supply chain, CI, ignore strategy.
D-031: Prefer-zero-deps, exact-pin
- Date: 2026-04-21
- Decision: Default to writing code ourselves. Every third-party Dart dependency needs a paragraph of justification in the PR that adds it. What stays is exact-pinned in
pubspec.yaml(no caret ranges),pubspec.lockis committed, and advisories are reviewed before every bump. - Rationale: Supply-chain gate. Flutter SDK + Dart SDK give us most of what we need; the dependencies we keep are the ones we can't reasonably write (yaml parser, mocktail, alchemist). Exact-pin because caret ranges mean "the CVE bumps itself in silently."
- Cost: Longer PR descriptions for deps; occasional reinvention of a convenience. Accepted.
- Raised by: 2026-04-21 planning; reinforced by user feedback memory.
D-032: CI — Gitea primary, Linux-only runners, not yet activated
- Date: 2026-04-21
- Decision: CI config lives at
.gitea/workflows/test.yml(Gitea Actions consumes GitHub-Actions syntax). Runners are Linux only; macOS is tested locally. The workflow is ready but Gitea Actions is not yet activated on the instance — the file is a staged pipeline for review. If the repo moves to GitHub, the file copies to.github/workflows/test.ymlverbatim. - Rationale: We want the CI story defined before we turn CI on — lower blast radius on early red builds. GitHub portability is free because the syntax is shared.
- Cost: PRs don't run CI yet;
make push-checkis the gate until activation. - Raised by: 2026-04-21 planning.
D-042: Dependencies documented in licenses.yaml
- Date: 2026-04-22
- Decision:
app/assets/licenses.yamlhas three sections:self:(clide's MIT license, rendered first in the About screen so the user knows what they're running),dependencies:(third-party artefacts that ship in the binary — fonts, runtime Dart packages, native supporter tools, bundled data), anddev_dependencies:(build-time-only tooling — test runners, mocks, lints, golden harness — tracked for audit but not rendered in the About screen because they don't reach the user). Each entry has name, kind, version, homepage, license identifier, and a one-line purpose; runtime entries also carry alicense_file:pointer to the bundled license text so the About screen can display it verbatim. Adding any dependency is a two-step commit: add the artefact and the correspondinglicenses.yamlentry in the same changeset, under the correct section. - Rationale: Complements D-031. Prefer-zero-deps is a budget;
licenses.yamlis the visible consequence. An extra row in the About screen is a review-time signal that the shipped-binary surface grew. Splitting dev deps out keeps the user-facing list small and honest — a test framework is not something the user needs to see in About — while still documenting every supply-chain input for audit completeness. The runtime entries discharge the redistribution obligations bundled licenses impose (OFL, MIT, BSD all require preserving the license text alongside the binary) without ad-hoc NOTICE files. - Cost: One extra edit per dep. Zero tolerance for drift — an un-listed dep is a contributor-visible bug. Until the About screen lands at Tier 6,
licenses.yamlis accurate but not rendered; the discipline applies from now regardless so Tier 6 inherits a clean list. - Raised by: 2026-04-22 planning (user-directed best practice).
D-033: Golden-output ignore pattern — coverage.* excludes output, not scripts
- Date: 2026-04-21
- Decision:
.gitignoreexcludescoverage.*(the lcov output files fromflutter test --coverage). Coverage-related scripts are namedci/test_coverage.sh(notci/coverage.sh) to stay outside the pattern. - Rationale: An earlier draft named the script
ci/coverage.shand it was silently git-ignored. Renaming the script is cheaper than narrowing the gitignore pattern (which risks re-introducing output churn). - Cost: Script names have a convention to follow.
- Raised by: 2026-04-21 planning (caught during commit rehearsal).