Skip to content

feat: support nub as a package manager - #300

Open
afonsojramos wants to merge 6 commits into
TanStack:mainfrom
afonsojramos:feat-nub-support
Open

afonsojramos wants to merge 6 commits into
TanStack:mainfrom
afonsojramos:feat-nub-support

Conversation

@afonsojramos

@afonsojramos afonsojramos commented Sep 30, 2026 •

Copy link
Copy Markdown

🎯 Changes

Adds nub as a supported package manager, so projects that use it get nub exec intent list / nub exec intent load <package>#<skill> in their guidance and hooks.

  • Detection (src/discovery/package-manager.ts): nub is recognised from nub.lock, a nub@ packageManager field, or devEngines.packageManager
  • Runner (src/shared/command-runner.ts): nub exec intent, which runs the installed node_modules/.bin/intent
  • Command parsing (src/hooks/policy.ts, eval harness): nub exec intent is accepted wherever runner commands are matched
  • Review (src/review/review.ts, docs): nub.lock joins the default-ignored lockfiles

I opened this as a PR rather than an issue first because the change is small and self-contained. Happy to move the discussion to an issue if you'd prefer.

Not in this PR

These already applied to nub projects before this change (they were detected as unknown), so they are not regressions:

  • The reusable check-skills / review-skills workflows don't provision nub or install from nub.lock.
  • Global package discovery uses npm root -g; nub's global root differs.
  • In a nub project, skills from transitive dependencies are not discovered, while pnpm finds the same ones. For example, a project depending only on @tanstack/react-router lists no skills under nub, but lists @tanstack/router-core's 10 skills under pnpm. nub links its per-project .store entries into a machine-wide store (~/.cache/nub/pm/store), whereas pnpm keeps real paths inside the project. Direct dependencies work.

Testing

  • Tested end to end in a real nub 0.7.5 project: nub exec intent install wrote nub exec intent commands to AGENTS.md, and nub exec intent list / load ran the installed CLI.

✅ Checklist

  • I have followed the steps in the Contributing guide.
  • I have tested this code locally with pnpm run test:pr (run pnpm build:all first).

🚀 Release Impact

  • This change affects published code, and I have generated a changeset.
  • This change is docs/CI/dev-only (no release).

Summary by CodeRabbit

  • New Features
    • Added support for Nub projects, detecting Nub from its lockfile or package-manager declarations and generating nub exec intent commands for supported actions.
  • Bug Fixes
    • Nub lockfiles are now excluded from review items, preventing them from appearing as unmapped changes.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 26a29c27-90d2-41bb-a86c-a3f3fe2b9984

📥 Commits

Reviewing files that changed from the base of the PR and between cf6f070 and cac355a.

📒 Files selected for processing (17)
  • .changeset/nub-package-manager.md
  • docs/cli/intent-review.md
  • evals/intent-discovery/harness-capture.eval.ts
  • evals/intent-discovery/harness/intent-hooks/hook-core.mjs
  • evals/intent-discovery/harness/parse-intent-commands.ts
  • evals/intent-discovery/intent-hooks.eval.ts
  • packages/intent/src/discovery/package-manager.ts
  • packages/intent/src/hooks/policy.ts
  • packages/intent/src/review/review.ts
  • packages/intent/src/shared/command-runner.ts
  • packages/intent/src/shared/types.ts
  • packages/intent/tests/cli.test.ts
  • packages/intent/tests/discovery-safety.test.ts
  • packages/intent/tests/hooks-install.test.ts
  • packages/intent/tests/install-writer.test.ts
  • packages/intent/tests/review.test.ts
  • packages/intent/tests/scanner.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The package adds Nub package-manager detection, generates nub exec intent commands, recognizes Nub intent invocations, and excludes nub.lock from review results.

Changes

Nub package-manager support

Layer / File(s) Summary
Detect Nub and generate commands
packages/intent/src/shared/types.ts, packages/intent/src/discovery/package-manager.ts, packages/intent/src/shared/command-runner.ts, packages/intent/tests/scanner.test.ts, packages/intent/tests/cli.test.ts, packages/intent/tests/discovery-safety.test.ts, .changeset/nub-package-manager.md
Detection recognizes Nub from packageManager, devEngines.packageManager.name, or nub.lock. The runner map generates nub exec intent. Tests cover detection and generated commands.
Recognize Nub intent commands
packages/intent/src/hooks/policy.ts, evals/intent-discovery/harness/parse-intent-commands.ts, evals/intent-discovery/harness/intent-hooks/hook-core.mjs, packages/intent/tests/hooks-install.test.ts, packages/intent/tests/install-writer.test.ts, evals/intent-discovery/harness-capture.eval.ts, evals/intent-discovery/intent-hooks.eval.ts
The policy matcher and evaluation parsers accept nub exec intent list and load commands. Tests cover parsed actions, skill references, and installation command handling.
Exclude nub.lock from reviews
packages/intent/src/review/review.ts, docs/cli/intent-review.md, packages/intent/tests/review.test.ts
The default review ignore patterns and CLI documentation include nub.lock. A test checks that the lockfile is excluded from review results.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Suggested reviewers: ladybluenotes

Merge Risk: ⚪ Minimal · up to cac35

Nub detection, generated commands, parsing, and lockfile exclusion align across the inspected paths; no actionable merge-blocking risk was found.

Security Architecture Review

Security architecture risk: 🔵 Low · up to cac35

The change stays within existing package-manager and hook boundaries, with no demonstrated new security defect. Nub’s external execution and download behavior remains unverified, so the assessment retains limited uncertainty.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The evidenced exposure is runner selection in project guidance and existing project- or user-scoped hooks, plus evaluation-run observations. The inspected changes do not demonstrate a new service, tenant boundary, credential grant, or tool capability.

Security Findings and Attack Paths

  • observed — The evaluation gate records a Bash load attempt before execution and accepts any recorded load, even without success or skill matching. This behavior predates the PR and was already reachable through accepted intent and npx syntax; adding Nub does not demonstrate greater authority or materially worsened exposure.

Trust Boundaries and Controls

  • observed — Metadata cannot supply an arbitrary runner string: supported names select fixed prefixes. The formatter retains character validation for argument arrays, while string arguments remain trusted templates. This bounds command construction but does not establish Nub’s external no-download behavior.

Resilience and Maintainability Implications

  • observed — Evaluation state uses a run-specific JSONL file reset before a prepared run. Repeated load observations satisfy the same existence check. Hook errors remain fail-open; execution-status reconciliation, explicit concurrency locking, and post-run cleanup are not established by the inspected state path. Nub does not change these transition rules.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 15 files. (2 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description check ✅ Passed The description explains the Nub package-manager support, lists the affected areas, documents out-of-scope limitations, reports testing, completes the checklist, and includes a changeset.
Title check ✅ Passed The title clearly and concisely summarizes the main change: adding Nub as a supported package manager.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 15 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@LadyBluenotes

Copy link
Copy Markdown
Member

Could you please rewrite the description so it's not AI generated

@afonsojramos

Copy link
Copy Markdown
Author

@LadyBluenotes sure, hope that helps

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants