feat: support nub as a package manager - #300
afonsojramos wants to merge 6 commits into
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (17)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe package adds Nub package-manager detection, generates ChangesNub package-manager support
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to Nub detection, generated commands, parsing, and lockfile exclusion align across the inspected paths; no actionable merge-blocking risk was found. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change stays within existing package-manager and hook boundaries, with no demonstrated new security defect. Nub’s external execution and download behavior remains unverified, so the assessment retains limited uncertainty. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 15 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Could you please rewrite the description so it's not AI generated |
|
@LadyBluenotes sure, hope that helps |
🎯 Changes
Adds nub as a supported package manager, so projects that use it get
nub exec intent list/nub exec intent load <package>#<skill>in their guidance and hooks.src/discovery/package-manager.ts): nub is recognised fromnub.lock, anub@packageManagerfield, ordevEngines.packageManagersrc/shared/command-runner.ts):nub exec intent, which runs the installednode_modules/.bin/intentsrc/hooks/policy.ts, eval harness):nub exec intentis accepted wherever runner commands are matchedsrc/review/review.ts, docs):nub.lockjoins the default-ignored lockfilesI opened this as a PR rather than an issue first because the change is small and self-contained. Happy to move the discussion to an issue if you'd prefer.
Not in this PR
These already applied to nub projects before this change (they were detected as
unknown), so they are not regressions:check-skills/review-skillsworkflows don't provision nub or install fromnub.lock.npm root -g; nub's global root differs.@tanstack/react-routerlists no skills under nub, but lists@tanstack/router-core's 10 skills under pnpm. nub links its per-project.storeentries into a machine-wide store (~/.cache/nub/pm/store), whereas pnpm keeps real paths inside the project. Direct dependencies work.Testing
nub exec intent installwrotenub exec intentcommands to AGENTS.md, andnub exec intent list/loadran the installed CLI.✅ Checklist
pnpm run test:pr(runpnpm build:allfirst).🚀 Release Impact
Summary by CodeRabbit
nub exec intentcommands for supported actions.