Commit 7b1512a
cowork-bot: automated improvements (cowork/improve-devforge-cli) (#14)
* cowork-bot: fix dispatch silent-failure + install-all extra + remove builtins alias
- dispatch: add _is_tool_installed() pre-flight check (importlib.util.find_spec)
so 'devforge guard ...' on an uninstalled tool shows a clear
'not installed — run pip install devforge[guard]' message instead of
silently exiting 1 with a raw Python ModuleNotFoundError trace.
The previous except FileNotFoundError was dead code: the error occurs
inside the subprocess, not at Popen launch time.
- install all: use canonical devforge[all] extra instead of joining all
tool keys into a comma-separated extras string (fragile; diverges if
TOOLS and pyproject.toml [all] ever drift).
- Remove 'import builtins as _builtins' workaround; no builtin shadowing
exists, so list() is fine throughout.
- Remove unused ctx: typer.Context parameter from dispatch inner function.
- Tests: 17/17 green; new TestIsToolInstalled + dispatch install-hint +
install-all-extra assertion tests cover the fixed paths.
* cowork-bot: seed cowork-auto-pr workflow for automated PR creation
* cowork-bot: merge origin/main into cowork/improve-devforge-cli; resolve cli.py merge conflicts keeping the install-all + dispatch improvements
* fix(install): replace broken bare 'pip install devforge-tools[...]' with verified-working git+ form
devforge-tools is NOT on public PyPI (verified 404 on pypi.org), so the
previous bare 'pip install devforge-tools[all/guard/...]' commands failed for
every user. README + AGENTS now lead with the git+ GitHub-source form and an
honest 'not on public PyPI' note; the 'devforge install <tool>' command and the
not-installed dispatch hint now build git+ URLs from each tool's repo URL; false
PyPI badges removed from README. Tests updated to assert the corrected hint.
Marketing-growth-agent run — conversion-surface repair (highest-ROI rung).
NOT pushed (W's call per OPS_CONTRACT).
* cowork-bot: forward tool flags in dispatch subcommands (fix silent-failure trap)
The per-tool subcommands (guard, sql, deploy, ...) used a typer Argument
for args, which made typer reject any token beginning with `-` as an
unknown option BEFORE the underlying tool ever ran. So `devforge guard
--config x.yaml` failed with "No such option" and the tool silently never
executed — the hub's known silent-failure/observability trap.
Register each dispatch command with ignore_unknown_options +
allow_extra_args and forward ctx.args to the underlying `python -m
<pkg>` invocation. Positional args and flags now reach the tool. Added a
regression test (test_dispatch_forwards_tool_flags) and the
cowork-auto-pr workflow so the improvement is delivered as a PR.
* ci: add CODEOWNERS, dependabot, CI/CD workflows (auto-PR, publish)
* fix(cli): use consistent devforge-cli.git URL in dispatch install hint + prevent rich line-wrap breaking the URL
* fix(tests): resolve merge conflict in test_cli.py (keep upstream test_dispatch_forwards_tool_flags)
* style(tests): fix E501 line-too-long in test_cli.py assertion (ruff lint)
* security(ci): pin all GitHub Actions to commit SHAs (supply-chain hardening)
Mutable tag/branch refs (@v6, @release/v1) in workflows with id-token:write
(OIDC trusted publishing) are a supply-chain risk: a compromised or moved ref
could intercept the OIDC token and publish malicious packages to PyPI.
Pinned:
- actions/checkout@v6 -> d23441a (v6)
- actions/setup-python@v6 -> ece7cb0 (v6)
- pypa/gh-action-pypi-publish@release/v1 -> ba38be9 (v1.14.1)
- actions/checkout@v4 -> 11d5960 (v4)
Aligns with engraphis build-compiled-wheels.yml which already pins SHAs.
All YAML validated, ruff clean, 19/19 tests pass.
* style: apply ruff format to cli.py and test_cli.py (CI lint fix)
* chore: remove accidentally committed scratch files (_audit_reqs.txt, parse_prs.py)
* fix(ci): revert invalid actions/checkout SHA pin to @v4 (11d5960 is not a valid ref)
---------
Co-authored-by: DevForge Engineer <engineer@devforge.dev>
Co-authored-by: Jaixii <algorithmictradingsolutions@gmail.com>1 parent 5b038a1 commit 7b1512a
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
0 commit comments