Repository navigation
Conversation
darnit install always registers 'uvx --from darnit-mcp darnit serve' as the MCP server command. From a source checkout that runs the PyPI package, not the code that was installed. --from-source registers the darnit executable of the running installation instead: the console script next to the running interpreter, falling back to darnit on PATH. The default entry is unchanged. Signed-off-by: Marc-cn <130138935+Marc-cn@users.noreply.github.com> Assisted-by: Claude:claude-fable-5-1
A source checkout installs every workspace plugin, and darnit serve without --framework takes the first one it finds (community-spec). Claude Code then connected to a server that had no OpenSSF Baseline tools. Register 'serve --framework openssf-baseline', the same arguments as the manual command in docs/install/from-source.md. Found by running the registered server from Claude Code. Signed-off-by: Marc-cn <130138935+Marc-cn@users.noreply.github.com> Assisted-by: Claude:claude-fable-5-1
Installs uv and zizmor if they are missing (asking first), uses the darnit checkout the script lives in or clones one, installs from uv.lock, runs an OpenSSF Baseline level 1 audit, and offers to register the MCP server with Claude Code through darnit install --from-source. Signed-off-by: Marc-cn <130138935+Marc-cn@users.noreply.github.com> Assisted-by: Claude:claude-fable-5-1
Marc-cn
force-pushed
the
feat/quickstart-script
branch
from
October 9, 2026 21:45
3a0b395 to
afe345a
Compare
mlieberman85
requested changes
Oct 10, 2026
mlieberman85
left a comment
Contributor
There was a problem hiding this comment.
Thanks, the script is careful in a lot of places (tty handling, leaving a foreign ~/.local/bin/darnit alone, nothing written to the audited repo; I confirmed that last one). A few things before merge:
- The uv bootstrap (
quickstart.sh:109-111) iscurl | shof an unpinned installer, which by default edits the user's shell rc files. Please run it withUV_NO_MODIFY_PATH=1and print the PATH hint, or say in the prompt that it will modify the profile. Pinning the installer version would be a bonus. - Please drop the
curl … | bash -s --usage from the header (lines 7-8). The docs rightly say download and read first. - The registration prompt (line 203) mentions only
~/.claude.json, butdarnit install --forcewithout--mcp-onlyalso reinstalls~/.claude/skills/darnit-*andrmtrees the existing ones. Please mention the skills in the prompt, or don't force them. uv sync --frozen(line 141) in a checkout synced with--all-extras(our CI/runbook default) uninstalls 33 packages (sigstore, pytest-cov, pre-commit, claude-agent-sdk, …).--inexactwould avoid that.- Smaller: I'd move the README pointer below the published channels, since 0.2.0 is about to make PyPI the default. Consider
[y/N]for the install prompts, and ashellcheck+--helpCI step.
This will need a rebase once #571 is squash-merged.
Drafted with Claude Code; reviewed and posted by me.
- Install a pinned uv with UV_NO_MODIFY_PATH=1, so the installer does not edit shell profiles; print the PATH line instead, and say so in the prompt. - Remove the curl-pipe-bash usage from the header. The docs say to read the script first. - The registration prompt now says that the darnit skills in ~/.claude/skills are reinstalled, not only that ~/.claude.json changes. - uv sync --inexact, so a checkout synced with --all-extras keeps its packages (116 before and after; it lost 33 without it). - Prompts default to no. - Move the README pointer below the published channels. - CI: shellcheck and --help on the script in the Lint job. Signed-off-by: Marc-cn <130138935+Marc-cn@users.noreply.github.com> Assisted-by: Claude:claude-fable-5-1
Collaborator
Author
|
Thanks, pushed one commit
I will rebase once #571 is squash-merged. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
scripts/quickstart.sh, a one-command setup from source.What it does:
ghis missing or not logged in.~/.local/share/darnit.uv sync --frozen, so users get the dependency versions inuv.lock, and linksdarnitinto~/.local/binif nothing is there already.--all-levelsfor everything).darnit install --from-source.It asks before installing anything or writing
~/.claude.json;--yesskips the questions. With no terminal and no--yesit installs nothing. It changes nothing in the audited repository.Docs: a "One-command setup" section in
docs/install/from-source.md, a pointer in the README, and a CHANGELOG entry.Depends on #571. This branch is stacked on it, so the diff shows that commit too until it merges. A run without a checkout clones main, and main needs
--from-sourcefor step 5 to work.Type of Change
Testing
uv run pytest tests/ -v): 5141 passed, 26 skippeduv run ruff check .);shellcheckis clean on the scriptManual runs on RHEL 10.2 (x86_64), against a toy repository with one README and no remote:
--dir: clones, installs, audits.--yes; a second run reuses the clone.--yes: refuses with exit 1 and writes nothing.~/.local/bin/darnitthat points elsewhere is left alone, with a warning.claudeon PATH: the entry is the checkout's.venv/bin/darnit serve; a second run does not stop on the overwrite prompt.Also run on WSL (Ubuntu 24.04) with Claude Code 2.1.168: the script registered the server, and Claude Code ran a level 1 audit of a real repository through it (the
/darnit-auditskill,audit_openssf_baseline, three judgments submitted). The repository's working tree stayed clean.Not tested: macOS and the wget fallback. Windows is supported only through WSL (bash).
AI assistance
Claude wrote the script and the doc edits. I ran every test above myself on the VM. The commit carries an
Assisted-by: Claude:claude-fable-5-1trailer.Additional Notes
Two choices worth a look in review:
uv sync --frozenand notuv tool install --editable(the "Quick install" infrom-source.md). The tool install resolves without the lockfile and today pickstree-sitter-language-pack1.6.3, with whichdarnit auditcrashes.uv syncalso installs the dev group; I kept it so that running the script inside a contributor's checkout does not remove pytest from their environment.--tags level=1, becausedarnit audit --profile level1_quickcurrently returns all 66 controls.I will file these as separate issues: the
uv tool installcrash,--profilehaving no effect ondarnit audit, and a repository with no remote producing platform API calls with an empty owner that are reported as ERROR.