Repository navigation
Conversation
With no --framework, cmd_serve took the first name from a sorted list of installed frameworks. On a full darnit-mcp install that is gittuf, so the MCP entry darnit install writes (uvx --from darnit-mcp darnit serve) gave clients the gittuf tools. Use the same default as darnit audit: openssf-baseline when it is installed, otherwise the only installed framework. With several installed and no baseline, exit with an error that asks for --framework. Signed-off-by: Marc-cn <130138935+Marc-cn@users.noreply.github.com> Assisted-by: Claude:claude-fable-5-1
4 of 12 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
darnit servewith no--frameworkserves whichever installed framework sorts first by name.cmd_servetakesframeworks[0]fromlist_available_frameworks(), which returns a sorted list.On a full
darnit-mcpinstall the list isgittuf,openssf-baseline,reproducibility, so the server starts with gittuf:darnit installregistersuvx --from darnit-mcp darnit serve, with no framework. So a client set up the documented way gets the gittuf tools and no OpenSSF Baseline tools. From a source checkout with every workspace plugin, the first name iscommunity-spec; that is how I found it reporting that only the CSL audit tool was available.darnit auditalready has a different rule:load_effective_config_autodefaults toopenssf-baseline. This makesservefollow the same default:openssf-baseline, if it is installed (and allowed by the operator configuration).--framework.Changes: a small
_default_frameworkhelper incli.py, the two help strings that said "auto-detect", tests, and a CHANGELOG entry.Type of Change
One case does change behavior and may deserve the "breaking" box, your call: with several frameworks installed and no baseline,
serveused to pick the first by name and now exits 1 asking for--framework.Framework Changes Checklist
docs/architecture/framework-design.md) if behavior changed (I did not find the serve default described there; say if it belongs)uv run python scripts/validate_sync.py --verboseand it passesTesting
uv run pytest tests/ -v): 5144 passed, 26 skipped (main: 5138)uv run ruff check .)Six test cases in
tests/darnit/test_cli.py: four for the helper, and two that runmain(["serve"])with a fake framework list and a fake server. The twoservetests fail without the fix. Nothing tested the default before.By hand, starting the real server with stdin closed:
darnit-mcpwheels in a clean venvgittufcommunity-spec(seen in Claude Code)openssf-baselineAI assistance
Claude Fable 5.1 wrote the helper, the tests and the help-text changes, and drafted this description. I ran every command and checked the results myself. The commit carries an
Assisted-by: Claude:claude-fable-5-1trailer.Additional Notes
serve --framework openssf-baselinefor source installs and has a code comment sayingservetakes the first framework it finds. Naming the framework stays correct after this PR; the comment should be updated in whichever of the two merges second.