Skip to content

fix(cli): make darnit serve default to openssf-baseline - #577

Open
Marc-cn wants to merge 1 commit into
darnitdevorg:mainfrom
Marc-cn:fix/serve-default-framework
Open

Marc-cn wants to merge 1 commit into
darnitdevorg:mainfrom
Marc-cn:fix/serve-default-framework

Conversation

@Marc-cn

@Marc-cn Marc-cn commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator

Summary

darnit serve with no --framework serves whichever installed framework sorts first by name. cmd_serve takes frameworks[0] from list_available_frameworks(), which returns a sorted list.

On a full darnit-mcp install the list is gittuf, openssf-baseline, reproducibility, so the server starts with gittuf:

$ darnit serve
INFO: Starting MCP server with framework: gittuf

darnit install registers uvx --from darnit-mcp darnit serve, with no framework. So a client set up the documented way gets the gittuf tools and no OpenSSF Baseline tools. From a source checkout with every workspace plugin, the first name is community-spec; that is how I found it reporting that only the CSL audit tool was available.

darnit audit already has a different rule: load_effective_config_auto defaults to openssf-baseline. This makes serve follow the same default:

  1. openssf-baseline, if it is installed (and allowed by the operator configuration).
  2. Otherwise the only installed framework, if there is exactly one.
  3. Otherwise an error that lists the installed frameworks and asks for --framework.

Changes: a small _default_framework helper in cli.py, the two help strings that said "auto-detect", tests, and a CHANGELOG entry.

Type of Change

  • Bug fix (non-breaking change fixing an issue)
  • New feature (non-breaking change adding functionality)
  • Breaking change (fix or feature causing existing functionality to change)
  • Documentation update
  • Refactoring (no functional changes)

One case does change behavior and may deserve the "breaking" box, your call: with several frameworks installed and no baseline, serve used to pick the first by name and now exits 1 asking for --framework.

Framework Changes Checklist

  • Updated framework spec (docs/architecture/framework-design.md) if behavior changed (I did not find the serve default described there; say if it belongs)
  • Ran uv run python scripts/validate_sync.py --verbose and it passes

Testing

  • Tests pass locally (uv run pytest tests/ -v): 5144 passed, 26 skipped (main: 5138)
  • Added tests for new functionality (if applicable)
  • Linting passes (uv run ruff check .)

Six test cases in tests/darnit/test_cli.py: four for the helper, and two that run main(["serve"]) with a fake framework list and a fake server. The two serve tests fail without the fix. Nothing tested the default before.

By hand, starting the real server with stdin closed:

Install Before After
The five darnit-mcp wheels in a clean venv gittuf not re-run on wheels; covered by the unit test with the same list
Workspace, eight frameworks community-spec (seen in Claude Code) openssf-baseline

AI assistance

  • No AI assistance was used
  • AI assistance was used

Claude Fable 5.1 wrote the helper, the tests and the help-text changes, and drafted this description. I ran every command and checked the results myself. The commit carries an Assisted-by: Claude:claude-fable-5-1 trailer.

Additional Notes

  • I have not installed the 0.1.0 that is on PyPI, so I do not know which framework it serves. The claim above is about anything built from current main.
  • feat(cli): add darnit install --from-source #571 registers serve --framework openssf-baseline for source installs and has a code comment saying serve takes the first framework it finds. Naming the framework stays correct after this PR; the comment should be updated in whichever of the two merges second.

With no --framework, cmd_serve took the first name from a sorted list of installed frameworks. On a full darnit-mcp install that is gittuf, so the MCP entry darnit install writes (uvx --from darnit-mcp darnit serve) gave clients the gittuf tools.

Use the same default as darnit audit: openssf-baseline when it is installed, otherwise the only installed framework. With several installed and no baseline, exit with an error that asks for --framework.

Signed-off-by: Marc-cn <130138935+Marc-cn@users.noreply.github.com>
Assisted-by: Claude:claude-fable-5-1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant