You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The scan root is a hypothesis, not a fact: checkup models the target as a single package rooted at the scan dir, but on inherited/low-quality codebases the root is often a thin orchestrator with the real work one level down. Two jobs: judge the topology (it is itself a finding) and recover (descend and actually measure), so a "looks clean" read can't come from having looked in the wrong place.
Status — most of this is DONE; the remainder is Phase 2b
✅ Phase 2a — recover the package-script checks. Clusters A (typecheck, tests, format, lint, type-aware lint, build) and B (npm-audit, dependency-freshness) iterate over the detected assessment roots, run in each sub-package, and emit per-package-labelled records via SLUG_NS (bin/checkup.sh:599, :1093; lib/run-tool.sh:197).
The checks that still run once over the whole tree, so on an undeclared fan-out they are neither measured in-package nor labelled per package:
Package-script stragglers — circular-deps, unused-code, coverage are run_profiled (npm/script-based, exactly like clusters A/B) but currently run only at the root. On a fan-out the root has no such script → they skip, and the sub-packages' results are lost. Fold them into the recover pass (absorb circular-deps into cluster B; a new cluster C for unused + coverage). Low-risk — same proven pattern; byte-identical on a single-package repo. ← first increment.
The scc/lizard measurement arms — codebase-stats, complexity, and the duplication lizard arm measure the whole tree (sub-package code is counted, but mushed into one record and routed by whole-tree dominance). Make them per-package: filter the existing single scc --by-file walk to each assessment root's subtree (reuse, don't re-walk), and route the complexity engine per package. Surface labelled (backend: 12 hotspots · frontend: clean). The harder half (per-package engine routing) — second increment.
Thesis
The scan root is a hypothesis, not a fact: checkup models the target as a single package rooted at the scan dir, but on inherited/low-quality codebases the root is often a thin orchestrator with the real work one level down. Two jobs: judge the topology (it is itself a finding) and recover (descend and actually measure), so a "looks clean" read can't come from having looked in the wrong place.
Status — most of this is DONE; the remainder is Phase 2b
classify_topology(lib/detect-topology.sh) distinguishes single-package / declared-workspace (healthy) / undeclared fan-out (smell) / orphan-root; surfaced as a macro-alarm on the headline; recorded indetection.json.topology. Tests intest/topology.test.sh. (Project-built checks report fail (not skip) when a manifest exists but the toolchain is absent #80)SLUG_NS(bin/checkup.sh:599,:1093;lib/run-tool.sh:197).scc --by-filewalk against the first-party inventory, so committed vendored bundles no longer misroute the primary stack.Phase 2b — the remaining recovery (this issue)
The checks that still run once over the whole tree, so on an undeclared fan-out they are neither measured in-package nor labelled per package:
circular-deps,unused-code,coveragearerun_profiled(npm/script-based, exactly like clusters A/B) but currently run only at the root. On a fan-out the root has no such script → they skip, and the sub-packages' results are lost. Fold them into the recover pass (absorb circular-deps into cluster B; a new cluster C for unused + coverage). Low-risk — same proven pattern; byte-identical on a single-package repo. ← first increment.codebase-stats,complexity, and theduplicationlizard arm measure the whole tree (sub-package code is counted, but mushed into one record and routed by whole-tree dominance). Make them per-package: filter the existing singlescc --by-filewalk to each assessment root's subtree (reuse, don't re-walk), and route the complexity engine per package. Surface labelled (backend: 12 hotspots · frontend: clean). The harder half (per-package engine routing) — second increment.Guardrails (unchanged)
skipwith a precise reason, never green-by-default (Absence/failure leaking as pass/fail: npm-audit (ENOLOCK), deps-freshness (empty), duplication (missing-script) #85, landed).CHECKUP_MAX_ASSESSMENT_ROOTS).Done when
Refs #7, #75; supersedes the original Repro B (now fixed).