Type-check this package as a ratchet - #6
Conversation
Nothing type-checked this code. mypy finds 22 errors across 7 of 14 modules. Everything is checked by default and the 7 failing modules are listed as exemptions, never the inverse. Listing what is checked would leave every new module unchecked by default, so debt would accumulate silently and the list would be the same size in a year. This way new code is checked without anyone deciding to check it, the list reads as a debt register rather than an achievement, and it can only shrink. The errors are narrowing failures in query, cursor and rendering paths. Fixing them belongs in deliberate per-module changes with their own test evidence, not bundled into a tooling PR where a mistake would be invisible. Removing a module from the list plus fixing its errors is the unit of progress. warn_unused_configs reports an exemption that matches nothing, but mypy prints that as a note and still exits 0, so the CI step pipes the output and fails on it. Without that a fixed module could quietly keep its exemption. Verified rather than assumed: the current tree passes, and a new module with a deliberate type error fails, confirming new code is checked. Behaviour unchanged.
|
Reviewed as an API client / hostile-terminal-data boundary change. This PR is tooling-only: it adds a The CI gate logic checks out: the default GitHub Actions bash shell already runs with No findings in the categories this review covers (opaque cursors, page-local re-ranking, exploit/lab safety claims, terminal escaping, token leakage, archive/extraction safety, stdout contamination, unbounded pagination/concurrency, scope creep into corpus/offline storage). Nothing to flag. |
The verification block listed ruff check and pytest. CI now also runs ruff format --check and mypy, added by this campaign, so the list was two gates short of the truth.
|
Reviewed against the API-client / hostile-terminal-data security checklist for this repo. This PR is CI/tooling-only — it adds a mypy No findings. (Side note, not a finding: the new CI gate in |
Nothing type-checked this code. mypy finds 22 errors across 7 of 14 modules.
A ratchet, not an allowlist
Everything is checked by default and the 7 failing modules are listed as exemptions, never the inverse. Listing what is checked leaves every new module unchecked by default, so debt accumulates silently and the list is the same size in a year. This way new code is checked without anyone deciding to check it, and the list can only shrink.
Why exempt rather than fixed
The errors are narrowing failures in query, cursor and rendering paths. Fixing them belongs in deliberate per-module changes with their own test evidence, not bundled into a tooling PR where a mistake would be invisible.
The list cannot go stale
warn_unused_configsreports an exemption matching nothing, but mypy prints that as a note and still exits 0, so the CI step pipes the output and greps for it. Verified on another repository in this campaign with the insertion confirmed and a warm cache.Verification
Gate proven: a new module containing
def probe(x: int) -> str: return xfails.