jevhooks.git / tools / README.md

Chapter 14: tools, two scripts and one rule about versions

A repository collects commands the way a kitchen drawer collects takeaway menus: one in the README, a slightly different one in a git hook, a third in somebody's shell history. jevhooks keeps them in one place instead. Every job has a name in mise.toml, and the README, the git hooks and you all call it by that name: mise run check, mise run mod, mise run daemon. mise installs the tools those tasks need as well, at the versions written in the same file, for one user and without root.

Most tasks are a line or two and live in mise.toml itself. The two that needed an if are scripts, here.

  • with-secrets.sh runs a command with Jev's key in its environment. The key is declared in fnox.toml, with no value and no provider. If you have fnox set up to supply TYPESAFE_API_KEY (from age, from a password manager), the command runs under fnox exec; if not, it simply runs, and the key must already be in the environment. Either way nothing reads a secret from a file in this repository, because none is ever written to one.
  • check-versions.sh fails when a version written somewhere other than mise.toml disagrees with it. There is one such place today: hk.pkl has to name the hk release it was written for. It also fails if flake.nix starts naming a toolchain.

Aside: why a version check at all? Because the alternative is a comment saying "remember to change both". The hooks file cannot read mise.toml, so the number is written twice, and a number written twice is two numbers the moment someone updates one. The check turns that into a failed commit instead of a puzzling afternoon.

Aside: where is nix? flake.nix is still at the top, for a machine that uses it: its shell holds mise itself and a C compiler, which is the one thing a downloaded toolchain does not bring (Rust build scripts link with it, even for wasm). It installs nothing else and pins nothing else.

Try it. mise tasks prints every task with its description. Then mise run check-versions (it needs no Rust), and, to watch it earn its keep, change hk = "2.5.0" in mise.toml to another number and run it again.

For the people who maintain it

TaskWhat it runs
submodulesgit submodule update --init --recursive
hooks:installhk install: the hooks in hk.pkl
modcargo for wasm32, wasm-opt -Oz, wasm2js -O2, into plugin/hooks/jevhooks.js (chapter 9)
daemona release build of jevhooks, copied into plugin/bin/ (chapter 11)
testcargo test --workspace
test:liveThe one test that asks the real Jev, through tools/with-secrets.sh (needs the key and the network)
clippycargo clippy --workspace
check-versionstools/check-versions.sh
plugin:validate, plugin:testclaude plugin validate plugin, claude plugin test plugin (CLAUDE names another binary)
checkcheck-versions, test, mod, daemon, then plugin:validate
servetools/with-secrets.sh plugin/bin/jevhooks serve
statusplugin/bin/jevhooks status

In this folder

PathWhat
with-secrets.shRuns its arguments under fnox exec when fnox resolves the key, plainly otherwise. JEVHOOKS_NO_FNOX=1 forces the plain path.
check-versions.shPOSIX tools only; reads mise.toml's key = "value" lines.

← Previous: Chapter 13, third-party/ · Up: jevhooks