Docs: add deno install instructions - #1079
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughExpands installation documentation with an AI assistant setup prompt, Yarn 2+ guidance, Deno installation workarounds and permissions, and ChangesInstallation Documentation
Estimated code review effort: 1 (Trivial) | ~3 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/installation.md`:
- Around line 29-30: Rewrite the sentence to improve grammar and clarify the
logic: change "change `@latest` tag with" to "replace the `@latest` tag with", add
"the" before "@latest tag", and make the flow explicit by stating that if Deno
has trouble resolving `@latest` you should instead specify a concrete version (for
example replace the `@latest` tag with a version specifier like @^1.3.1). Ensure
the resulting sentence reads smoothly and unambiguously explains when and how to
use a pinned version.
- Around line 32-36: Replace the overly permissive Deno install commands that
use --allow-all with the minimal required permissions; update the bash snippets
that install npm:`@fission-ai/openspec` (both the `@latest` and @^1.3.1 variants) to
use --allow-read --allow-write --allow-env --allow-net instead of --allow-all so
the installation lines reflect only the actual permissions OpenSpec needs.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 484f8d20-e2f2-4530-838a-c3e8dd8e98be
📒 Files selected for processing (1)
docs/installation.md
alfred-openspec
left a comment
There was a problem hiding this comment.
Thanks for adding this. I smoke-tested the Deno path with Deno 2.7.14 in an isolated temp cache. The npm:@fission-ai/openspec@latest and @^1.3.1 specifiers parse and basic OpenSpec commands can run under Deno's Node/npm compatibility, but we should not document --allow-all.
Please switch this to a narrower set, and include --allow-sys=cpus,homedir as well. Without --allow-sys=cpus, even openspec --version fails via fast-glob/os.cpus(), and without homedir, openspec init --tools none fails through config path resolution. A safer default command would be:
deno install --global \
--allow-read --allow-write --allow-env --allow-sys=cpus,homedir --allow-net=edge.openspec.dev \
npm:@fission-ai/openspec@latestI'd also add a short note that subcommands which launch external tools, like config edit, feedback, or workspace open, may need a scoped --allow-run=<program> if users rely on them.
|
Thanks for the feedback @alfred-openspec . I considered settings scope one by one, but deno runs the apps sandboxed as default, and since node and bun etc. does not this anyways, and the possibility of future new permissions made me consider adding I've updated due your feedback, and updated my pull request. |
alfred-openspec
left a comment
There was a problem hiding this comment.
The narrower permissions resolve the earlier safety concern, and the documented command successfully installs and runs OpenSpec 1.6.0 under Deno 2.7.14. Good to go from my review.
|
Rebased again, and fixed the new emerged conflict. I believe if you're okay the PR is ready to be merged. |
alfred-openspec
left a comment
There was a problem hiding this comment.
Re-reviewed the rebased head d2dfd39. The diff is still limited to the Deno installation guidance, both documented specifiers install OpenSpec 1.7.0 successfully under Deno 2.9.4 with the scoped permissions, and the CodeRabbit check is green. Good to merge.
This PR introduces deno install instructions for OpenSpec.
I've tried already and I've been using without issues.
I've also added a small notice for @latest tag parsing.
Thanks!
Summary by CodeRabbit
deno install --globalcommands, and required--allow-*permissions guidance.openspec updatecan check for newer CLI releases and offer upgrades.