Toilal
Following #1, ruff (lint + format) and commitizen are wired into pre-commit and CI, but the rest of the quality tooling used on the other projects is still missing here. This ticket tracks turning it on, with the volumes measured on the current `develop`. ## Type checking mypy is not enabled at all. | mode | errors | files | | --- | --- | --- | | default + `ignore_missing_imports` | 97 | 44 / 110 | | `strict = true` (what guessit/rebulk use) | 1356 | 89 / 110 | - [ ] Enable mypy in the default (non-strict) mode, blocking in pre-commit and CI, with the modules that still fail listed explicitly as debt so clean modules cannot regress. - [ ] Burn down that list module by module. - [ ] Only then consider `strict = true`; on a codebase with essentially no annotations, going straight to strict means annotating everything. ## Security and correctness lint Ruff rule families that are not selected yet. Counts are for `ddb/` only (tests are dominated by `S101`, the bare `assert`, which is expected there): | family | violations in `ddb/` | note | | --- | --- | --- | | `S` (flake8-bandit) | 9 | requests without timeout (4), pickle (2), insecure hash (1), subprocess (1), jinja2 autoescape off (1) | | `EM` | 16 | messages built inline in `raise` | | `TRY` | 36 | 16 of which are `TRY003`, usually too noisy to keep | | `C90` | 9 | functions above the default complexity threshold | | `N` | 8 | 5 are `N818` (exception classes not suffixed `Error`) — renaming those is a public API break | | `DTZ` | 1 | naive `date.today()` | - [ ] Select `S`, `EM`, `DTZ`, `LOG`, `G` and fix them; the security ones are few and real. - [ ] Select `TRY` minus `TRY003`, and `N` minus `N818` (or rename the exceptions in a major release). - [ ] Select `C90` with `max-complexity` pinned at the current worst value, so complexity cannot grow, then lower it. ## Deferred, too large for one pass Each deserves its own ticket if we want them: | family | violations | what it means | | --- | --- | --- | | `D` (pydocstyle) | 2450 | docstring formatting conventions | | `ANN` | 1546 | missing annotations, overlaps with strict mypy | | `PTH` | 1073 | `os.path` → `pathlib` | | `FBT` | 181 | boolean positional arguments | | `ARG` | 119 | unused arguments (many are interface-imposed) | ## Related - Toilal/docker-devbox-ddb#1 modernize the toolchain - Test coverage is tracked separately.