Python Tooling
Priority: P1 (HIGH)
Rules
- Keep one authoritative dependency surface per environment and audit every tracked requirements file.
- Prefer
rufffor lint plus import hygiene; usepyrightorbasedpyrightfor type feedback. - Run
pytestpluspython -m compileallfor runtime Python changes. - Add smoke or security gates when the change touches workflow/runtime behavior.
Verification Workflow
- Lint with
ruff check. - Type-check with
pyrightorbasedpyrightwhere configured. - Run focused pytest scope for changed behavior.
- Run
python -m compileall -q ...for changed runtime trees. - Run security or smoke gates when auth, workflow runtime, or dependency surfaces change.
Anti-Patterns
- No untracked requirements files outside the audit list.
- No format-only green claim for runtime changes.
- No stale SBOM or audit artifacts in release gates.
- No local-only fix without CI parity when changing gates.
References
- Framework Map
- Tooling Gates