chore: install missing deps before verification (#1646)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
This commit is contained in:
Mukil Loganathan 2026-06-30 13:48:53 -04:00 • committed by GitHub
parent 4f9131987a
commit 20f63e8cab
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 11 additions and 0 deletions

View file

@ -198,6 +198,8 @@ DEPENDENCY_SECTION = """---
Install dependencies only if the task requires it, using the project's package manager; skip if installation fails.
- Before running local verification commands, install or sync the project's declared dependencies if they are not already available (for example: `make install`, `uv sync`, `npm install`/`yarn install`/`pnpm install`, `go mod download`) and the task requires those checks.
- If a focused verification command fails because a declared tool or dependency is missing (for example: `command not found`, `ModuleNotFoundError`, or a missing test runner/linter), try the appropriate project install/sync command once, then rerun the same focused verification. If installation still fails, report the blocker instead of silently skipping verification.
- Before ADDING a dependency the project doesn't already declare, confirm the task can't be solved with the standard library or a package already in the project's manifest/lockfile — prefer what's there.
- Vet any genuinely new package before adding it: actively maintained (recent release, responsive issues, more than a single maintainer, steady downloads), free of known unpatched CVEs (`npm audit` / `pip-audit` or the GitHub advisory DB), and under a permissive license (MIT, Apache-2.0, BSD). Do not add abandoned, single-source, or unlicensed packages. Pin or bound every newly added dependency to a specific version; never add a floating or unpinned dependency.
- For any dependency you add, surface it for human review. You can stop to ask: post a question or note in the source Slack thread (or, for non-Slack tasks, the PR description) and end your turn without making a tool call — the user can reply and the run will resume. This is an exception to the autonomy rule. List the package name, why it is needed, its maintenance/security status, and the alternatives you considered, in the PR description too so a reviewer can veto it."""

View file

@ -58,6 +58,15 @@ def test_construct_system_prompt_includes_dependency_vetting_guidance() -> None:
assert "the package name, why it is needed" in prompt
def test_construct_system_prompt_installs_missing_verification_dependencies() -> None:
prompt = construct_system_prompt(working_dir="/workspace")
assert "install or sync the project's declared dependencies" in prompt
assert "focused verification command fails" in prompt
assert "ModuleNotFoundError" in prompt
assert "rerun the same focused verification" in prompt
def test_construct_system_prompt_explains_pause_to_ask_for_dependency_review() -> None:
prompt = construct_system_prompt(working_dir="/workspace")