From 20f63e8cab8fd5c97ce48cfec4021ac76ac5e13d Mon Sep 17 00:00:00 2001 From: Mukil Loganathan Date: Tue, 30 Jun 2026 13:48:53 -0400 Subject: [PATCH] chore: install missing deps before verification (#1646) Co-authored-by: open-swe[bot] --- agent/prompt.py | 2 ++ tests/test_github_comment_prompts.py | 9 +++++++++ 2 files changed, 11 insertions(+) diff --git a/agent/prompt.py b/agent/prompt.py index 765d4d12..796bfff3 100644 --- a/agent/prompt.py +++ b/agent/prompt.py @@ -198,6 +198,8 @@ DEPENDENCY_SECTION = """--- Install dependencies only if the task requires it, using the project's package manager; skip if installation fails. +- Before running local verification commands, install or sync the project's declared dependencies if they are not already available (for example: `make install`, `uv sync`, `npm install`/`yarn install`/`pnpm install`, `go mod download`) and the task requires those checks. +- If a focused verification command fails because a declared tool or dependency is missing (for example: `command not found`, `ModuleNotFoundError`, or a missing test runner/linter), try the appropriate project install/sync command once, then rerun the same focused verification. If installation still fails, report the blocker instead of silently skipping verification. - Before ADDING a dependency the project doesn't already declare, confirm the task can't be solved with the standard library or a package already in the project's manifest/lockfile — prefer what's there. - Vet any genuinely new package before adding it: actively maintained (recent release, responsive issues, more than a single maintainer, steady downloads), free of known unpatched CVEs (`npm audit` / `pip-audit` or the GitHub advisory DB), and under a permissive license (MIT, Apache-2.0, BSD). Do not add abandoned, single-source, or unlicensed packages. Pin or bound every newly added dependency to a specific version; never add a floating or unpinned dependency. - For any dependency you add, surface it for human review. You can stop to ask: post a question or note in the source Slack thread (or, for non-Slack tasks, the PR description) and end your turn without making a tool call — the user can reply and the run will resume. This is an exception to the autonomy rule. List the package name, why it is needed, its maintenance/security status, and the alternatives you considered, in the PR description too so a reviewer can veto it.""" diff --git a/tests/test_github_comment_prompts.py b/tests/test_github_comment_prompts.py index 57a79f37..aa330ffb 100644 --- a/tests/test_github_comment_prompts.py +++ b/tests/test_github_comment_prompts.py @@ -58,6 +58,15 @@ def test_construct_system_prompt_includes_dependency_vetting_guidance() -> None: assert "the package name, why it is needed" in prompt +def test_construct_system_prompt_installs_missing_verification_dependencies() -> None: + prompt = construct_system_prompt(working_dir="/workspace") + + assert "install or sync the project's declared dependencies" in prompt + assert "focused verification command fails" in prompt + assert "ModuleNotFoundError" in prompt + assert "rerun the same focused verification" in prompt + + def test_construct_system_prompt_explains_pause_to_ask_for_dependency_review() -> None: prompt = construct_system_prompt(working_dir="/workspace")