A follow-up to #201, #202 and #203: mex check false positives on clean, freshly set-up
scaffolds that none of those issues cover. Each was observed on a real scaffold. A freshly
populated Hono scaffold scores 8/100, and 10 of its 12 issues are false.
1. Scoped packages declared in package.json but not installed
✗ MISSING_PATH Referenced path does not exist: @hono/node-server
✗ MISSING_PATH Referenced path does not exist: @typescript/native-preview
✗ MISSING_PATH Referenced path does not exist: @types/node
All three are in the repository's devDependencies. pathExists
(src/drift/checkers/path.ts:225) confirms a scoped package only through Node module resolution
or a workspace name, so every clone that hasn't run npm install reports every scoped package it
documents. The declared manifests should count, which loadAllDependencies already reads. (This
is separate from #202 bullet 5, which is about installed packages with a strict exports map.)
2. A package's JSR name
✗ MISSING_PATH Referenced path does not exist: @hono/hono (×3)
The npm package is hono; @hono/hono is its JSR name, documented in the prose. A scoped name
matching the project's own package or jsr.json / deno.json name should not be a path claim.
3. Brace-expanded script names
✗ DEAD_COMMAND Script "test:{node,workerd,fastly,lambda,lambda-edge}" not found in package.json scripts
From bun run test:{node,workerd,…}. Expand the braces and check each script, or skip values
containing {…} (the path checker already treats braces as template placeholders).
4. Tool commands read as dependencies
⚠ DEPENDENCY_MISSING Claimed dependency "bun test" not found in any manifest
⚠ DEPENDENCY_MISSING Claimed dependency "deno test" not found in any manifest
A bullet like - **`bun test` / `deno test`** — used only for runtime-tests/… under a heading
that matches DEPENDENCY_SECTION_PATTERNS (src/drift/claims.ts:14) becomes a dependency claim.
A value containing whitespace is a command, not a package name.
5. Bare runtime filenames
✗ MISSING_PATH Referenced path does not exist: hub-onboarding.json (×2, on mex's own scaffold)
The file is .mex/local/hub-onboarding.json, created at runtime and gitignored. The prose names
it bare, so neither the path nor the gitignore exemption matches.
6. Import-specifier examples
✗ MISSING_PATH Referenced path does not exist: ./parse.js
From "ESM TypeScript imports use emitted .js specifiers, including relative imports such as
./parse.js." A relative ./x.js specifier in a sentence about imports describes a convention,
not a file at the repository root.
Expected behavior
None of these are drift. Happy to split into separate issues if that suits contributors better.
Items 1, 3 and 4 are small and self-contained.
A follow-up to #201, #202 and #203:
mex checkfalse positives on clean, freshly set-upscaffolds that none of those issues cover. Each was observed on a real scaffold. A freshly
populated Hono scaffold scores 8/100, and 10 of its 12 issues are false.
1. Scoped packages declared in
package.jsonbut not installedAll three are in the repository's
devDependencies.pathExists(
src/drift/checkers/path.ts:225) confirms a scoped package only through Node module resolutionor a workspace name, so every clone that hasn't run
npm installreports every scoped package itdocuments. The declared manifests should count, which
loadAllDependenciesalready reads. (Thisis separate from #202 bullet 5, which is about installed packages with a strict
exportsmap.)2. A package's JSR name
The npm package is
hono;@hono/honois its JSR name, documented in the prose. A scoped namematching the project's own package or
jsr.json/deno.jsonname should not be a path claim.3. Brace-expanded script names
From
bun run test:{node,workerd,…}. Expand the braces and check each script, or skip valuescontaining
{…}(the path checker already treats braces as template placeholders).4. Tool commands read as dependencies
A bullet like
- **`bun test` / `deno test`** — used only for runtime-tests/…under a headingthat matches
DEPENDENCY_SECTION_PATTERNS(src/drift/claims.ts:14) becomes a dependency claim.A value containing whitespace is a command, not a package name.
5. Bare runtime filenames
The file is
.mex/local/hub-onboarding.json, created at runtime and gitignored. The prose namesit bare, so neither the path nor the gitignore exemption matches.
6. Import-specifier examples
From "ESM TypeScript imports use emitted
.jsspecifiers, including relative imports such as./parse.js." A relative./x.jsspecifier in a sentence about imports describes a convention,not a file at the repository root.
Expected behavior
None of these are drift. Happy to split into separate issues if that suits contributors better.
Items 1, 3 and 4 are small and self-contained.