Skip to content

chore: propagate the community files and the review dispositions - #8

Merged
alexdobin merged 1 commit into
mainfrom
chore/propagate-2026-08-18
Aug 19, 2026
Merged

alexdobin merged 1 commit into
mainfrom
chore/propagate-2026-08-18

Conversation

@alexdobin

@alexdobin alexdobin commented Aug 19, 2026 •

Copy link
Copy Markdown
Collaborator

Brings this repository up to date as of 2026-08-19.

This is a content update to the v0.8.0 milestone this repository already publishes, not a new release: the tag, the version and every install pin are unchanged.

What arrives

The community-health set GitHub surfaces — CONTRIBUTING.md, SECURITY.md, CODE_OF_CONDUCT.md and CITATION.cff — written for a reader who has only this repository:

  • CONTRIBUTING says what is and is not here, and why a code comment may cite a design label whose document you cannot open.
  • SECURITY states a threat model for a compute library rather than a boilerplate one: the interesting surface is the input you hand de(), cell_source= runs a callable you supply by design, and "it needs a CUDA GPU" is explicitly out of scope.
  • CITATION.cff carries no ORCID and no DOI — a placeholder in a machine-readable citation file is worse than an absent field.

docs/reviews/README.md, and a resolution status for every finding in the 2026-06-27 ultrareview. A published findings list with no dispositions reads as a list of known open bugs, which is the opposite of why it is published. Each of the 22 now names evidence you can open — a regression test that cites the finding ID, or the code that now carries the guard — and the two that were answered by deciding not to change code say so, because "addressed" is not the same as "changed".

Corrections that came with it

Reading CONTRIBUTING.md as someone who has only this repository turned up four claims that were false here:

claim why it was wrong
the uv sync warning blamed a committed lockfile there is no lockfile here — it is gitignored. The cause is [tool.uv.sources], exactly as README.md and the CI workflow already said
pytest and ruff were given bare uv venv creates .venv but does not activate it. They are now the two uv run --no-sync … commands CI runs verbatim
"src/, docs/, tests/ and examples/ are the whole of it" it denied the existence of benchmarks/, which is here and maintained
the 2026-06-27 review's subtotals said Low 10 / Nit 8 against findings L1–L11 and N1–N7. The total of 22 was always right, so it was invisible until the resolution table listed every ID

The subtotal fix carries a dated note saying it was a transcription error and not a re-triage — that report is a dated record rather than a live tracker, and a silent edit to one would be worse than the miscount.

Two .gitignore entries and one changelog parenthetical also referred to build infrastructure that is not part of this repository; both are gone.

Verification

  • No unexplained internal reference across all 78 files.
  • This tree, no GPU: 626 passed / 202 skipped (828 collected). CI-equivalent, with shardad unimportable: 556 / 134. ruff check src/ tests/ examples/ clean.
  • benchmarks/rapids_sc/, which lives only here, is byte-identical across the update — sha256 manifest taken before and after, 10 files, no diff.

🤖 Generated with Claude Code

Brings this repository up to the development tree as of 2026-08-19. Regenerated
from it by the publication tooling rather than hand-edited.

This is a content update to the **v0.8.0** milestone this repository already
publishes, not a new release: the tag, the version and every install pin are
unchanged.

### What arrives

- **The community-health set GitHub surfaces** — `CONTRIBUTING.md`,
  `SECURITY.md`, `CODE_OF_CONDUCT.md` and `CITATION.cff`. Written for a reader
  who has only this repository: CONTRIBUTING says what is and is not here and
  why a code comment may cite a design label you cannot open, SECURITY states a
  threat model for a compute library rather than a boilerplate one, and
  CITATION.cff carries no ORCID and no DOI because a placeholder in a
  machine-readable citation file is worse than an absent field.
- **`docs/reviews/README.md`, and a resolution status for every finding** in the
  2026-06-27 ultrareview. A published findings list with no dispositions reads
  as a list of known open bugs; each of the 22 now names evidence you can open,
  and the two that were answered by deciding *not* to change code say so.

### Corrections that came with it

Reading `CONTRIBUTING.md` as someone who has only this repository turned up four
claims that were false here, all fixed upstream before this propagation:

- the `uv sync` warning blamed a lockfile that is not committed — the cause is
  `[tool.uv.sources]`, as `README.md` and the CI workflow already said;
- `pytest` and `ruff` were given bare, but `uv venv` does not activate `.venv`;
  they are now the two `uv run --no-sync …` commands CI runs verbatim;
- "`src/`, `docs/`, `tests/` and `examples/` are the whole of it" denied the
  existence of `benchmarks/`, which is here and maintained;
- the 2026-06-27 review's severity subtotals said Low 10 / Nit 8 against
  findings L1-L11 and N1-N7. Corrected, with a dated note: the total of 22 was
  always right, and that report is a dated record rather than a live tracker.

Two `.gitignore` entries and one changelog parenthetical also referred to
development-side infrastructure that is not part of this repository; both are
gone.

### Verification

- The publication tooling reports every rule firing exactly as declared and no
  unexplained internal reference across all 78 generated files. Scanned again
  over the full tree as committed here, `benchmarks/` included — which the
  generator never sees — with the same result.
- This tree, no GPU: **626 passed / 202 skipped** (828 collected). CI-equivalent,
  with `shardad` unimportable: **556 / 134**. `ruff check src/ tests/ examples/`
  clean.
- `benchmarks/rapids_sc/`, which lives only here, is byte-identical across the
  sync — sha256 manifest before and after, 10 files, no diff.
- A fresh generation of the same source `diff -rq`s clean against this branch.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@alexdobin
alexdobin requested a lite review from Copilot August 19, 2026 03:36
@alexdobin

Copy link
Copy Markdown
Collaborator Author

/gemini review

This comment was marked as outdated.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces several repository documentation and community health files, including a citation file, a Code of Conduct, a contributing guide, a security policy, and detailed resolution status tables for past codebase reviews. Feedback on the changes points out an invalid --torch-backend argument in the uv pip install setup instructions within CONTRIBUTING.md, which should be replaced with the correct --extra-index-url option to prevent installation failures.

Comment thread CONTRIBUTING.md

```bash
git clone https://github.com/ArcInstitute/gpudge.git && cd gpudge
uv venv && uv pip install --torch-backend=cu126 -e ".[dev,fast]"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The uv pip install command does not support a --torch-backend option. Running this command will fail with an unexpected argument error. To install PyTorch with a specific CUDA version, use the --extra-index-url option pointing to the PyTorch wheel index.

Suggested change
uv venv && uv pip install --torch-backend=cu126 -e ".[dev,fast]"
uv venv && uv pip install -e ".[dev,fast]" --extra-index-url https://download.pytorch.org/whl/cu126

gemini-code-assist[bot]

This comment was marked as outdated.

@alexdobin

Copy link
Copy Markdown
Collaborator Author

Thanks — checked this one against the tool rather than the docs, and it does not hold.

--torch-backend is a real uv pip install flag, added in uv 0.7.3, and cu126 is one of its accepted values:

$ uv --version
uv 0.7.12
$ uv pip install --help | grep -A3 -- '--torch-backend'
      --torch-backend <TORCH_BACKEND>
          The backend to use when fetching packages in the PyTorch ecosystem (e.g., `cpu`, `cu126`,
          or `auto`) [possible values: auto, cpu, cu128, cu126, cu125, ...]

It is also not what this PR changed — the line predates it, and README.md carries the same command with the (uv ≥ 0.7.3) version note attached. Swapping it for --extra-index-url would be a regression: the flag exists precisely so the index does not have to be named by hand, and pyproject.toml already declares the cu126 index under [tool.uv.index].

Not applying. Worth adding the (uv ≥ 0.7.3) annotation to CONTRIBUTING.md as well, so a reader on an older uv gets an explanation rather than an unknown-argument error — noted for a follow-up rather than folded in here.

@alexdobin
alexdobin merged commit 51a6df0 into main Aug 19, 2026
5 checks passed
@alexdobin
alexdobin deleted the chore/propagate-2026-08-18 branch August 19, 2026 03:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants