github sponge-b0b/arid v2.2.1

latest releases: v2.2.3, v2.2.2
26 days ago

Arid 2.2.1 — Correct Project Exclusions for Dot Scan Roots

Arid 2.2.1 is a narrowly scoped correctness patch for configured project exclusions during directory discovery.

Arid 2.2.0 could load a project configuration such as:

[tool.arid]
exclude = ["legacy/**"]

and still discover files under legacy/ when invoked from the project root with the common command:

arid .

The same path could correctly report Decision: exclude through --explain-path while still appearing in --list-files and normal scan results.

Fix

Relative scan inputs are converted to absolute paths before discovery. For arid ., that can preserve a lexical /. component in the walk root and descendant paths.

Arid 2.2.0 passed those absolute walker paths directly to the configured ignore matcher. A project-relative pattern such as legacy/** could therefore fail to match a walker path whose matcher-relative form retained ./legacy/....

Arid 2.2.1 now derives the project-relative path with Rust Path semantics before evaluating configured exclusions. The matcher therefore receives legacy/... rather than an absolute path containing the lexical dot component.

The fix deliberately does not use filesystem canonicalization, so Arid's existing symlink behavior remains unchanged.

Regression coverage

The patch adds both layers that were missing from the 2.2 qualification suite:

  • a discovery unit regression using an absolute scan root containing /. with a configured generated/** exclusion;
  • a real CLI validation that changes into a configured project and runs arid . --list-files, proving the excluded directory is absent.

The corrected build passed the established Rust checks and validation/v2.sh. It was also reproduced against the Polaris repository that exposed the defect: the configured legacy/** tree disappeared from discovery, findings, and hotspots.

Compatibility

Arid 2.2.1 changes no duplicate-detection semantics.

The following remain unchanged:

  • exact normalized duplicate identity;
  • DUP001;
  • finding fingerprints;
  • report-v4, summary-v1, baseline-v1, and other machine contracts;
  • normalization behavior;
  • baseline and focus behavior;
  • worker behavior;
  • ordinary scan exit meanings;
  • hidden-file and ignore-file policy;
  • explicit-file behavior;
  • symlink traversal policy.

The only product behavior corrected by this patch is enforcement of existing configured exclude patterns when directory discovery begins from paths such as ..

Install

With uv:

uv tool install --upgrade "arid==2.2.1"
arid --version

Or with pip:

python -m pip install --upgrade "arid==2.2.1"
arid --version

Expected version output:

arid 2.2.1

Official GitHub Action

Pin the patch release directly:

- uses: sponge-b0b/arid@v2.2.1
  with:
    paths: .

Don't miss a new arid release

NewReleases is sending notifications on new releases.