github sponge-b0b/arid v2.2.2

latest release: v2.2.3
25 days ago

Arid 2.2.2 — Surface Suppression Health in Normal Scans

Arid 2.2.2 makes suppression health available as part of an ordinary duplication workflow without changing Arid's default fast path or existing machine contracts.

Source-level suppressions already distinguish intentional duplication from stale maintenance state. Previously, however, that lifecycle information was available only through the standalone --suppression-status administrative command, and --fail-on-stale required a status mode.

Arid 2.2.2 integrates that maintenance signal into normal scans when explicitly requested.

Suppression summary in normal scans

Use:

arid . --suppression-summary

to run the normal duplication scan and append aggregate suppression health to human text output:

Suppressions

┌────────┬───┐
│ Total  │ 4 │
│ Active │ 3 │
│ Stale  │ 1 │
└────────┴───┘

This mode is informational. Stale suppressions do not change the normal scan exit status unless stale enforcement is also requested.

Ordinary:

arid .

continues to use the existing fast path and does not pay for the additional suppression audit.

Fail normal scans on stale suppressions

--fail-on-stale is now a normal-scan exit policy:

arid . --fail-on-stale

Arid performs the ordinary duplicate scan, audits suppressions, and returns findings exit 1 when either normal duplicate findings are reportable or stale suppression state is enforced.

A stale-only project therefore exits 1 even when the duplication scan itself has no reportable findings.

In normal text output, --fail-on-stale also includes the aggregate Suppressions block automatically.

The existing detailed administrative workflow remains available:

arid . --suppression-status
arid . --suppression-status --fail-on-stale

Machine-contract compatibility

This release does not widen Arid's existing machine contracts.

--suppression-summary is human text presentation only.

During normal JSON, Markdown, or SARIF scans, --fail-on-stale changes only exit policy. Suppression state is not added to:

  • report-v4;
  • summary-v1;
  • Markdown output;
  • SARIF output;
  • supplemental normal-scan reports.

The existing deterministic suppression-status-v1 contract remains the detailed machine-readable suppression audit.

Validation

The release adds focused unit and CLI regression coverage for:

  • ordinary scans remaining suppression-audit-free;
  • aggregate Total / Active / Stale suppression health;
  • informational --suppression-summary behavior;
  • stale-only normal scans failing under --fail-on-stale;
  • active suppressions not causing stale-policy failure;
  • normal JSON retaining the existing report-v4 shape while stale policy affects only process status.

The complete locked Rust checks, Clippy gate, release build, and validation/v2.2.sh passed before release preparation.

Release workflow housekeeping

The release workflow also preserves manual workflow_dispatch as a pre-publication build/verification path. Published-action verification remains tag-gated after PyPI and GitHub release publication, avoiding the pre-release circular check identified during the 2.2.1 process.

Install

With uv:

uv tool install --upgrade "arid==2.2.2"
arid --version

Or with pip:

python -m pip install --upgrade "arid==2.2.2"
arid --version

Expected version output:

arid 2.2.2

Official GitHub Action

Pin the patch release directly:

- uses: sponge-b0b/arid@v2.2.2
  with:
    paths: .

Don't miss a new arid release

NewReleases is sending notifications on new releases.