The old bare-import regex ran over raw source text, so English prose like "flips from 'missing' to an mtime" in a JSDoc comment was classified as an import statement and tripped the gate (blocked the whole tree). Replace the regex with a state-machine scan that skips comments, string and template literals and only accepts keyword-boundary from / import( forms; add regression cases for comment prose, literal prose, property lookups and real imports beside comments.
Grouping by dirname() put lib/ files in a package.json-less group that the
CLI skipped, so the issue-#70 gate scanned zero files while reporting
success. Files now group under the nearest ancestor with a tracked
package.json, and the output reports per-package lib counts plus the
scanned total so an idle gate is visible at a glance.
skin-center 0.1.9 crashed dsh web at boot (ERR_MODULE_NOT_FOUND):
lib/index.js imported schemastery at runtime while the package only
declared it in devDependencies, and pnpm/npm do not install a
dependency's devDependencies. Add a CI check that fails on that whole
bug class:
- scans git-tracked lib/ files of every package (packages that do not
commit lib/, like dsh-ssh, are skipped by design);
- node:* builtins and @deepseek-ai/* (provided by the DSH runtime, see
.npmrc) are exempt;
- every other bare import must be declared in the package's
dependencies.
Unit tests (scripts/runtime-deps-check.test.mjs, node:test) include the
exact issue #70 fixture (refs #70).
Co-authored-by: spacexun2 <204033719+spacexun2@users.noreply.github.com>