Merge Bash script projects into a single output file
Project description
modash
modash merges Bash script projects into one file.
It resolves source dependencies without executing shell code during normal
compile. When a path can only be known by running the script, modash can trace
one explicit run and compile from the reviewed result.
Install
python -m pip install modash
For source-tree development:
git clone https://github.com/nmehran/modash.git
cd modash
python -m pip install -e .
No external runtime dependencies are required.
Quick Start
Readable review output:
modash scripts/main.sh merged-context.sh
Runnable output for the supported Bash subset:
modash scripts/main.sh merged.sh --mode executable
If executable mode cannot prove a source site is safe to lower, it fails
before writing or overwriting the output file.
Output Modes
Context Mode
Context mode is the default. It writes dependency-first sections for the files
modash can resolve, preserves original source lines, and annotates resolved
relationships:
# modash: source ./dep.sh -> dep.sh
source ./dep.sh
Use context mode for review, debugging, and collecting complete shell-project context for another tool. It is not a runtime parity mode.
Executable Mode
Executable mode inlines sourced files at their source sites so supported parent
shell state remains Bash-equivalent: variables, functions, set state, current
directory, source arguments, repeated sources, and function-scoped sources.
The supported static subset includes exact paths, exact variables, safe path
commands and file producers, arrays, finite loops, modeled read loops,
branch-aware if and case source sites, child-shell source contexts, and
bounded source-bearing function calls.
See Supported Source Resolution for the current support matrix and fail-closed boundaries.
Runtime-Dependent Sources
Most source dependencies can be resolved without running the script. When a
project chooses a source path at runtime, use runtime discovery explicitly. It
runs the target once, records the source files that were actually loaded, writes
review artifacts, and then compiles from that reviewed graph.
Use this for patterns like hook dispatchers, plugin loaders, or helper functions where a normal executable compile correctly fails closed because the source path depends on runtime state.
Recommended flow:
modash trace scripts/main.sh --output observation.json -- --flag
modash graph scripts/main.sh --from-observation observation.json --output runtime-graph.json
modash compile-observed scripts/main.sh merged.sh --from-graph runtime-graph.json
The graph and its text report are the review points. They show which source sites ran, which files were loaded, and whether the files still match the trace. One trace represents one execution path; it is not proof that every branch was covered.
If you want to keep the generated compiler input as a separate file, write an explicit supplement and pass it to executable compile:
modash supplement scripts/main.sh --from-graph runtime-graph.json --output source-supplement.json
modash scripts/main.sh merged.sh --mode executable --source-supplement source-supplement.json
For automation, observe-compile performs the explicit trace, writes the graph
and report, and compiles from that newly observed graph:
modash observe-compile scripts/main.sh merged.sh --reviewed-graph-out runtime-graph.json -- --flag
Normal compile never traces. Runtime artifacts are data, not shell code, and generated supplements contain exact values for source resolution rather than commands to execute. See Runtime Source Discovery for the detailed artifact formats, trust checks, and safety model.
Commands
modash <entrypoint> <output> [--mode context|executable] [--source-supplement FILE]
modash trace <entrypoint> [--cwd DIR] [--env KEY=VALUE] [--output FILE] [--timeout SECONDS] [--] [args...]
modash graph <entrypoint> --from-observation observation.json --output runtime-graph.json [--report graph-review.txt]
modash supplement <entrypoint> (--from-observation observation.json [--report report.json] | --from-graph runtime-graph.json) --output source-supplement.json
modash compile-observed <entrypoint> <output> --from-graph runtime-graph.json
modash observe-compile <entrypoint> <output> --reviewed-graph-out runtime-graph.json [--observation-out observation.json] [--report graph-review.txt] [--cwd DIR] [--env KEY=VALUE] [--timeout SECONDS] [--] [args...]
Useful options:
--mode executable: write runnable output for the supported subset.--source-supplement FILE: provide exact values for runtime-dynamic source sites.trace --cwd DIR: run the target script from a specific directory.trace --env KEY=VALUE: add an environment overlay for the traced run.trace --timeout SECONDS: bound target execution. Default:30.graph --from-observation FILE: build a trusted source graph from a trace observation.graph --report FILE: choose the human-readable graph review report path.compile-observed --from-graph FILE: compile executable output using a trusted graph and an in-memory generated supplement.observe-compile --reviewed-graph-out FILE: explicitly run tracing, write review artifacts, and compile executable output from the newly observed graph.supplement --report FILE: choose where to write the review report.
Development
Run the local verification suite:
pytest -q
python -m py_compile $(find methods -name '*.py' -print) $(find test -name '*.py' -print) modash.py
git diff --check
Optional packaging checks:
python -m build --sdist --wheel --outdir dist
python -m twine check dist/*
MODASH_PACKAGING_SMOKE=1 pytest -q test/test_packaging_smoke.py
Design notes live in docs.
License
This project is licensed under the Apache 2.0 License. See LICENSE.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file modash-0.6.0.tar.gz.
File metadata
- Download URL: modash-0.6.0.tar.gz
- Upload date:
- Size: 139.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
af9ceae97e0eb4c44b4a9bcb229b4108ed420b8cebbbfec8c869520fb18e1384
|
|
| MD5 |
e77ca9c3188a074e742746467e8c4536
|
|
| BLAKE2b-256 |
c36cecb8648ccc0ef7abfb49b00748ac55ee2e1446c4b33de7c971fdbca3e4c3
|
Provenance
The following attestation bundles were made for modash-0.6.0.tar.gz:
Publisher:
publish-pypi.yml on nmehran/modash
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
modash-0.6.0.tar.gz -
Subject digest:
af9ceae97e0eb4c44b4a9bcb229b4108ed420b8cebbbfec8c869520fb18e1384 - Sigstore transparency entry: 1710887636
- Sigstore integration time:
-
Permalink:
nmehran/modash@3027f7269a367445292a3ae319323c2af80d8599 -
Branch / Tag:
refs/tags/v0.6.0 - Owner: https://github.com/nmehran
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@3027f7269a367445292a3ae319323c2af80d8599 -
Trigger Event:
release
-
Statement type:
File details
Details for the file modash-0.6.0-py3-none-any.whl.
File metadata
- Download URL: modash-0.6.0-py3-none-any.whl
- Upload date:
- Size: 152.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
174842ddcdb3577268ec87ceabafcadc6fd70cb7bf71580c6fbd895372ca0c22
|
|
| MD5 |
480d733769d2e75a05af63fa47cb8b71
|
|
| BLAKE2b-256 |
3f1abaf658710dd254833e696b0d98747b67a69adb2b40922b724b93b819cbd9
|
Provenance
The following attestation bundles were made for modash-0.6.0-py3-none-any.whl:
Publisher:
publish-pypi.yml on nmehran/modash
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
modash-0.6.0-py3-none-any.whl -
Subject digest:
174842ddcdb3577268ec87ceabafcadc6fd70cb7bf71580c6fbd895372ca0c22 - Sigstore transparency entry: 1710887647
- Sigstore integration time:
-
Permalink:
nmehran/modash@3027f7269a367445292a3ae319323c2af80d8599 -
Branch / Tag:
refs/tags/v0.6.0 - Owner: https://github.com/nmehran
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@3027f7269a367445292a3ae319323c2af80d8599 -
Trigger Event:
release
-
Statement type: