fix: pin database-postgres driver to the golden tuple (pg 8.22.0, Kysely 0.29.4)
CI / Frozen lockfile install (pull_request) Successful in 46s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 35s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 25s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 31s

Review finding on PR #391: packages/database-postgres pinned pg@8.23.0 and
kysely@0.29.5, but the architecture doc's golden tuple (Technology-Stack
section 5.2 / section 7) pins pg@8.22.0 and Kysely@0.29.4. Reproducibility
requires the exact documented versions.

- packages/database-postgres/package.json: pg 8.23.0 -> 8.22.0,
  kysely 0.29.5 -> 0.29.4, @types/pg 8.23.1 -> 8.21.0 (no 8.22.x of
  @types/pg is published; 8.21.0 is the closest matching release, types
  for the immediately preceding pg minor)
- pnpm-lock.yaml: regenerated with pnpm 11.23.0 (Node 24); the resolved
  pg dependency tree is unchanged apart from the driver version itself
- tests/database-postgres-imports.test.mjs: exact-pin assertions updated
  to the corrected versions, with a comment noting the @types/pg choice
This commit is contained in:
implementer
2026-08-29 11:27:29 +00:00
parent 97c5306768
commit 09b7a40d00
3 changed files with 27 additions and 24 deletions
+6 -3
View File
@@ -370,9 +370,12 @@ test('packages/database-postgres exists, is the driver owner, and its source imp
assert.equal(manifest.name, '@personal-blog/database-postgres');
// The driver is owned here: exact pins, never ranges (reproducibility,
// same policy as typescript@6.0.3 at the root).
assert.equal(manifest.dependencies?.pg, '8.23.0', 'owner must pin pg exactly');
assert.equal(manifest.dependencies?.kysely, '0.29.5', 'owner must pin kysely exactly');
assert.equal(manifest.devDependencies?.['@types/pg'], '8.23.1', 'owner must pin @types/pg exactly');
// Golden tuple (Technology-Stack §5.2 / §7): pg 8.22.0, Kysely 0.29.4.
// @types/pg has no 8.22.x release; 8.21.0 is the closest published match
// (types for the immediately preceding pg minor).
assert.equal(manifest.dependencies?.pg, '8.22.0', 'owner must pin pg exactly');
assert.equal(manifest.dependencies?.kysely, '0.29.4', 'owner must pin kysely exactly');
assert.equal(manifest.devDependencies?.['@types/pg'], '8.21.0', 'owner must pin @types/pg exactly');
// The boundary module really imports the driver — the isolation is
// exercised, not just declared.