fix: pin database-postgres driver to the golden tuple (pg 8.22.0, Kysely 0.29.4)
CI / Frozen lockfile install (pull_request) Successful in 46s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 35s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 25s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 31s

Review finding on PR #391: packages/database-postgres pinned pg@8.23.0 and
kysely@0.29.5, but the architecture doc's golden tuple (Technology-Stack
section 5.2 / section 7) pins pg@8.22.0 and Kysely@0.29.4. Reproducibility
requires the exact documented versions.

- packages/database-postgres/package.json: pg 8.23.0 -> 8.22.0,
  kysely 0.29.5 -> 0.29.4, @types/pg 8.23.1 -> 8.21.0 (no 8.22.x of
  @types/pg is published; 8.21.0 is the closest matching release, types
  for the immediately preceding pg minor)
- pnpm-lock.yaml: regenerated with pnpm 11.23.0 (Node 24); the resolved
  pg dependency tree is unchanged apart from the driver version itself
- tests/database-postgres-imports.test.mjs: exact-pin assertions updated
  to the corrected versions, with a comment noting the @types/pg choice
This commit is contained in:
implementer
2026-08-29 11:27:29 +00:00
parent 97c5306768
commit 09b7a40d00
3 changed files with 27 additions and 24 deletions
+3 -3
View File
@@ -9,11 +9,11 @@
"typecheck": "tsc -p tsconfig.json --noEmit" "typecheck": "tsc -p tsconfig.json --noEmit"
}, },
"dependencies": { "dependencies": {
"kysely": "0.29.5", "kysely": "0.29.4",
"pg": "8.23.0" "pg": "8.22.0"
}, },
"devDependencies": { "devDependencies": {
"@types/pg": "8.23.1" "@types/pg": "8.21.0"
}, },
"main": "./dist/index.js", "main": "./dist/index.js",
"types": "./dist/index.d.ts", "types": "./dist/index.d.ts",
+18 -18
View File
@@ -25,26 +25,26 @@ importers:
packages/database-postgres: packages/database-postgres:
dependencies: dependencies:
kysely: kysely:
specifier: 0.29.5 specifier: 0.29.4
version: 0.29.5 version: 0.29.4
pg: pg:
specifier: 8.23.0 specifier: 8.22.0
version: 8.23.0 version: 8.22.0
devDependencies: devDependencies:
'@types/pg': '@types/pg':
specifier: 8.23.1 specifier: 8.21.0
version: 8.23.1 version: 8.21.0
packages: packages:
'@types/node@24.13.3': '@types/node@24.13.3':
resolution: {integrity: sha512-Dh8vAsV36ig5wa9OX4pXvMc9D3Veibfw2wix0CUwYODLD8nkj9UsLjASr49nPg+2eKzxhBV+v7L8pXvT4e639Q==} resolution: {integrity: sha512-Dh8vAsV36ig5wa9OX4pXvMc9D3Veibfw2wix0CUwYODLD8nkj9UsLjASr49nPg+2eKzxhBV+v7L8pXvT4e639Q==}
'@types/pg@8.23.1': '@types/pg@8.21.0':
resolution: {integrity: sha512-fKVHpikPdg4GKks3JuLEhvwSyvwzF23hnabPy6DD8ljVbC7+6J5dQzdv4arV6jqq57djnMgs1HKBxX4P8aBI3A==} resolution: {integrity: sha512-AYdtudzabjLZgVgRZmAnU8bAnVUXzuJX2IYHeSIiIHm68olD+LgQYCGWdtcNYnP0uq9c4S4NibVG3Ni7VbKW7Q==}
kysely@0.29.5: kysely@0.29.4:
resolution: {integrity: sha512-ooa+eSbBNPTo3MycPEuW5jdrxQdQwdtB3LC3h43FiXQbIry5tR0C5lDG7eealK0E4D7XjrnOP5DIUg/LyjRMYQ==} resolution: {integrity: sha512-y5mVgQNkMbs1eK9Xyc0pmNdabN2wHhRYY/5r4W5HrUT1rYCEPeVNSj1RUJeSDKT3U0p+mXCvLgkrFuIafYI6BA==}
engines: {node: '>=22.0.0'} engines: {node: '>=22.0.0'}
pg-cloudflare@1.4.0: pg-cloudflare@1.4.0:
@@ -69,8 +69,8 @@ packages:
resolution: {integrity: sha512-qTAAlrEsl8s4OiEQY69wDvcMIdQN6wdz5ojQiOy6YRMuynxenON0O5oCpJI6lshc6scgAY8qvJ2On/p+CXY0GA==} resolution: {integrity: sha512-qTAAlrEsl8s4OiEQY69wDvcMIdQN6wdz5ojQiOy6YRMuynxenON0O5oCpJI6lshc6scgAY8qvJ2On/p+CXY0GA==}
engines: {node: '>=4'} engines: {node: '>=4'}
pg@8.23.0: pg@8.22.0:
resolution: {integrity: sha512-Ip2EQCngowJLGOfCwkFhPXU7/ljlhn6Rxlmy4XYfL2Y+vyRM59+8uR2xqRWKdYmbXmxCFOAmKxBuSUCdF34qLg==} resolution: {integrity: sha512-8wih1vVIBMxoUM2oB4soJsD9tDnDpLv4OXBJ+EJzFsvycD+lfyIreC2gGHq78f8jbLLt+bvlPTFdFZfJkOuzAA==}
engines: {node: '>= 16.0.0'} engines: {node: '>= 16.0.0'}
peerDependencies: peerDependencies:
pg-native: '>=3.0.1' pg-native: '>=3.0.1'
@@ -119,13 +119,13 @@ snapshots:
dependencies: dependencies:
undici-types: 7.18.2 undici-types: 7.18.2
'@types/pg@8.23.1': '@types/pg@8.21.0':
dependencies: dependencies:
'@types/node': 24.13.3 '@types/node': 24.13.3
pg-protocol: 1.16.0 pg-protocol: 1.16.0
pg-types: 2.2.0 pg-types: 2.2.0
kysely@0.29.5: {} kysely@0.29.4: {}
pg-cloudflare@1.4.0: pg-cloudflare@1.4.0:
optional: true optional: true
@@ -134,9 +134,9 @@ snapshots:
pg-int8@1.0.1: {} pg-int8@1.0.1: {}
pg-pool@3.14.0(pg@8.23.0): pg-pool@3.14.0(pg@8.22.0):
dependencies: dependencies:
pg: 8.23.0 pg: 8.22.0
pg-protocol@1.16.0: {} pg-protocol@1.16.0: {}
@@ -148,10 +148,10 @@ snapshots:
postgres-date: 1.0.7 postgres-date: 1.0.7
postgres-interval: 1.2.0 postgres-interval: 1.2.0
pg@8.23.0: pg@8.22.0:
dependencies: dependencies:
pg-connection-string: 2.14.0 pg-connection-string: 2.14.0
pg-pool: 3.14.0(pg@8.23.0) pg-pool: 3.14.0(pg@8.22.0)
pg-protocol: 1.16.0 pg-protocol: 1.16.0
pg-types: 2.2.0 pg-types: 2.2.0
pgpass: 1.0.5 pgpass: 1.0.5
+6 -3
View File
@@ -370,9 +370,12 @@ test('packages/database-postgres exists, is the driver owner, and its source imp
assert.equal(manifest.name, '@personal-blog/database-postgres'); assert.equal(manifest.name, '@personal-blog/database-postgres');
// The driver is owned here: exact pins, never ranges (reproducibility, // The driver is owned here: exact pins, never ranges (reproducibility,
// same policy as typescript@6.0.3 at the root). // same policy as typescript@6.0.3 at the root).
assert.equal(manifest.dependencies?.pg, '8.23.0', 'owner must pin pg exactly'); // Golden tuple (Technology-Stack §5.2 / §7): pg 8.22.0, Kysely 0.29.4.
assert.equal(manifest.dependencies?.kysely, '0.29.5', 'owner must pin kysely exactly'); // @types/pg has no 8.22.x release; 8.21.0 is the closest published match
assert.equal(manifest.devDependencies?.['@types/pg'], '8.23.1', 'owner must pin @types/pg exactly'); // (types for the immediately preceding pg minor).
assert.equal(manifest.dependencies?.pg, '8.22.0', 'owner must pin pg exactly');
assert.equal(manifest.dependencies?.kysely, '0.29.4', 'owner must pin kysely exactly');
assert.equal(manifest.devDependencies?.['@types/pg'], '8.21.0', 'owner must pin @types/pg exactly');
// The boundary module really imports the driver — the isolation is // The boundary module really imports the driver — the isolation is
// exercised, not just declared. // exercised, not just declared.