fix: pin database-postgres driver to the golden tuple (pg 8.22.0, Kysely 0.29.4)
CI / Frozen lockfile install (pull_request) Successful in 46s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 35s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 25s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 31s

Review finding on PR #391: packages/database-postgres pinned pg@8.23.0 and
kysely@0.29.5, but the architecture doc's golden tuple (Technology-Stack
section 5.2 / section 7) pins pg@8.22.0 and Kysely@0.29.4. Reproducibility
requires the exact documented versions.

- packages/database-postgres/package.json: pg 8.23.0 -> 8.22.0,
  kysely 0.29.5 -> 0.29.4, @types/pg 8.23.1 -> 8.21.0 (no 8.22.x of
  @types/pg is published; 8.21.0 is the closest matching release, types
  for the immediately preceding pg minor)
- pnpm-lock.yaml: regenerated with pnpm 11.23.0 (Node 24); the resolved
  pg dependency tree is unchanged apart from the driver version itself
- tests/database-postgres-imports.test.mjs: exact-pin assertions updated
  to the corrected versions, with a comment noting the @types/pg choice
This commit is contained in:
implementer
2026-08-29 11:27:29 +00:00
parent 97c5306768
commit 09b7a40d00
3 changed files with 27 additions and 24 deletions
+3 -3
View File
@@ -9,11 +9,11 @@
"typecheck": "tsc -p tsconfig.json --noEmit"
},
"dependencies": {
"kysely": "0.29.5",
"pg": "8.23.0"
"kysely": "0.29.4",
"pg": "8.22.0"
},
"devDependencies": {
"@types/pg": "8.23.1"
"@types/pg": "8.21.0"
},
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
+18 -18
View File
@@ -25,26 +25,26 @@ importers:
packages/database-postgres:
dependencies:
kysely:
specifier: 0.29.5
version: 0.29.5
specifier: 0.29.4
version: 0.29.4
pg:
specifier: 8.23.0
version: 8.23.0
specifier: 8.22.0
version: 8.22.0
devDependencies:
'@types/pg':
specifier: 8.23.1
version: 8.23.1
specifier: 8.21.0
version: 8.21.0
packages:
'@types/node@24.13.3':
resolution: {integrity: sha512-Dh8vAsV36ig5wa9OX4pXvMc9D3Veibfw2wix0CUwYODLD8nkj9UsLjASr49nPg+2eKzxhBV+v7L8pXvT4e639Q==}
'@types/pg@8.23.1':
resolution: {integrity: sha512-fKVHpikPdg4GKks3JuLEhvwSyvwzF23hnabPy6DD8ljVbC7+6J5dQzdv4arV6jqq57djnMgs1HKBxX4P8aBI3A==}
'@types/pg@8.21.0':
resolution: {integrity: sha512-AYdtudzabjLZgVgRZmAnU8bAnVUXzuJX2IYHeSIiIHm68olD+LgQYCGWdtcNYnP0uq9c4S4NibVG3Ni7VbKW7Q==}
kysely@0.29.5:
resolution: {integrity: sha512-ooa+eSbBNPTo3MycPEuW5jdrxQdQwdtB3LC3h43FiXQbIry5tR0C5lDG7eealK0E4D7XjrnOP5DIUg/LyjRMYQ==}
kysely@0.29.4:
resolution: {integrity: sha512-y5mVgQNkMbs1eK9Xyc0pmNdabN2wHhRYY/5r4W5HrUT1rYCEPeVNSj1RUJeSDKT3U0p+mXCvLgkrFuIafYI6BA==}
engines: {node: '>=22.0.0'}
pg-cloudflare@1.4.0:
@@ -69,8 +69,8 @@ packages:
resolution: {integrity: sha512-qTAAlrEsl8s4OiEQY69wDvcMIdQN6wdz5ojQiOy6YRMuynxenON0O5oCpJI6lshc6scgAY8qvJ2On/p+CXY0GA==}
engines: {node: '>=4'}
pg@8.23.0:
resolution: {integrity: sha512-Ip2EQCngowJLGOfCwkFhPXU7/ljlhn6Rxlmy4XYfL2Y+vyRM59+8uR2xqRWKdYmbXmxCFOAmKxBuSUCdF34qLg==}
pg@8.22.0:
resolution: {integrity: sha512-8wih1vVIBMxoUM2oB4soJsD9tDnDpLv4OXBJ+EJzFsvycD+lfyIreC2gGHq78f8jbLLt+bvlPTFdFZfJkOuzAA==}
engines: {node: '>= 16.0.0'}
peerDependencies:
pg-native: '>=3.0.1'
@@ -119,13 +119,13 @@ snapshots:
dependencies:
undici-types: 7.18.2
'@types/pg@8.23.1':
'@types/pg@8.21.0':
dependencies:
'@types/node': 24.13.3
pg-protocol: 1.16.0
pg-types: 2.2.0
kysely@0.29.5: {}
kysely@0.29.4: {}
pg-cloudflare@1.4.0:
optional: true
@@ -134,9 +134,9 @@ snapshots:
pg-int8@1.0.1: {}
pg-pool@3.14.0(pg@8.23.0):
pg-pool@3.14.0(pg@8.22.0):
dependencies:
pg: 8.23.0
pg: 8.22.0
pg-protocol@1.16.0: {}
@@ -148,10 +148,10 @@ snapshots:
postgres-date: 1.0.7
postgres-interval: 1.2.0
pg@8.23.0:
pg@8.22.0:
dependencies:
pg-connection-string: 2.14.0
pg-pool: 3.14.0(pg@8.23.0)
pg-pool: 3.14.0(pg@8.22.0)
pg-protocol: 1.16.0
pg-types: 2.2.0
pgpass: 1.0.5
+6 -3
View File
@@ -370,9 +370,12 @@ test('packages/database-postgres exists, is the driver owner, and its source imp
assert.equal(manifest.name, '@personal-blog/database-postgres');
// The driver is owned here: exact pins, never ranges (reproducibility,
// same policy as typescript@6.0.3 at the root).
assert.equal(manifest.dependencies?.pg, '8.23.0', 'owner must pin pg exactly');
assert.equal(manifest.dependencies?.kysely, '0.29.5', 'owner must pin kysely exactly');
assert.equal(manifest.devDependencies?.['@types/pg'], '8.23.1', 'owner must pin @types/pg exactly');
// Golden tuple (Technology-Stack §5.2 / §7): pg 8.22.0, Kysely 0.29.4.
// @types/pg has no 8.22.x release; 8.21.0 is the closest published match
// (types for the immediately preceding pg minor).
assert.equal(manifest.dependencies?.pg, '8.22.0', 'owner must pin pg exactly');
assert.equal(manifest.dependencies?.kysely, '0.29.4', 'owner must pin kysely exactly');
assert.equal(manifest.devDependencies?.['@types/pg'], '8.21.0', 'owner must pin @types/pg exactly');
// The boundary module really imports the driver — the isolation is
// exercised, not just declared.