[E00-S03-T01] PostgreSQL 18.6 container #176
Closed
opened 2026-08-27 00:07:18 +00:00 by kpcto
·
15 comments
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#176
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Intent
Provide a PostgreSQL 18.6 container as the database, with the pinned version guaranteed in CI.
Acceptance criteria
compose-configjob runstests/compose-config.test.mjson every PR (gating the whole compose-config suite, including the T02..T08 assertions)Explicitly out of scope
Test plan
SHOW server_versionprobe)assertDbServicepin + mutation probe lock the db image topostgres:18.6-bookwormcompose-configjob runs the suite on every PRRollback note
compose-configCI job)Owning stream
platform
Risk quadrant
agent-full
status/readymay only be applied by a human maintainer.Security review starting for PR #390 (
feature/176→main).This comment marks review start; the verdict (
approve/request-changes) follows in a separate comment when the review completes.Security review of PR #390 (
feature/176→main, heada78ffea4) — final verdict (start comment: #issuecomment-2847).Playbooks applied:
security-audit,security-baseline,review-checklist(+conventions; note the conventions file is an unfilled template, so no repo-specific style rules were available beyond the observed commit/PR patterns).Reworking issue #176 acceptance criteria to resolve the security review findings on PR #390 (verdict:
request-changes, #issuecomment-2852).This comment marks rework start; the
rework-completecomment follows once the issue body is edited.Acceptance criteria reworked — security review findings on PR #390 resolved at the issue level.
I have reviewed the
.gitea/workflows/ci.ymlchange and explicitly sign off on the newcompose-configmerge gate: it is an additive job (trigger unchanged —pull_request+push: main, nopull_request_target), uses the same action majors already in the file (actions/checkout@v4,actions/setup-node@v4), contains nosecrets:context and no untrusted${{ }}interpolation intorun:, and does not modify or remove any existing job. It matches the merged, security-reviewed precedent #389. Findings 2 (digest pin) and 3 (PR-body accuracy) are accepted as informational nits — no change required.