[E00-S03-T02] pg/Kysely imports isolated to database-postgres #177
Closed
opened 2026-08-27 00:07:20 +00:00 by kpcto
·
12 comments
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#177
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Intent
Isolate
pg/Kysely imports to thedatabase-postgrespackage.Acceptance criteria
pg/Kysely imports are isolated todatabase-postgresExplicitly out of scope
Test plan
Rollback note
Owning stream
platform
Risk quadrant
agent-full
status/readymay only be applied by a human maintainer.Security assessment (manual trace of the diff): the PR adds a new workspace package (
@personal-blog/database-postgres) importingpg/kyselyand re-exportingPool/Kysely/PostgresDialect, a comment-aware import-isolation test suite, package-set fixture updates, and an additive CI job. No secrets are committed (gitleaks-clean tree per prior tasks; only dev defaults already present on main); no new routes/handlers/auth surface; no untrusted input reaches any subprocess (test code usesspawnSyncwith argv arrays and reads local files only); no deserialization/SSRF surface. The.gitea/workflows/ci.ymlchange is additive (trigger unchanged, same action majors, nosecrets:context, no untrusted${{ }}interpolation intorun:) and matches merged precedents #389/#390 — I sign off on the newdatabase-postgres-importsmerge gate.