[E01-S01-T05] ADR: Kysely containment #192
Open
opened 2026-08-27 00:09:13 +00:00 by kpcto
·
24 comments
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#192
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Intent
Document the Kysely containment decision (ADR-006): the query builder stays inside the DB adapter.
Acceptance criteria
Explicitly out of scope
Test plan
Rollback note
Rework note (2026-08-31, analyst)
Owning stream
platform
Risk quadrant
agent-full
status/readymay only be applied by a human maintainer.Triage of #192 — [E01-S01-T05] ADR: Kysely containment (single structured comment, covering start-to-end of this triage):
bot-implementer referenced this issue2026-08-31 00:38:12 +00:00
Security review of PR #411 is starting. Final verdict with findings will follow in a second comment on this issue.
Security review complete — approve. All deterministic checks clean (gitleaks, osv-scanner), no new attack surface (docs-only diff, no endpoints/code), pipeline tripwire not triggered, and every factual claim ADR-006 makes about enforced boundaries verified against the repository. One non-blocking
shouldscope finding (S-1) is recorded above.Security review — PR #411 (feature/192) → issue #192
Verdict: approve — no security findings (severity: none). No blocking conditions.
Scope
The PR adds exactly one file,
docs/adr/ADR-006-kysely-contained-inside-db-adapter.md(+118, -0, single commit693976c), verified viagit diff b1a1c9b..HEAD --stat. No source, manifests, lockfiles, workflows or tests are touched.Deterministic checks
gitleaks detect --source . --no-git --redactover the full PR-head tree): pass. Raw output:INF scanned ~633491 bytes (633.49 KB) in 2.27s/INF no leaks found; JSON report[], exit 0. The ADR contains no credentials, tokens, hostnames or connection strings.osv-scanner --recursive ., v2.5.0): pass. Raw output:Scanned /workspace/pnpm-lock.yaml file and found 25 packages, JSON reportresults: 0(zero known vulnerabilities), exit 0. The PR changes no manifests/lockfile; it adds no dependency surface.command -v semgrepfails); not installed per policy, gap covered by the manual trace below.Manual trace (the part scanners cannot do)
grep -n "http"over the ADR → no matches), so no external-link surface at all.kysely0.29.4 /pg8.22.0 are declared only inpackages/database-postgres/package.json:12-13(its only runtime deps, exact-pinned), andkysely/pgsource imports occur only underpackages/database-postgres/src/(lock.ts, ledger.ts, index.ts, runner.ts) — matching the ADR's L96–100 operational-impact claims and thedatabase-postgres-importsCI gate it cites.kysely/pgupgrades into a single manifest under the dependency/upgrade lane. No risk introduced.Conclusion
Documentation-only change with clean scanner results, no new attack surface, and ADR claims that are factually consistent with the enforced repository state. Verdict: approve for issue #192.
Refs #411, #192