[E00-S01] Workspace bootstrap #367

Closed
bot-implementer wants to merge 1 commits from feature/58 into main
Member

What changed

Bootstraps the EPPP pnpm workspace (E00-S01):

  • pnpm 11.23.0 workspace via packageManager pin + pnpm-workspace.yaml (apps/*, packages/*, extensions/*) with a committed frozen lockfile
  • Node engine restricted to the 24.x line (engines.node: "24.x")
  • TypeScript 6.0.3 pinned as an exact dependency (root devDependencies); Vitest 4.1.10 and @types/node 24.13.3 also exact-pinned per technology-stack.md
  • strict base tsconfig (tsconfig.base.json: ES2023 / NodeNext / strict family per engineering-standards.md)
  • skeleton workspaces in each group: apps/server, packages/core, extensions/example — each with build/typecheck scripts
  • root commands: pnpm build, pnpm test, pnpm typecheck
  • FIT-001 architecture test (tests/architecture.test.ts): no packages/* source imports a concrete extension — extension packages are discovered from the filesystem, so new extensions are guarded automatically
  • minimal CI (.gitea/workflows/ci.yml) running only the root scripts; pipeline stages beyond root scripts are E00-S05 (out of scope)

Criterion → test table

Acceptance criterion Evidence / test
pnpm 11.23.0 workspace committed with a frozen lockfile packageManager: pnpm@11.23.0 in root package.json; pnpm-workspace.yaml; pnpm-lock.yaml committed (lockfileVersion 9.0); CI installs with pnpm install --frozen-lockfile
Node engine restricted to the 24.x line root package.json engines.node: "24.x"; CI installs Node 24 via setup-node
TypeScript 6.0.3 pinned as an exact dependency root devDependencies "typescript": "6.0.3" (no range); lockfile resolves 6.0.3
strict base tsconfig committed to the repository tsconfig.base.json with strict: true + noUncheckedIndexedAccess, exactOptionalPropertyTypes, noImplicitOverride, useUnknownInCatchVariables, verbatimModuleSyntax, NodeNext
apps, packages and extensions kept as separate workspaces pnpm-workspace.yaml globs apps/*, packages/*, extensions/*; skeleton package in each group (install reports "all 4 workspace projects")
root commands exist for build, test and typecheck root scripts: build (pnpm -r --if-present run build), test (vitest run), typecheck (tsc -p tsconfig.json && pnpm -r --if-present run typecheck)
a clean clone installs with pnpm install --frozen-lockfile verified manually: fresh git clone + pnpm install --frozen-lockfile (fresh store) succeeds; build/test/typecheck all pass in the clone
no core package imports a concrete extension tests/architecture.test.ts (FIT-001): scans every packages/* source file and rejects imports of extension packages by name or by relative path into extensions/; negative control verified (injecting a core→extension import makes the test fail)

Test plan executed

  • clean clone → pnpm install --frozen-lockfile ✓
  • compile every workspace package (pnpm build) ✓
  • run the architecture import test (pnpm test → FIT-001) ✓
  • typecheck root tests + every workspace package (pnpm typecheck) ✓

Risks / notes

  • apps/server and extensions/example are placeholders; later stories replace their contents (Fastify shell, real extensions).
  • FIT-001 is a source-scan heuristic over import specifiers; a match inside a comment/string is treated as a violation (acceptable conservatism).
  • CI deliberately runs only root scripts; gitleaks/secret scan and further stages belong to E00-S05.

Closes #58

## What changed Bootstraps the EPPP pnpm workspace (E00-S01): - pnpm 11.23.0 workspace via `packageManager` pin + `pnpm-workspace.yaml` (`apps/*`, `packages/*`, `extensions/*`) with a committed frozen lockfile - Node engine restricted to the 24.x line (`engines.node: "24.x"`) - TypeScript 6.0.3 pinned as an **exact** dependency (root devDependencies); Vitest 4.1.10 and @types/node 24.13.3 also exact-pinned per technology-stack.md - strict base tsconfig (`tsconfig.base.json`: ES2023 / NodeNext / strict family per engineering-standards.md) - skeleton workspaces in each group: `apps/server`, `packages/core`, `extensions/example` — each with `build`/`typecheck` scripts - root commands: `pnpm build`, `pnpm test`, `pnpm typecheck` - FIT-001 architecture test (`tests/architecture.test.ts`): no `packages/*` source imports a concrete extension — extension packages are discovered from the filesystem, so new extensions are guarded automatically - minimal CI (`.gitea/workflows/ci.yml`) running only the root scripts; pipeline stages beyond root scripts are E00-S05 (out of scope) ## Criterion → test table | Acceptance criterion | Evidence / test | | --- | --- | | pnpm 11.23.0 workspace committed with a frozen lockfile | `packageManager: pnpm@11.23.0` in root `package.json`; `pnpm-workspace.yaml`; `pnpm-lock.yaml` committed (lockfileVersion 9.0); CI installs with `pnpm install --frozen-lockfile` | | Node engine restricted to the 24.x line | root `package.json` `engines.node: "24.x"`; CI installs Node 24 via setup-node | | TypeScript 6.0.3 pinned as an exact dependency | root devDependencies `"typescript": "6.0.3"` (no range); lockfile resolves `6.0.3` | | strict base tsconfig committed to the repository | `tsconfig.base.json` with `strict: true` + noUncheckedIndexedAccess, exactOptionalPropertyTypes, noImplicitOverride, useUnknownInCatchVariables, verbatimModuleSyntax, NodeNext | | apps, packages and extensions kept as separate workspaces | `pnpm-workspace.yaml` globs `apps/*`, `packages/*`, `extensions/*`; skeleton package in each group (install reports "all 4 workspace projects") | | root commands exist for build, test and typecheck | root scripts: `build` (`pnpm -r --if-present run build`), `test` (`vitest run`), `typecheck` (`tsc -p tsconfig.json && pnpm -r --if-present run typecheck`) | | a clean clone installs with `pnpm install --frozen-lockfile` | verified manually: fresh `git clone` + `pnpm install --frozen-lockfile` (fresh store) succeeds; build/test/typecheck all pass in the clone | | no core package imports a concrete extension | `tests/architecture.test.ts` (FIT-001): scans every `packages/*` source file and rejects imports of extension packages by name or by relative path into `extensions/`; negative control verified (injecting a core→extension import makes the test fail) | ## Test plan executed - clean clone → `pnpm install --frozen-lockfile` ✓ - compile every workspace package (`pnpm build`) ✓ - run the architecture import test (`pnpm test` → FIT-001) ✓ - typecheck root tests + every workspace package (`pnpm typecheck`) ✓ ## Risks / notes - `apps/server` and `extensions/example` are placeholders; later stories replace their contents (Fastify shell, real extensions). - FIT-001 is a source-scan heuristic over import specifiers; a match inside a comment/string is treated as a violation (acceptable conservatism). - CI deliberately runs only root scripts; gitleaks/secret scan and further stages belong to E00-S05. Closes #58
bot-implementer added 1 commit 2026-08-27 23:02:08 +00:00
feat: bootstrap pnpm workspace (E00-S01)
CI / Workspace bootstrap checks (pull_request) Successful in 4m41s
1d649648da
pnpm 11.23.0 workspace with a committed frozen lockfile, Node engine
restricted to the 24.x line, TypeScript 6.0.3 pinned exactly, strict base
tsconfig, apps/packages/extensions kept as separate workspaces, root
build/test/typecheck commands, and the FIT-001 architecture test rejecting
core-to-extension imports. Minimal CI runs only the root scripts (S05
stages stay out of scope). Closes #58.
kpcto closed this pull request 2026-08-27 23:47:29 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.