[E00-S01-T09] TypeScript 6.0.3 exact dependency #376
No Reviewers
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#376
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What changed
Makes both acceptance criteria for [E00-S01-T09] TypeScript 6.0.3 exact dependency (#162) enforceable rather than incidental. The root manifest already pins
typescript: "6.0.3"exactly (introduced with the build/typecheck scripts in E00-S01-T05); this change locks that state in with a regression suite:tests/typescript-pin.test.mjs(new) — anode:testsuite (zero dependencies,pnpm-lock.yamluntouched) that fails if the pin or the resolution ever drifts:package.jsondeclaresdevDependencies.typescriptas exactly6.0.3— a bareMAJOR.MINOR.PATCHwith no^/~/>=range;pnpm-lock.yamlresolves the root importer withspecifier: 6.0.3/version: 6.0.3and that the packages section contains exactly one resolved TypeScript entry (typescript@6.0.3);apps/server,packages/core,extensions/example) resolves the exact version end-to-end:pnpm exec tsc --versionrun inside each package directory (the same resolution the packagebuild/typecheckscripts use) reportsVersion 6.0.3.Explicitly out of scope per the brief (not touched): Node engine restriction (E00-S01-T08), strict base tsconfig (E00-S01-T10), apps/packages/extensions separation (E00-S01-T11). No CI workflow changes — test-suite wiring in CI is E00-S05 by design (same as T05–T08); the existing CI job (frozen install +
pnpm -r liston Node 24) stays green.Criterion → test table
tests/typescript-pin.test.mjs: "root package.json pins typescript as an exact dependency (6.0.3)" — assertsdevDependencies.typescriptis exactly"6.0.3"and matches a bareMAJOR.MINOR.PATCH(no semver range). Mutation-probed:^6.0.3fails this testtests/typescript-pin.test.mjs: "pnpm-lock.yaml resolves the root typescript pin to exactly 6.0.3" — asserts the root importer resolvesspecifier: 6.0.3/version: 6.0.3and the packages section contains exactly onetypescript@6.0.3entry. Mutation-probed: lockfileversion: 6.0.2fails this testtests/typescript-pin.test.mjs: "every workspace package resolves the exact TypeScript version (6.0.3)" — runspnpm exec tsc --versioninapps/server,packages/core,extensions/exampleand asserts each reportsVersion 6.0.3. Mutation-probed: a faketscprintingVersion 6.0.2inapps/server/node_modules/.binfails this test (and any manifest/lockfile drift additionally trips pnpm's ownERR_PNPM_OUTDATED_LOCKFILEguard in this environment)Test plan executed
node_modules), Node 24:pnpm install --frozen-lockfile→ success,using pnpm v11.23.0, lockfile unchanged ✓pnpm -r list --depth -1(second CI step), Node 24 → lists all four workspace projects, exit 0 ✓pnpm typecheck→ all three packages passtsc -p tsconfig.json --noEmitunder the pinned 6.0.3 ✓node --test tests/typescript-pin.test.mjs→ 3/3 pass ✓node --test "tests/**/*.test.mjs"on Node 24 (v24.20.0) → 24/24 pass (10 architecture-import + 6 workspace-config + 5 node-engine + 3 typescript-pin), exit 0 ✓package.json"typescript": "^6.0.3"→ exactness test fails; resolution test also fails viaERR_PNPM_OUTDATED_LOCKFILE✓pnpm-lock.yamlimporterversion: 6.0.2→ lockfile test fails; resolution test also fails viaERR_PNPM_OUTDATED_LOCKFILE✓tscreportingVersion 6.0.2shadowing a package.bin→ resolution test fails ✓Risks / notes
6.0.3(manifest, lockfile specifier/version, resolved entry) and the exactVersion 6.0.3output oftsc; a deliberate TypeScript bump must update the pin, the regenerated lockfile and this suite in the same change.pnpm execverifies the lockfile against the manifest before running (frozen in CI-like environments), so any pin drift fails the resolution test even beforetscruns — an extra guard, not a flake.Refs #162