[E00-S01-T13] Clean clone installs with frozen lockfile #380
No Reviewers
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#380
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What changed
Locks in the [E00-S01-T13] clean-clone frozen lockfile install (#166): a clean clone must install with
pnpm install --frozen-lockfile, and the frozen install must complete without resolving new versions.tests/frozen-install.test.mjs(new) — anode:testsuite (zero dependencies, lockfile untouched) that simulates a real clean clone and enforces both acceptance criteria:node_modules, no untracked files — exactly whatgit clonegives a new developer) and runscorepack pnpm install --frozen-lockfile(the pinned pnpm 11.23.0, the same path CI and the docs use);node_modules/.pnpmvirtual store;Lockfile is up to date, resolution step is skippedand thatpnpm-lock.yamlis byte-identical after the install (a frozen install never rewrites the lockfile);packages:entry is present innode_modules/.pnpm/<name>@<version>and nothing beyond the locked set is installed (no new versions resolved);corepack pnpm exec tsc --version), plus a non-vacuous probe of the lockfile→virtual-store helpers (scoped and peer-suffixed layouts).Explicitly out of scope per the brief (not touched): root build/test/typecheck commands (E00-S01-T12), no core imports a concrete extension (E00-S01-T14). No CI workflow changes — the existing CI job (frozen install +
pnpm -r liston Node 24) stays green and already runs the same frozen install on the PR head.Criterion → test table
tests/frozen-install.test.mjs: "a clean clone installs with a frozen lockfile (pnpm install --frozen-lockfile)" — clones the committed tree into a temp dir and runscorepack pnpm install --frozen-lockfile, asserting exit 0 and a populatednode_modules/.pnpm. Mutation-probed: a stale lockfile (manifest drift, e.g. adding a dependency without updatingpnpm-lock.yaml) makes the frozen install fail (specifiers in the lockfile don't match) → the suite failstests/frozen-install.test.mjs: "the frozen install completes without resolving new versions" — asserts pnpm skips the resolution step (Lockfile is up to date) and thatpnpm-lock.yamlis byte-identical before/after; "the installed dependency tree matches the lockfile exactly (no new versions)" — asserts every lockfilepackages:entry has itsnode_modules/.pnpm/<name>@<version>dir and the virtual store holds exactly the locked set; "the clean clone resolves the exact locked TypeScript version (6.0.3)"Test plan executed
node_modules), Node 24 (v24.20.0):pnpm install --frozen-lockfilevia corepack → success,Lockfile is up to date, resolution step is skipped,using pnpm v11.23.0, lockfile unchanged ✓node --test tests/frozen-install.test.mjs→ 5/5 pass (clean clone install, no-resolution checks, tree↔lockfile parity, tsc 6.0.3, non-vacuous probe) ✓node --test "tests/**/*.test.mjs"on Node 24 (v24.20.0) → 47/47 pass (42 pre-existing + 5 new), exit 0 ✓actions/checkoutstyle): running the suite from a--depth 1clone of the branch → 5/5 pass ✓left-pad@1.3.0to a clone'spackage.jsonwithout updating the lockfile →pnpm install --frozen-lockfileexits 1 (specifiers in the lockfile don't match specifiers in package.json) — the exact drift the suite must catch ✓Risks / notes
git clone+ one real frozen install per run (a few seconds with a warm pnpm store; the first run downloads into the store); it needsgit,corepackand registry access — the documented developer/CI prerequisites.@scope+name@version) and peer-suffixed (_peer@…) pnpm layout names so the check keeps working as dependencies grow.Lockfile is up to date, resolution step is skipped; pnpm is itself pinned to 11.23.0 viapackageManager, so the message is stable.Refs #166
Pull Request Review
This PR successfully implements the frozen lockfile installation test as described in issue #166. The implementation is thorough and well-designed.
Summary of Review
✅ Criterion → test mapping: All acceptance criteria are properly tested
✅ Scope: Remains within defined scope, no unrelated changes
✅ Correctness: Comprehensive test coverage with proper edge case handling
✅ Security: Follows security best practices, no hardcoded secrets
✅ Test honesty: Tests assert behavior accurately without weakened assertions
Detailed Findings
Recommendation
The implementation meets all requirements and is ready to be merged. The tests provide valuable validation of the workspace bootstrap process.