[E00-S03-T02] pg/Kysely imports isolated to database-postgres #391

Merged
kpcto merged 3 commits from feature/177 into main 2026-08-29 23:04:54 +00:00
Member

What changed

Implements [E00-S03-T02] pg/Kysely imports isolated to database-postgres (#177): the PostgreSQL driver (pg) and Kysely now live only in the new database-postgres package, and the isolation is locked in by a static scan with mutation probes and enforced in CI.

  • packages/database-postgres — new driver-owner package (@personal-blog/database-postgres): the single workspace package allowed to import the PostgreSQL driver. It declares the architecture doc's golden tuple (Technology-Stack §5.2 / §7) as exact dependencies — pg@8.22.0 and kysely@0.29.4 (@types/pg@8.21.0 for types — no 8.22.x of @types/pg is published, so 8.21.0, the closest matching release for the preceding pg minor, is pinned) — and its src/index.ts imports and re-exports the driver pieces (Pool, Kysely, PostgresDialect), so the isolation is real — the driver is reachable only from this boundary — not a placeholder. Rollback: remove the package and revert pnpm-lock.yaml.
  • pnpm-lock.yaml — importer + resolved driver tree: packages/database-postgres importer plus the locked pg/kysely/@types/pg dependency graph (generated by pnpm 11.23.0; pnpm install --frozen-lockfile passes). The resolved transitive pg tree (pg-connection-string 2.14.0, pg-pool 3.14.0, pg-protocol 1.16.0, pg-types 2.2.0, pgpass 1.0.5, pg-cloudflare 1.4.0) is unchanged between the old and new driver pins.
  • tests/database-postgres-imports.test.mjs — new suite locking in both acceptance criteria: a string/comment-aware static scan of every workspace package source proves that every pg/kysely import specifier (static import/export-from, dynamic import, require — incl. subpaths like pg/…, kysely/…) resolves to a file inside packages/database-postgres; the owner manifest pins the driver and no other package declares it. Mutation probes prove non-vacuousness: injecting import { Pool } from 'pg'; into apps/server/src/index.ts in a temp copy of the committed tree fails the scan, naming the file and the driver; a clean copy passes (probe sanity). Unit probes cover the specifier matcher and comment stripping.
  • Package-set fixtures updated: workspace-layout, workspace-config, strict-tsconfig and typescript-pin now include packages/database-postgres (layout ↔ lockfile parity, strict-base compile, pinned-TS resolution).
  • .gitea/workflows/ci.yml — new database-postgres-imports job runs node --test tests/database-postgres-imports.test.mjs on every PR, so the isolation criterion gates merges. (Note: this touches the CI workflow — pipeline tripwire, additive job, same action majors, no secrets: context, no untrusted interpolation; matches the merged precedent #390.)
  • docs/development/non-container.md — workspace package table and build expectations updated for the new package.

Review fix (finding #1 — golden-tuple pin alignment)

The previous head pinned pg@8.23.0 / kysely@0.29.5 / @types/pg@8.23.1; the architecture doc's golden tuple (Technology-Stack §5.2 runtime stack and §7 golden compatibility tuple) pins pg@8.22.0 and Kysely@0.29.4. This head corrects packages/database-postgres/package.json, regenerates pnpm-lock.yaml (pnpm 11.23.0), and updates the exact-pin assertions in tests/database-postgres-imports.test.mjs to the documented versions. @types/pg has no published 8.22.x; 8.21.0 (types for the immediately preceding pg minor) is the closest matching release.

Explicitly out of scope per the brief, not touched: PostgreSQL 18.6 container (E00-S03-T01), migration ledger (E00-S03-T03), advisory lock (E00-S03-T04).

Criterion → test table

Acceptance criterion Test (fails without the committed state)
pg/Kysely imports are isolated to database-postgres tests/database-postgres-imports.test.mjs — "packages/database-postgres exists, is the driver owner, and its source imports the driver" (manifest pins pg@8.22.0/kysely@0.29.4/@types/pg@8.21.0 exactly; src/index.ts imports both); "pg/Kysely imports are isolated to database-postgres in the real workspace" (scan of every workspace package source finds driver imports only under packages/database-postgres, and the owner really imports both drivers — non-vacuous); "comment stripping ignores commented-out driver imports (unit probe)"
no other package imports the database driver directly tests/database-postgres-imports.test.mjs — "no other package declares the database driver in its manifest" (only the owner's manifest lists pg/kysely); "the isolation scan catches a driver import injected into another package (mutation probe)" (inject import { Pool } from 'pg'; into apps/server/src/index.ts in a temp tree copy → scan fails naming the file and driver); "a copy of the committed tree without misplaced driver imports passes the scan (probe sanity)"; "the specifier matcher flags pg/kysely imports and ignores other packages (unit probe)"
the guarantee is enforced in CI tests/database-postgres-imports.test.mjs — "the isolation criterion is enforced in CI" (asserts the root test glob covers the suite and .gitea/workflows/ci.yml runs it); .gitea/workflows/ci.yml — database-postgres-imports job runs node --test tests/database-postgres-imports.test.mjs on every PR

Test plan executed

  • node --test tests/database-postgres-imports.test.mjs → pass.
  • Full suite (node --test "tests/**/*.test.mjs", Node 24.19.0 + pnpm 11.23.0, frozen install) → pass, zero failures.
  • pnpm install --frozen-lockfile on the corrected lockfile → passes ("Lockfile is up to date"); pnpm build / pnpm typecheck over the 4-package workspace → exit 0.

Risks / notes

  • pg/kysely/@types/pg are pinned to exact versions matching the documented golden tuple (repo policy, same as typescript@6.0.3); the lockfile carries the full resolved driver tree so --frozen-lockfile stays reproducible.
  • The pg optional dependency pg-cloudflare installs on standard linux/x64 CI runners (no platform gate); the frozen-install "exact tree" assertion counts it in both lockfile and virtual store.
  • The driver boundary re-exports (Pool, Kysely, PostgresDialect) are the surface later stories (migration ledger T03, advisory lock T04) build the adapter on; until then nothing else in the workspace imports the driver.
  • CI workflow change is strictly additive (new job, no existing job modified) and matches the security-reviewed #390 precedent; per the review-checklist pipeline tripwire a human decision on the new merge gate may be requested.

Refs #177

## What changed Implements [E00-S03-T02] pg/Kysely imports isolated to database-postgres (#177): the PostgreSQL driver (`pg`) and Kysely now live **only** in the new `database-postgres` package, and the isolation is locked in by a static scan with mutation probes and enforced in CI. - **`packages/database-postgres` — new driver-owner package** (`@personal-blog/database-postgres`): the single workspace package allowed to import the PostgreSQL driver. It declares the architecture doc's golden tuple (Technology-Stack §5.2 / §7) as exact dependencies — `pg@8.22.0` and `kysely@0.29.4` (`@types/pg@8.21.0` for types — no `8.22.x` of `@types/pg` is published, so `8.21.0`, the closest matching release for the preceding pg minor, is pinned) — and its `src/index.ts` **imports and re-exports** the driver pieces (`Pool`, `Kysely`, `PostgresDialect`), so the isolation is real — the driver is reachable only from this boundary — not a placeholder. Rollback: remove the package and revert `pnpm-lock.yaml`. - **`pnpm-lock.yaml` — importer + resolved driver tree**: `packages/database-postgres` importer plus the locked `pg`/`kysely`/`@types/pg` dependency graph (generated by pnpm 11.23.0; `pnpm install --frozen-lockfile` passes). The resolved transitive pg tree (pg-connection-string 2.14.0, pg-pool 3.14.0, pg-protocol 1.16.0, pg-types 2.2.0, pgpass 1.0.5, pg-cloudflare 1.4.0) is unchanged between the old and new driver pins. - **`tests/database-postgres-imports.test.mjs` — new suite locking in both acceptance criteria**: a string/comment-aware static scan of every workspace package source proves that every `pg`/`kysely` import specifier (static import/export-from, dynamic import, require — incl. subpaths like `pg/…`, `kysely/…`) resolves to a file inside `packages/database-postgres`; the owner manifest pins the driver and **no other package declares it**. **Mutation probes prove non-vacuousness**: injecting `import { Pool } from 'pg';` into `apps/server/src/index.ts` in a temp copy of the committed tree fails the scan, naming the file and the driver; a clean copy passes (probe sanity). Unit probes cover the specifier matcher and comment stripping. - **Package-set fixtures updated**: `workspace-layout`, `workspace-config`, `strict-tsconfig` and `typescript-pin` now include `packages/database-postgres` (layout ↔ lockfile parity, strict-base compile, pinned-TS resolution). - **`.gitea/workflows/ci.yml` — new `database-postgres-imports` job** runs `node --test tests/database-postgres-imports.test.mjs` on every PR, so the isolation criterion gates merges. (Note: this touches the CI workflow — pipeline tripwire, additive job, same action majors, no `secrets:` context, no untrusted interpolation; matches the merged precedent #390.) - **`docs/development/non-container.md`** — workspace package table and build expectations updated for the new package. ### Review fix (finding #1 — golden-tuple pin alignment) The previous head pinned `pg@8.23.0` / `kysely@0.29.5` / `@types/pg@8.23.1`; the architecture doc's golden tuple (Technology-Stack §5.2 runtime stack and §7 golden compatibility tuple) pins **`pg@8.22.0`** and **Kysely@0.29.4**. This head corrects `packages/database-postgres/package.json`, regenerates `pnpm-lock.yaml` (pnpm 11.23.0), and updates the exact-pin assertions in `tests/database-postgres-imports.test.mjs` to the documented versions. `@types/pg` has no published `8.22.x`; `8.21.0` (types for the immediately preceding pg minor) is the closest matching release. Explicitly out of scope per the brief, **not touched**: PostgreSQL 18.6 container (E00-S03-T01), migration ledger (E00-S03-T03), advisory lock (E00-S03-T04). ## Criterion → test table | Acceptance criterion | Test (fails without the committed state) | | --- | --- | | `pg`/Kysely imports are isolated to `database-postgres` | `tests/database-postgres-imports.test.mjs` — **"packages/database-postgres exists, is the driver owner, and its source imports the driver"** (manifest pins `pg@8.22.0`/`kysely@0.29.4`/`@types/pg@8.21.0` exactly; `src/index.ts` imports both); **"pg/Kysely imports are isolated to database-postgres in the real workspace"** (scan of every workspace package source finds driver imports **only** under `packages/database-postgres`, and the owner really imports both drivers — non-vacuous); **"comment stripping ignores commented-out driver imports (unit probe)"** | | no other package imports the database driver directly | `tests/database-postgres-imports.test.mjs` — **"no other package declares the database driver in its manifest"** (only the owner's manifest lists `pg`/`kysely`); **"the isolation scan catches a driver import injected into another package (mutation probe)"** (inject `import { Pool } from 'pg';` into `apps/server/src/index.ts` in a temp tree copy → scan fails naming the file and driver); **"a copy of the committed tree without misplaced driver imports passes the scan (probe sanity)"**; **"the specifier matcher flags pg/kysely imports and ignores other packages (unit probe)"** | | the guarantee is enforced in CI | `tests/database-postgres-imports.test.mjs` — **"the isolation criterion is enforced in CI"** (asserts the root test glob covers the suite and `.gitea/workflows/ci.yml` runs it); `.gitea/workflows/ci.yml` — **`database-postgres-imports` job** runs `node --test tests/database-postgres-imports.test.mjs` on every PR | ## Test plan executed - `node --test tests/database-postgres-imports.test.mjs` → pass. - Full suite (`node --test "tests/**/*.test.mjs"`, Node 24.19.0 + pnpm 11.23.0, frozen install) → pass, zero failures. - `pnpm install --frozen-lockfile` on the corrected lockfile → passes ("Lockfile is up to date"); `pnpm build` / `pnpm typecheck` over the 4-package workspace → exit 0. ## Risks / notes - `pg`/`kysely`/`@types/pg` are pinned to exact versions matching the documented golden tuple (repo policy, same as `typescript@6.0.3`); the lockfile carries the full resolved driver tree so `--frozen-lockfile` stays reproducible. - The `pg` optional dependency `pg-cloudflare` installs on standard linux/x64 CI runners (no platform gate); the frozen-install "exact tree" assertion counts it in both lockfile and virtual store. - The driver boundary re-exports (`Pool`, `Kysely`, `PostgresDialect`) are the surface later stories (migration ledger T03, advisory lock T04) build the adapter on; until then nothing else in the workspace imports the driver. - CI workflow change is strictly additive (new job, no existing job modified) and matches the security-reviewed #390 precedent; per the review-checklist pipeline tripwire a human decision on the new merge gate may be requested. Refs #177
bot-implementer added 2 commits 2026-08-29 11:15:14 +00:00
- packages/database-postgres (@personal-blog/database-postgres): the single
  workspace package allowed to import the PostgreSQL driver — declares pg and
  kysely as exact dependencies (@types/pg for types) and its src/index.ts
  imports and re-exports the driver pieces (Pool, Kysely, PostgresDialect) so
  the isolation is real, not a placeholder
- pnpm-lock.yaml: importer for packages/database-postgres plus the resolved
  pg/kysely dependency tree (frozen-lockfile install keeps working)
- .gitea/workflows/ci.yml: new database-postgres-imports job runs
  tests/database-postgres-imports.test.mjs on every PR so the isolation
  criterion gates merges
test: lock in pg/Kysely import isolation to database-postgres (E00-S03-T02)
CI / Frozen lockfile install (pull_request) Successful in 43s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 30s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 31s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 24s
97c5306768
- database-postgres-imports.test.mjs: static scan of every workspace package
  source proves pg/kysely import specifiers resolve only to
  packages/database-postgres; owner manifest pins the driver and no other
  package declares it; mutation probes prove the scan catches a driver import
  injected into apps/server/src/index.ts; comment-stripping and specifier
  matcher unit probes; CI-enforcement assertion
- workspace-layout / workspace-config / strict-tsconfig / typescript-pin:
  package-set fixtures updated to include packages/database-postgres
- docs/development/non-container.md: workspace package table and build
  expectations updated for the new package
Member
agent: tester
phase: start
issue: "177"
pr: "391"
objective: "independently probe the PR for #177"
acceptance:
  - "pg/Kysely imports are isolated to database-postgres"
  - "no other package imports the database driver directly"
constraints:
  - "never edit the implementer's tests in the same PR"
scope_files: []
method:
  - "static scan: locate every pg/kysely import specifier across the workspace"
  - "verify driver-owner manifest (packages/database-postgres) and no other package declares pg/kysely"
  - "independently run the isolation test suite (node --test) + frozen-install check"
  - "verify CI job definition and run status; collect CI links"
```yaml agent: tester phase: start issue: "177" pr: "391" objective: "independently probe the PR for #177" acceptance: - "pg/Kysely imports are isolated to database-postgres" - "no other package imports the database driver directly" constraints: - "never edit the implementer's tests in the same PR" scope_files: [] method: - "static scan: locate every pg/kysely import specifier across the workspace" - "verify driver-owner manifest (packages/database-postgres) and no other package declares pg/kysely" - "independently run the isolation test suite (node --test) + frozen-install check" - "verify CI job definition and run status; collect CI links" ```
Member
agent: tester
phase: complete
issue: "177"
pr: "391"
head_sha: "97c530676844779297247650aa92f1d6a54c70b6"
verdict: pass
acceptance:
  - criterion: "pg/Kysely imports are isolated to database-postgres"
    result: pass
    evidence: "independent grep over apps/, packages/, extensions/ (sources + manifests) — the only driver import site is packages/database-postgres/src/index.ts (import { Pool } from 'pg'; import { Kysely, PostgresDialect } from 'kysely';). Owner manifest pins pg@8.23.0, kysely@0.29.5, @types/pg@8.23.1 exactly. Isolation is non-vacuous: the owner really imports both drivers."
  - criterion: "no other package imports the database driver directly"
    result: pass
    evidence: "zero pg/kysely/@types/pg references outside packages/database-postgres across all package sources and manifests. Independent mutation probe: injecting `import { Pool } from 'pg';` into apps/server/src/index.ts in a temp tree is caught immediately by a plain grep (line 1)."
tests:
  - "node --test tests/database-postgres-imports.test.mjs -> 8 pass / 0 fail / 0 skip (independent local run)"
  - "full suite node --test 'tests/**/*.test.mjs' -> 110 pass / 12 fail / 9 skip; ALL 12 failures are environmental (local Node v22.23.2 vs required 24.x + deps never installed -> frozen-install / tsc / typecheck probes fail), none relate to this PR; the isolation suite itself passes 8/8"
ci:
  run: "http://gitea:3000/Fabrika/PersonalBlog/actions/runs/82"
  status: success
  jobs:
    - "Frozen lockfile install -> success (job 101)"
    - "Secrets not embedded (E00-S02-T08) -> success (job 102)"
    - "Database-postgres import isolation (E00-S03-T02) -> success (job 103)"
    - "Compose config (E00-S03-T01) -> success (job 104)"
constraints:
  - "never edit the implementer's tests in the same PR -> respected (read-only review; temp copies confined to /tmp)"
notes:
  - "Scan surface (tests/database-postgres-imports.test.mjs collectSourceFiles) walks apps/, packages/, extensions/ only; root-level and tests/ files sit outside the scan, but the acceptance criterion concerns packages, so this is acceptable and not blocking."
```yaml agent: tester phase: complete issue: "177" pr: "391" head_sha: "97c530676844779297247650aa92f1d6a54c70b6" verdict: pass acceptance: - criterion: "pg/Kysely imports are isolated to database-postgres" result: pass evidence: "independent grep over apps/, packages/, extensions/ (sources + manifests) — the only driver import site is packages/database-postgres/src/index.ts (import { Pool } from 'pg'; import { Kysely, PostgresDialect } from 'kysely';). Owner manifest pins pg@8.23.0, kysely@0.29.5, @types/pg@8.23.1 exactly. Isolation is non-vacuous: the owner really imports both drivers." - criterion: "no other package imports the database driver directly" result: pass evidence: "zero pg/kysely/@types/pg references outside packages/database-postgres across all package sources and manifests. Independent mutation probe: injecting `import { Pool } from 'pg';` into apps/server/src/index.ts in a temp tree is caught immediately by a plain grep (line 1)." tests: - "node --test tests/database-postgres-imports.test.mjs -> 8 pass / 0 fail / 0 skip (independent local run)" - "full suite node --test 'tests/**/*.test.mjs' -> 110 pass / 12 fail / 9 skip; ALL 12 failures are environmental (local Node v22.23.2 vs required 24.x + deps never installed -> frozen-install / tsc / typecheck probes fail), none relate to this PR; the isolation suite itself passes 8/8" ci: run: "http://gitea:3000/Fabrika/PersonalBlog/actions/runs/82" status: success jobs: - "Frozen lockfile install -> success (job 101)" - "Secrets not embedded (E00-S02-T08) -> success (job 102)" - "Database-postgres import isolation (E00-S03-T02) -> success (job 103)" - "Compose config (E00-S03-T01) -> success (job 104)" constraints: - "never edit the implementer's tests in the same PR -> respected (read-only review; temp copies confined to /tmp)" notes: - "Scan surface (tests/database-postgres-imports.test.mjs collectSourceFiles) walks apps/, packages/, extensions/ only; root-level and tests/ files sit outside the scan, but the acceptance criterion concerns packages, so this is acceptable and not blocking." ```
Author
Member
agent: implementer
phase: start
issue: 177
pr: 391
head_branch: feature/177
base_sha: 797a1b8dc2b928c5b4f70961339d169f3c3c9bc2
head_sha: 97c530676844779297247650aa92f1d6a54c70b6
summary: |
  Implementing review finding #1 on PR #391: the committed driver pins in
  packages/database-postgres/package.json deviate from the architecture doc
  golden tuple (Technology-Stack section 5.2 / section 7 pins pg 8.22.0 and
  Kysely 0.29.4). Plan: correct the pins, regenerate pnpm-lock.yaml with
  pnpm 11.23.0, update the exact-pin assertions in
  tests/database-postgres-imports.test.mjs, run the full suite under
  Node 24.19.0, then push and confirm CI green.
tasks:
  - id: 1
    what: "Set packages/database-postgres/package.json dependencies to pg@8.22.0, kysely@0.29.4; align @types/pg to the 8.22.x release if published, otherwise closest matching"
  - id: 2
    what: "Regenerate pnpm-lock.yaml with pnpm 11.23.0 (Node 24)"
  - id: 3
    what: "Update exact-pin assertions in tests/database-postgres-imports.test.mjs to the corrected versions"
  - id: 4
    what: "Run the full test suite (Node 24.19.0 + pnpm 11.23.0, frozen install); push to feature/177; confirm CI green on PR #391"
```yaml agent: implementer phase: start issue: 177 pr: 391 head_branch: feature/177 base_sha: 797a1b8dc2b928c5b4f70961339d169f3c3c9bc2 head_sha: 97c530676844779297247650aa92f1d6a54c70b6 summary: | Implementing review finding #1 on PR #391: the committed driver pins in packages/database-postgres/package.json deviate from the architecture doc golden tuple (Technology-Stack section 5.2 / section 7 pins pg 8.22.0 and Kysely 0.29.4). Plan: correct the pins, regenerate pnpm-lock.yaml with pnpm 11.23.0, update the exact-pin assertions in tests/database-postgres-imports.test.mjs, run the full suite under Node 24.19.0, then push and confirm CI green. tasks: - id: 1 what: "Set packages/database-postgres/package.json dependencies to pg@8.22.0, kysely@0.29.4; align @types/pg to the 8.22.x release if published, otherwise closest matching" - id: 2 what: "Regenerate pnpm-lock.yaml with pnpm 11.23.0 (Node 24)" - id: 3 what: "Update exact-pin assertions in tests/database-postgres-imports.test.mjs to the corrected versions" - id: 4 what: "Run the full test suite (Node 24.19.0 + pnpm 11.23.0, frozen install); push to feature/177; confirm CI green on PR #391" ```
bot-implementer added 1 commit 2026-08-29 11:28:32 +00:00
fix: pin database-postgres driver to the golden tuple (pg 8.22.0, Kysely 0.29.4)
CI / Frozen lockfile install (pull_request) Successful in 46s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 35s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 25s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 31s
09b7a40d00
Review finding on PR #391: packages/database-postgres pinned pg@8.23.0 and
kysely@0.29.5, but the architecture doc's golden tuple (Technology-Stack
section 5.2 / section 7) pins pg@8.22.0 and Kysely@0.29.4. Reproducibility
requires the exact documented versions.

- packages/database-postgres/package.json: pg 8.23.0 -> 8.22.0,
  kysely 0.29.5 -> 0.29.4, @types/pg 8.23.1 -> 8.21.0 (no 8.22.x of
  @types/pg is published; 8.21.0 is the closest matching release, types
  for the immediately preceding pg minor)
- pnpm-lock.yaml: regenerated with pnpm 11.23.0 (Node 24); the resolved
  pg dependency tree is unchanged apart from the driver version itself
- tests/database-postgres-imports.test.mjs: exact-pin assertions updated
  to the corrected versions, with a comment noting the @types/pg choice
Author
Member
agent: implementer
phase: end
issue: 177
pr: 391
head_branch: feature/177
base_sha: 797a1b8dc2b928c5b4f70961339d169f3c3c9bc2
head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa
status: done
summary: |
  Review finding #1 resolved: the driver pins now match the architecture doc
  golden tuple exactly. packages/database-postgres/package.json pins
  pg@8.22.0 and kysely@0.29.4 (Technology-Stack section 5.2 / section 7);
  @types/pg is 8.21.0 — no 8.22.x of @types/pg is published, so the closest
  matching release (types for the immediately preceding pg minor) is pinned.
  pnpm-lock.yaml was regenerated with pnpm 11.23.0 (Node 24.19.0); the
  resolved transitive pg tree is unchanged apart from the driver version
  itself. Exact-pin assertions in tests/database-postgres-imports.test.mjs
  were updated to the corrected versions with an explanatory comment.
findings:
  - id: 1
    severity: should
    status: fixed
    evidence: |
      package.json: "pg": "8.22.0", "kysely": "0.29.4",
      "@types/pg": "8.21.0"; lockfile importer and packages/snapshots
      resolved to those versions; test assertions updated and passing.
verification:
  - full_suite: "131 tests, 122 pass, 0 fail, 9 skip (Docker-gated probes + nested root-command guard) under Node 24.19.0 + pnpm 11.23.0"
  - isolation_suite: "8/8 pass incl. corrected exact-pin assertions"
  - frozen_install: "5/5 pass — clean-clone `pnpm install --frozen-lockfile` on the corrected lockfile, byte-identical, exact virtual-store tree"
  - ci_run: "run #83 on head 09b7a40 — success (frozen-install, secrets-not-embedded, database-postgres-imports, compose-config)"
acceptance:
  - "pg/Kysely imports are isolated to database-postgres" -> "tests/database-postgres-imports.test.mjs (scan + manifest + mutation probes)"
  - "no other package imports the database driver directly" -> "tests/database-postgres-imports.test.mjs (manifest scan + injection probe)"
  - "PR open, CI green, criterion→test table in description" -> "PR #391 open, run #83 green, table updated in description"
```yaml agent: implementer phase: end issue: 177 pr: 391 head_branch: feature/177 base_sha: 797a1b8dc2b928c5b4f70961339d169f3c3c9bc2 head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa status: done summary: | Review finding #1 resolved: the driver pins now match the architecture doc golden tuple exactly. packages/database-postgres/package.json pins pg@8.22.0 and kysely@0.29.4 (Technology-Stack section 5.2 / section 7); @types/pg is 8.21.0 — no 8.22.x of @types/pg is published, so the closest matching release (types for the immediately preceding pg minor) is pinned. pnpm-lock.yaml was regenerated with pnpm 11.23.0 (Node 24.19.0); the resolved transitive pg tree is unchanged apart from the driver version itself. Exact-pin assertions in tests/database-postgres-imports.test.mjs were updated to the corrected versions with an explanatory comment. findings: - id: 1 severity: should status: fixed evidence: | package.json: "pg": "8.22.0", "kysely": "0.29.4", "@types/pg": "8.21.0"; lockfile importer and packages/snapshots resolved to those versions; test assertions updated and passing. verification: - full_suite: "131 tests, 122 pass, 0 fail, 9 skip (Docker-gated probes + nested root-command guard) under Node 24.19.0 + pnpm 11.23.0" - isolation_suite: "8/8 pass incl. corrected exact-pin assertions" - frozen_install: "5/5 pass — clean-clone `pnpm install --frozen-lockfile` on the corrected lockfile, byte-identical, exact virtual-store tree" - ci_run: "run #83 on head 09b7a40 — success (frozen-install, secrets-not-embedded, database-postgres-imports, compose-config)" acceptance: - "pg/Kysely imports are isolated to database-postgres" -> "tests/database-postgres-imports.test.mjs (scan + manifest + mutation probes)" - "no other package imports the database driver directly" -> "tests/database-postgres-imports.test.mjs (manifest scan + injection probe)" - "PR open, CI green, criterion→test table in description" -> "PR #391 open, run #83 green, table updated in description" ```
Member
agent: tester
phase: start
issue: 177
pr: 391
head_branch: feature/177
head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa
summary: |
  Independent probe of PR #391 starting. Plan:
  (1) golden-tuple pin alignment — verify packages/database-postgres pins
      pg@8.22.0 / kysely@0.29.4 (@types/pg closest match) against the
      architecture doc (Architecture §7 / Technology-Stack §5.2);
  (2) import isolation — verify pg/Kysely imports + manifest declarations live
      only in packages/database-postgres, and that the scan is non-vacuous
      (mutation probes);
  (3) CI enforcement — confirm the database-postgres-imports job gates every PR.
  Will post an evidence comment with CI links on completion.
```yaml agent: tester phase: start issue: 177 pr: 391 head_branch: feature/177 head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa summary: | Independent probe of PR #391 starting. Plan: (1) golden-tuple pin alignment — verify packages/database-postgres pins pg@8.22.0 / kysely@0.29.4 (@types/pg closest match) against the architecture doc (Architecture §7 / Technology-Stack §5.2); (2) import isolation — verify pg/Kysely imports + manifest declarations live only in packages/database-postgres, and that the scan is non-vacuous (mutation probes); (3) CI enforcement — confirm the database-postgres-imports job gates every PR. Will post an evidence comment with CI links on completion. ```
Member
agent: tester
phase: end
issue: 177
pr: 391
head_branch: feature/177
head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa
verdict: pass
summary: |
  Independent probe complete. The previous reviewer finding #1 (golden-tuple pin
  drift: pg@8.23.0 / kysely@0.29.5) is resolved in this head, and both
  acceptance criteria hold.

evidence:
  - id: golden-tuple-pins
    what: |
      packages/database-postgres/package.json pins dependencies pg@8.22.0 and
      kysely@0.29.4, and devDependency @types/pg@8.21.0 — exactly matching the
      architecture doc: Technology-Stack §5.2 runtime stack (pg 8.22.0, Kysely
      0.29.4) and §7 golden compatibility tuple (pg 8.22.0, Kysely 0.29.4).
      @types/pg has no published 8.22.x, so 8.21.0 (closest preceding minor) is
      the correct closest match. pnpm-lock.yaml importer + resolved tree agree
      (pg@8.22.0, kysely@0.29.4, @types/pg@8.21.0).
  - id: import-isolation
    what: |
      Static scan of apps/, packages/, extensions/ finds pg/kysely imports only
      in packages/database-postgres/src/index.ts (imports + re-exports Pool,
      Kysely, PostgresDialect). No other workspace manifest declares
      pg/kysely/@types/pg. tests/database-postgres-imports.test.mjs passes 8/8
      locally (node --test, Node v22.23.2), including the mutation probe
      (a driver import injected into apps/server is caught, naming file + driver)
      and the probe-sanity check (clean copy passes) — the scan is non-vacuous.
  - id: ci-enforcement
    what: |
      .gitea/workflows/ci.yml adds a database-postgres-imports job that runs
      `node --test tests/database-postgres-imports.test.mjs` on every PR, so the
      isolation criterion gates merges. CI run #83 (head 09b7a40…) is green with
      that job succeeding.

ci_links:
  - run: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/83
  - isolation-job: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/83/jobs/107

findings: []
```yaml agent: tester phase: end issue: 177 pr: 391 head_branch: feature/177 head_sha: 09b7a40d007c4575ca52f05ef2a53dc34a190eaa verdict: pass summary: | Independent probe complete. The previous reviewer finding #1 (golden-tuple pin drift: pg@8.23.0 / kysely@0.29.5) is resolved in this head, and both acceptance criteria hold. evidence: - id: golden-tuple-pins what: | packages/database-postgres/package.json pins dependencies pg@8.22.0 and kysely@0.29.4, and devDependency @types/pg@8.21.0 — exactly matching the architecture doc: Technology-Stack §5.2 runtime stack (pg 8.22.0, Kysely 0.29.4) and §7 golden compatibility tuple (pg 8.22.0, Kysely 0.29.4). @types/pg has no published 8.22.x, so 8.21.0 (closest preceding minor) is the correct closest match. pnpm-lock.yaml importer + resolved tree agree (pg@8.22.0, kysely@0.29.4, @types/pg@8.21.0). - id: import-isolation what: | Static scan of apps/, packages/, extensions/ finds pg/kysely imports only in packages/database-postgres/src/index.ts (imports + re-exports Pool, Kysely, PostgresDialect). No other workspace manifest declares pg/kysely/@types/pg. tests/database-postgres-imports.test.mjs passes 8/8 locally (node --test, Node v22.23.2), including the mutation probe (a driver import injected into apps/server is caught, naming file + driver) and the probe-sanity check (clean copy passes) — the scan is non-vacuous. - id: ci-enforcement what: | .gitea/workflows/ci.yml adds a database-postgres-imports job that runs `node --test tests/database-postgres-imports.test.mjs` on every PR, so the isolation criterion gates merges. CI run #83 (head 09b7a40…) is green with that job succeeding. ci_links: - run: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/83 - isolation-job: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/83/jobs/107 findings: [] ```
kpcto merged commit 33ac04e795 into main 2026-08-29 23:04:54 +00:00
kpcto deleted branch feature/177 2026-08-29 23:04:55 +00:00
Sign in to join this conversation.