3.3 KiB
Technology stack
Researched 2026-08-26. Three support classes (§5.1): A = fixed upstream EOL date; B = documented support policy, no fixed multi-year date; C = rolling, exact-pinned + tested + upgraded deliberately.
Runtime stack (§5.2)
| Layer | Version | Class |
|---|---|---|
| Node.js | 24.19.0 LTS (Krypton) | A |
| TypeScript | 6.0.3 | C |
| Fastify | 5.12.1 | B |
| PostgreSQL | 18.6 | A |
pg |
8.22.0 | C |
| Kysely | 0.29.4 | C |
| React / React DOM | 19.2.8 | C |
@sinclair/typebox |
0.34.52 | project-designated LTS |
| Ajv | 8.20.0 | C |
| Pino | 10.3.1 | B |
argon2 |
0.45.1 | C |
@fastify/cookie / helmet / rate-limit / static / csrf-protection / swagger |
11.1.2 / 13.1.1 / 11.2.0 / 10.1.3 / 8.0.1 / 9.8.1 | Fastify lifecycle |
@fastify/multipart |
10.1.1 | C/ecosystem (CI gate before enabling) |
v1.1 verification note (§5.2.1)
An independent re-check on 2026-08-27 found: TypeScript verified correct (7.0 GA'd 2026-07-08 without a stable programmatic API before 7.1; 6.0 is the bridge). PostgreSQL "18.6" could not be confirmed — postgresql.org shows 18.3 (2026-02-26) with quarterly minors, placing late August at 18.4/18.5. Sprint 0 re-runs the provenance table (§74) and commits the re-verified tuple. A "verified" pin is trusted for one sprint, not the life of the document.
Build/admin/test toolchain (§5.3)
Vite 8.2.2 · @vitejs/plugin-react 6.1.0 · pnpm 11.23.0 · Vitest 4.1.10 · Playwright 1.62.1 · Docker Engine 29.7.2 (CI ref) · Docker Compose 5.5.0 (CI ref) · Caddy 2.11.4 (optional).
Golden compatibility tuple (§7)
Every release candidate must pass the full integration suite on: Node 24.19.0, TypeScript 6.0.3, Fastify 5.12.1, PostgreSQL 18.6, pg 8.22.0, Kysely 0.29.4, React/React DOM 19.2.8, TypeBox 0.34.52, Ajv 8.20.0, Pino 10.3.1. Certified container platforms: linux/amd64, linux/arm64. Playwright runs Chromium, Firefox, WebKit.
Container image pins (§5.4)
node:24.19.0-bookworm-slim # application (glibc → argon2 native deps)
postgres:18.6-bookworm
caddy:2.11.4-alpine # optional edge profile
Release automation records immutable image digests in an SBOM/release manifest.
Version discipline (§8)
Direct platform dependencies are exact-pinned in release branches; the lockfile is committed; no caret ranges for core runtime/build deps. packageManager: pnpm@11.23.0, engines.node: 24.x.
Update lanes: Security emergency (immediate, focused + full CI) · Patch (weekly batch) · Minor (monthly review) · Major (explicit programme item: ADR + migration/compatibility).
LTS strategy (§6)
- Node 24 EOL 2028-04-30; evaluate Node 26 only after it is LTS + compatibility CI passes; major change requires ADR.
- PostgreSQL 18 supported to 2030-11-14; always run current minor; major upgrade is a separate operator procedure.
- Fastify 5 — no fixed EOL claimed; upgrade to v6 gated on: stable v6, all plugins compatible, full suite green, extension contracts stable/migrated, ADR.
- React — exact-pinned 19.2.8, no RSC in v1, kept out of persisted content formats.
- TypeScript — 6.0.3 baseline, formal review after TS 7.1 stable.
- Kysely — pre-1.0, contained inside the PostgreSQL adapter; domain/extension packages never import it.