diff --git a/Technology-Stack.-.md b/Technology-Stack.-.md new file mode 100644 index 0000000..4c892dc --- /dev/null +++ b/Technology-Stack.-.md @@ -0,0 +1,58 @@ +# Technology stack + +Researched 2026-08-26. Three support classes (§5.1): **A** = fixed upstream EOL date; **B** = documented support policy, no fixed multi-year date; **C** = rolling, exact-pinned + tested + upgraded deliberately. + +## Runtime stack (§5.2) + +| Layer | Version | Class | +|---|---|---| +| Node.js | 24.19.0 LTS (Krypton) | A | +| TypeScript | 6.0.3 | C | +| Fastify | 5.12.1 | B | +| PostgreSQL | 18.6 | A | +| `pg` | 8.22.0 | C | +| Kysely | 0.29.4 | C | +| React / React DOM | 19.2.8 | C | +| `@sinclair/typebox` | 0.34.52 | project-designated LTS | +| Ajv | 8.20.0 | C | +| Pino | 10.3.1 | B | +| `argon2` | 0.45.1 | C | +| `@fastify/cookie` / `helmet` / `rate-limit` / `static` / `csrf-protection` / `swagger` | 11.1.2 / 13.1.1 / 11.2.0 / 10.1.3 / 8.0.1 / 9.8.1 | Fastify lifecycle | +| `@fastify/multipart` | 10.1.1 | C/ecosystem (CI gate before enabling) | + +## v1.1 verification note (§5.2.1) + +An independent re-check on 2026-08-27 found: **TypeScript verified correct** (7.0 GA'd 2026-07-08 without a stable programmatic API before 7.1; 6.0 is the bridge). **PostgreSQL "18.6" could not be confirmed** — postgresql.org shows 18.3 (2026-02-26) with quarterly minors, placing late August at 18.4/18.5. Sprint 0 re-runs the provenance table (§74) and commits the re-verified tuple. A "verified" pin is trusted for one sprint, not the life of the document. + +## Build/admin/test toolchain (§5.3) + +Vite 8.2.2 · `@vitejs/plugin-react` 6.1.0 · pnpm 11.23.0 · Vitest 4.1.10 · Playwright 1.62.1 · Docker Engine 29.7.2 (CI ref) · Docker Compose 5.5.0 (CI ref) · Caddy 2.11.4 (optional). + +## Golden compatibility tuple (§7) + +Every release candidate must pass the full integration suite on: Node 24.19.0, TypeScript 6.0.3, Fastify 5.12.1, PostgreSQL 18.6, pg 8.22.0, Kysely 0.29.4, React/React DOM 19.2.8, TypeBox 0.34.52, Ajv 8.20.0, Pino 10.3.1. Certified container platforms: `linux/amd64`, `linux/arm64`. Playwright runs Chromium, Firefox, WebKit. + +## Container image pins (§5.4) + +```text +node:24.19.0-bookworm-slim # application (glibc → argon2 native deps) +postgres:18.6-bookworm +caddy:2.11.4-alpine # optional edge profile +``` + +Release automation records immutable image digests in an SBOM/release manifest. + +## Version discipline (§8) + +Direct platform dependencies are exact-pinned in release branches; the lockfile is committed; no caret ranges for core runtime/build deps. `packageManager: pnpm@11.23.0`, `engines.node: 24.x`. + +Update lanes: **Security emergency** (immediate, focused + full CI) · **Patch** (weekly batch) · **Minor** (monthly review) · **Major** (explicit programme item: ADR + migration/compatibility). + +## LTS strategy (§6) + +- **Node 24** EOL 2028-04-30; evaluate Node 26 only after it is LTS + compatibility CI passes; major change requires ADR. +- **PostgreSQL 18** supported to 2030-11-14; always run current minor; major upgrade is a separate operator procedure. +- **Fastify 5** — no fixed EOL claimed; upgrade to v6 gated on: stable v6, all plugins compatible, full suite green, extension contracts stable/migrated, ADR. +- **React** — exact-pinned 19.2.8, no RSC in v1, kept out of persisted content formats. +- **TypeScript** — 6.0.3 baseline, formal review after TS 7.1 stable. +- **Kysely** — pre-1.0, contained inside the PostgreSQL adapter; domain/extension packages never import it.