Skip to content

deps: take the 2026-10 production-dependency group without the better-auth family (replaces Dependabot #21029) #21094

Description

@objectstack-fleet

Filing-gate class: ③ maintainer-directed task.
Body last written 2026-10-01T09:03Z: the serial wait on #21102 is over (#21024 merged as 840ec9d; #21102 closed completed).
Acting reader: the triage seat grades this card (domain / area / priority); the lane seat it names dispatches one os-dev.
Dedup: repo:objectstack-ai/objectstack is:issue "21029" OR "production-dependencies" OR "@libsql/client@0.18", open and closed: 160 hits by relevance; the only one in scope is #21055 (the next + dompurify OSV fix), which this card deliberately excludes. No card exists for this group.
Filed by: PM seat, session session_018gA1pE6eJtwHhqx72G8U9X.

Maintainer ruling (verbatim)

按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地

Given in session session_018gA1pE6eJtwHhqx72G8U9X on 2026-10-01, in reply to the seat's risk read of #21024 and #21029. The recommendation it accepts: close #21029, carry its safe part on this card, and leave the better-auth family where it is.

What to land

Dependabot's #21029 (closed in favour of this card) bumped 27 production dependencies. Take them, with these exceptions and corrections.

  1. better-auth family: excluded. better-auth, @better-auth/core, @better-auth/oauth-provider, @better-auth/scim and @better-auth/sso stay at 1.7.3 in packages/plugins/plugin-auth/package.json, and the family's override targets in pnpm-workspace.yaml stay untouched. A lift is a separate reviewed edit (see the overrides note in pnpm-workspace.yaml, bug(plugin-auth): published 17.1.0/17.2.0/17.3.0 float @better-auth/core to 1.7.3, which dropped createLocalAccountIssuer — a fresh objectstack dev --seed-admin never creates the system tables and never seeds #16186), and the maintainer deferred it.
  2. next: excluded. [finding] main's lockfile carries two new OSV advisories (next 16.3.3 GHSA-vcvr-r3jv-pc5j, critical; dompurify 3.4.13): the scheduled scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21055 owns raising apps/docs's next to 16.3.6 or later. If [finding] main's lockfile carries two new OSV advisories (next 16.3.3 GHSA-vcvr-r3jv-pc5j, critical; dompurify 3.4.13): the scheduled scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21055 merges first, merge main and leave next alone.
  3. Lockfile: regenerate it with the repo's tooling, never by hand.
  4. @libsql/client 0.17.x to 0.18.x: a ruling gated on a premise.
    • Ruling: lift packages/drivers/driver-turso to ^0.18.0.
    • Premise (falsifiable; verify it FIRST): every behaviour the driver documents as measured against @libsql/client@0.17.4 re-measures identically on the resolved 0.18.x.
    • Sites at origin/main 63d1a7c:
      • src/turso-driver.ts: 12 citations, including refusal message text at lines 1001, 1061, 1384 and 1417.
      • src/turso-authtoken-url-channel.test.ts: the measurement docblock at lines 17-18 and the version pin at line 281.
      • src/turso-driver-remote-url-replica-refusal.test.ts, src/turso-driver-timeout.test.ts, src/turso-driver-unrecognised-url-refusal.test.ts, src/turso-driver-uppercase-ws-scheme-timeout-refusal.test.ts and src/turso-driver-ws-timeout-refusal.test.ts.
    • Re-check command: git grep -n -E "0\.17\.[0-9]" -- packages/drivers/driver-turso/src
    • Evidence so far: on chore(deps)(deps): bump the production-dependencies group with 27 updates #21029's CI (resolved 0.18.0), the line-281 version pin was driver-turso's only failure; 2194 other tests passed. That makes the premise plausible. It does NOT prove the documented claims.
    • If the premise holds, update the pin, the docblocks and the message text to the version actually measured.
    • ⛔ If any claim no longer holds, do not force it and do not quietly keep 0.17 either. Keep ^0.17.3, finish the rest of this card, and report the fork with the differing measurement.
  5. Changeset. Add a patch changeset naming every published package whose dependencies range moves. After exclusion 1, plugin-auth is not among them. Do not use skip-changeset: these ranges reach consumers.

Measure what #21029 never measured

#21029's red jobs stopped early, so these were never run. Run them here:

  • Test Core shard 4/6 stopped at the first failure and never reached eight packages: rest, driver-sql, plugin-email, plugin-approvals, plugin-webhooks, trigger-schedule, connector-mcp and client-react.
  • Lint & Repo Gates stopped at check:vendor-export-contract; every gate after it is unmeasured.
  • The OSV step of Validate Package Dependencies was never reached.

Notes from the risk read (not acceptance criteria)

Expected file surface


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Triage: first grade — dependencies · priority:p2 · domain:devx · area:devpath · pm:queue. The maintainer-directed production-dependency group, without better-auth and next

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-01T07:03Z. ⛔ Not a claim, ⛔ not a dispatch.

    Why p2. It is maintainer-directed (the card quotes 「按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地」). Its measured risks are named: the better-auth override split, nodemailer's downgrade, and @libsql/client 0.18's premise.

    Routing. The lockfile and workspace dependencies are domain:devx, as #21055 was.

    Direction. It is the card's own scope, confirmed, item by item. Two points stand out:

    Serial. pnpm-lock.yaml is a hot file. #21102 (the #21024 re-lock) and #21055's remnants touch it, so whichever lands second merges main and regenerates the lockfile with the tooling.


    Generated by Claude Code

  2. added
    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iterate
    dependenciesPull requests that update a dependency file
    on Oct 1, 2026
  3. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    pm:queue → pm:blocked: serial wait on #21102

    Read 2026-10-01T08:12Z · PM session session_018gA1pE6eJtwHhqx72G8U9X (the maintainer's direct-dispatch session: 「相关卡片你使用项目经理技能派发处理」).


    Generated by Claude Code

  4. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 2
    Session: session_018gA1pE6eJtwHhqx72G8U9X
    Account: os-bill (the seat's linked user as GET /user answers it; the card's assignee from this act)
    Branch: claude/issue-21094-prod-deps-group
    Worktree: objectstack-issue-21094
    Domain: domain:devx
    Seat: domain:devx#3 (the maintainer's direct-dispatch session; it holds no seat post, so #3 collides with no post: objectstack devx seats 1 and 2 are #6023 and #20163)
    Provenance:


    Generated by Claude Code

  5. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Correction to this card's item 5 (Changeset), from the PM seat that wrote it

    Read 2026-10-01T09:05Z. Item 5 says "After exclusion 1, plugin-auth is not among them." That is wrong. plugin-auth also declares @noble/hashes and jose in dependencies, and #21029 moves both: ^2.3.0 to ^2.4.0 and ^6.2.8 to ^6.2.12. Excluding the five better-auth lines does not take the package out.

    Measured over #21029's manifest diff against its merge base: excluding apps/docs and the better-auth lines, 19 published packages have a dependencies range that moves:

    • @objectstack/cli and create-objectstack
    • @objectstack/connector-mcp
    • @objectstack/core, @objectstack/objectql, @objectstack/rest, @objectstack/runtime and @objectstack/spec
    • @objectstack/driver-mongodb, @objectstack/driver-sqlite-wasm and @objectstack/driver-turso
    • @objectstack/mcp
    • @objectstack/metadata-core, @objectstack/metadata-protocol and @objectstack/metadata
    • @objectstack/plugin-auth, @objectstack/plugin-hono-server and @objectstack/plugin-pinyin-search
    • @objectstack/service-settings

    The patch changeset names those 19. If item 4's premise fails and @libsql/client stays on ^0.17.3, driver-turso still moves because of zod. The dispatched dev re-derives the list from its own diff, and this comment is not a substitute for that.


    Generated by Claude Code

  6. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 21094,
      "status": "done",
      "branch": "claude/issue-21094-prod-deps-group",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/21162",
      "session": "session_018gA1pE6eJtwHhqx72G8U9X",
      "premise_still_valid": true,
      "summary": "Draft PR #21162 (head 56e421979) takes the 2026-10 production-dependency group. Dependabot #21029's 63 range moves were re-applied one at a time onto current main, each guarded by an exact-match check, across 43 manifests. apps/docs (next) and the five better-auth lines in plugin-auth were left out; better-auth stays at 1.7.3 and pnpm-workspace.yaml is untouched. The lockfile was regenerated with pnpm 10.31.0. Compared pair by pair with merge base b616c0a6, no resolved version went DOWN, and nodemailer stays at 10.0.13. Item 4: @libsql/client is lifted to ^0.18.0 because the premise holds. All 21 sites stamped 0.17.4 in driver-turso/src re-measure identically on 0.18.0 and are restamped (version pin, docblocks, and the four refusal messages). A patch changeset names the 19 published packages whose dependencies ranges move, re-derived from this diff; the list matches PM correction 5928286488, plugin-auth included. One step beyond H3: plain `pnpm install --lockfile-only` left hono at 4.13.7, below the published ^4.13.9, because the hono override rewrites declarations to ^4.13.5 and lockfile inertia held 4.13.7. A filtered `pnpm update --lockfile-only --no-save hono` over the three hono importers moved the single hono copy to 4.13.12. That touched no manifest and no override (see deviations).",
      "item4_libsql": "LIFTED to ^0.18.0. The premise held, measured three ways before any driver edit. (1) npm-pack diff: @libsql/core 0.17.4 vs 0.18.0 differs only in package.json's version. @libsql/client differs only in lib-esm/sqlite3.js, lib-cjs/sqlite3.js, sqlite3.d.ts and package.json: a connection pool for the local file: client. http.js, ws.js and node.js are byte-identical, and so are the installed @libsql/hrana-client 0.10.0 and native libsql 0.5.29. (2) One probe script run against side-by-side installs gives identical output except the version strings and the syncUrl count in sqlite3.js (3 to 4, the new pool-size line). Readings on 0.18.0: expandConfig maps WSS to wss, Ws to ws, LIBSQL to https (control) and FILE: to file; :memory: expands to file::memory:; isInMemoryConfig is true for file::memory: and its query form, false for the file:./x.db control. createClient gives URL_INVALID for ./data/app.db, data/app.db, /abs/app.db, :MEMORY:, empty and libsql:host, and URL_SCHEME_NOT_SUPPORTED for sqlite:, memory:// and a C: path. Remote sync() rejects SYNC_NOT_SUPPORTED on https and ws. :memory:+syncUrl throws URL_INVALID 'Embedded replica must use file for local db'. Line counts: syncUrl in http.js 0, ws.js 0 (control authToken 6 and 6); ws.js fetch 0, timeout 0; hrana ws/*.js+index.js timeout 0 (control http fetch 15). The api.d.ts docblock 'remote clients ignore it' is byte-identical. (3) driver-turso suite: 0.17.4 at base, 2210 passed / 33 skipped. 0.18.0 before the restamp, 2209 passed / 1 failed / 33 skipped, per-test outcomes identical except the version pin. After the restamp at 56e421979, 2210 passed / 33 skipped. Every claim: held. The pin moved to 0.18.0 by design.",
      "tests": "All exit 0, read from vitest/turbo summary lines with exit codes captured before any pipe. driver-turso full suite as in item4_libsql, at 56e421979 after merge and full rebuild, plus `pnpm --filter @objectstack/driver-turso run typecheck` passing. H4's eight packages at cf1d700b (pre-merge), via turbo test (45/45 tasks): rest 250 files 4728 passed / 248 skipped; driver-sql 205 files 3303 passed / 188 skipped; plugin-email 31/510; plugin-approvals 52/804; plugin-webhooks 13/160; trigger-schedule 8/170; connector-mcp 3/23; client-react 3/34. Packages whose own deps moved, at cf1d700b (41/41 tasks): driver-mongodb 30 files 675 passed / 172 skipped; mcp 32/344; plugin-hono-server 27/324; plugin-auth 115/2472; service-settings 33/584; plugin-pinyin-search 2/21; driver-sqlite-wasm 36/675; driver-memory 69/1613; service-analytics 155/3526 (10 skipped); create-objectstack 16/247; @objectstack/hono 5/122. Also `pnpm --filter @objectstack/cli exec vitest run --project unit` 242 files / 3432 passed, and `@objectstack/spec` `--project local` 591 files / 17368 passed. Typecheck via turbo over the 19 movers plus client-react, hono and lint: 80/80 tasks. OSV: osv-scanner v2.3.8, built from the Go module proxy because api.osv.dev is egress-denied, run on the offline npm DB over lockfile blob 70547c67 with osv-scanner.toml loaded: 1388 packages, 'No issues found', exit 0. Its positive control (same lockfile, hono rewritten to 4.12.32) gave exit 1 with 8 hono advisories including GHSA-8j4g-w8fx-2239. z.properties: `git grep -n -E \"z\\.properties\\(\" -- packages/` 0 lines (exit 1); control z.object( 1825. NOT MEASURED: driver-mongodb live-mongod suites, because fastdl.mongodb.org is egress-denied (CONNECT 403). NOT MEASURED locally: the 72 Lint & Repo Gates steps after check:vendor-export-contract, which belong to CI; the vendor-export-contract step itself passed locally. No ablation applies: there is no new guard, only re-measurement.",
      "gates": "`node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands` (no paths) at HEAD 56e421979 derived 100 commands over 52 paths against merge base f20f669e1, identical to the pre-merge derivation. All 100 exit 0, plus `pnpm check:vendor-export-contract` exit 0 ('VERDICT: PASS — vendor export contract (installed workspace), 1 edge(s) verified'). `--ran` gives 'Run reconciliation — 100 derived, 100 run, 0 NOT-MEASURED, 0 UNRUN' with an exit code on every line. Pre-merge, two gates refused on the shallow clone: check-engine-split-ratio --days 90 (exit 2) and check-plugin-teardown-shape --self-test (exit 3). That is PREREQUISITE NOT MET, not red; after `git fetch --shallow-since=2026-06-26 origin main` both exit 0. The seven filtered `pnpm --filter @objectstack/spec run check:*` logs each echo their script name. CI on 56e421979 at report time: 35 check runs, 13 success, 2 skipped, 20 in_progress.",
      "mcp_calls": "0 — no MCP GitHub tool was called",
      "api_writes": "3 — each a fleet-write relay stroke (POST /repos/objectstack-ai/objectstack/dispatches) executed as objectstack-fleet[bot]: (1) pr_create -> POST /repos/objectstack-ai/objectstack/pulls (#21162, draft forced, body read back byte-identical 13513/13513); (2) label-write --assign os-bill -> POST /repos/objectstack-ai/objectstack/issues/21162/assignees (read-back matches; size/m was added by another actor); (3) post-stamped -> POST /repos/objectstack-ai/objectstack/issues/21094/comments (this report). Zero label writes: no label is named and a changeset exists. git push is not REST.",
      "open_questions": [],
      "out_of_scope_findings": [
        "carrier: none · noted, not filed — packages/spec/src/data/driver/common.zod.ts:269 (the TSDoc of CREDENTIAL_URL_QUERY_PARAMS, 'measured ... in the versions pinned by this tree') and driver-credential-refusal.test.ts:325 name @libsql/core@0.17.4. Re-measured on 0.18.0, the behaviour is identical: ?authToken= overrides the config token, auth%54oken is decoded, AuthToken and token give URL_PARAM_NOT_SUPPORTED, and the no-query control keeps the config token. Only the version label goes stale. Editing packages/spec src would add 27 gate families beyond this derivation (bounded-fix condition 4 fails). The edit is two version strings, 0.17.4 to 0.18.0, for whoever next touches those files.",
        "carrier: none · noted, not filed — libsql 0.18.0 pools the local sqlite3 client with a single connection for syncUrl. From reading the code (not measured), a second replica sync() now queues behind an uncancelled first one that outlived TursoDriverConfig.timeout, where on 0.17.4 both ran concurrently on one native handle. No driver docblock claims either behaviour.",
        "carrier: PM (filing, per its mid-run message) · noted, not filed — turbo 2.11.5 agentGuidance appends a managed block to the root AGENTS.md on every repository-scoped turbo run in an agent session."
      ],
      "deviations": [
        "Lockfile, beyond H3's single command: after `pnpm install --lockfile-only`, also ran `pnpm --filter @objectstack/plugin-hono-server --filter @objectstack/plugin-auth --filter @objectstack/hono update --lockfile-only --no-save hono` (commit 12a5ae80). This was needed because the `hono` override (selector below 5.0.0, target ^4.13.5) left hono at 4.13.7, below plugin-hono-server's published ^4.13.9. Side effect, found when reading the hunks: the vitest snapshot of the `packages/apps/account` importer moved from the esbuild 0.28.1 peer copy to the 0.28.2 copy already present (up, not down). esbuild 0.28.1 stays in the lockfile for other importers. An unfiltered `pnpm update -r` was tried and reverted (`git checkout HEAD -- pnpm-lock.yaml`) because it dropped knex's mysql2/pg/tedious peer links in two importers. To undo: revert 12a5ae80; plain install output was 338da254's lockfile.",
        "Environment side effect (PM message): turbo re-added its block to AGENTS.md after turbo runs. Restored 7 times with `git restore --source=HEAD --staged --worktree AGENTS.md`. `git status --porcelain` was empty before every commit, and no commit on the branch lists AGENTS.md (checked per commit with `git show --name-only`). Some gate and test runs executed while the block was present in the working tree; all were green.",
        "Shared .git deepened (additive): `git fetch --shallow-since=2026-06-26 origin main` for the two shallow-refused gates.",
        "The H4 and direct-mover package suites ran at cf1d700b, before merging main at f20f669e1. After the merge: full rebuild, the driver-turso suite and typecheck, and the full 100-gate union at 56e421979. main has since moved to 2488b98b4 (2 commits, neither on this PR's paths); not re-merged.",
        "Claim comment 5928265691 says '44 manifests ... minus apps/docs' and the dispatch says 43. #21029 touched 44 including apps/docs, so 43 land here, matching the dispatch.",
        "Commit trailers use AGENTS.md's model-free pair (Claude-Session + Co-authored-by: Claude), not the harness reminder's model-named form. The PR body footer follows AGENTS.md's session-URL form.",
        "PR body omission (body written once, not PATCHed): the lockfile bullet's step 2 does not name the side effect above. Correction for the seat, if wanted: append \"Side effect: `packages/apps/account`'s vitest snapshot moves from the esbuild 0.28.1 peer copy to the 0.28.2 copy already present.\" to that bullet."
      ],
      "line_budget": "n/a — no skills/** or line-ratcheted ledger in the diff; PR diff 52 files +626/-552 vs main (under the 5,000-line class-(c) bound); no governed surface",
      "files_changed": "52: 43 package.json (examples/app-showcase, examples/app-todo, root, packages/{adapters/hono, cli, client-react, client, connectors/connector-mcp, core, create-objectstack, drivers/driver-memory, drivers/driver-mongodb, drivers/driver-sqlite-wasm, drivers/driver-turso, lint, mcp, metadata-core, metadata-protocol, metadata, objectql, plugins/{embedder-openai, knowledge-memory, knowledge-ragflow, organizations, plugin-approvals, plugin-audit, plugin-auth, plugin-dev, plugin-email, plugin-hono-server, plugin-pinyin-search, plugin-security, plugin-sharing, plugin-webhooks}, rest, runtime, services/{service-analytics, service-automation, service-cluster, service-knowledge, service-settings, service-storage}, spec}); pnpm-lock.yaml; packages/drivers/driver-turso/src/{turso-driver.ts, turso-authtoken-url-channel.test.ts, turso-driver-remote-url-replica-refusal.test.ts, turso-driver-timeout.test.ts, turso-driver-unrecognised-url-refusal.test.ts, turso-driver-uppercase-ws-scheme-timeout-refusal.test.ts, turso-driver-ws-timeout-refusal.test.ts}; .changeset/21094-prod-deps-group.md"
    }

    Generated by Claude Code

  7. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Review: REWORK, patch round 1, PR #21162 (head 56e4219798)

    Reviewed 2026-10-01T11:05Z by the PM seat (session_018gA1pE6eJtwHhqx72G8U9X) against GitHub and the branch.

    Holds as reported, verified at the head:

    • Shape: the PR is a draft against main. Its body opens Fixes #21094, with no other closing keyword. The assignee is os-bill.
    • Scope: 52 files.
      • No AGENTS.md, turbo.json, pnpm-workspace.yaml, apps/docs/package.json or other governed path is in the diff.
      • plugin-auth's five better-auth lines are still 1.7.3.
    • Lockfile: compared pair by pair against the merge base f20f669e17, 0 versions go down.
      • nodemailer@10.0.13, hono@4.13.12, better-auth@1.7.3.
      • Only @libsql/client@0.18.0 and @libsql/core@0.18.0 remain; no 0.17.4 copy.
    • Changeset: it names exactly the 19 packages of correction 5928286488, all patch.
    • Item 4: the premise is measured three ways and holds, so the lift is right.

    The one REWORK item. The PR makes published text false; the review checklist calls that a must-fix in this round.

    • packages/spec/src/data/driver/common.zod.ts ships in @objectstack/spec. That package is one of this changeset's 19, so the text ships in the same release.
    • Its TSDoc for CREDENTIAL_URL_QUERY_PARAMS says it was measured "in the versions pinned by this tree" and names `@libsql/core@0.17.4`.
    • After this PR the tree pins only 0.18.0, so the label becomes false. The behaviour it describes does not: the os-dev's report re-measured it as identical on 0.18.0.
    • The fix: restamp that label, and its echo in driver-credential-refusal.test.ts, to the version actually measured. Nothing else changes.
    • "Out of scope: 27 gate families" does not apply. It is the rule for an adjacent defect the PR did not cause; this PR causes this one.

    Owed after the patch round: .changeset prose is on this diff, and the patch round adds published spec source (packages/spec/src/**, non-test). Both are contract-review surfaces, so the PR also owes a CONTRACT_REVIEW_TIER review record before it queues. The seat runs that review on the patched head.

    Noted from the report: the PR body's lockfile bullet does not mention that packages/apps/account's vitest snapshot moved from the esbuild 0.28.1 peer copy to the 0.28.2 copy already present (upward, and tool-generated). It is recorded here; the body stays as written.


    Generated by Claude Code

  8. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 21094,
      "patch_round": 1,
      "status": "done",
      "branch": "claude/issue-21094-prod-deps-group",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/21162",
      "session": "session_018gA1pE6eJtwHhqx72G8U9X",
      "premise_still_valid": true,
      "summary": "Patch round 1, per verdict 5930050869, is one commit, a2d5d53c4, now pushed and the PR head. It restamps the @libsql/core version label from 0.17.4 to 0.18.0 in two places: the TSDoc of CREDENTIAL_URL_QUERY_PARAMS (packages/spec/src/data/driver/common.zod.ts:269) and its echo in driver-credential-refusal.test.ts:325. Nothing else in packages/spec changed; the diff is 2 files, +2/-2. The commit body cites the 0.18.0 re-measurement, run again in this round against the repo's installed @libsql/core 0.18.0. With config authToken 'BINDER': url ?authToken=URLTOK gives URLTOK (the URL overrides); ?auth%54oken=URLTOK gives URLTOK (the key is percent-decoded); ?AuthToken= and ?token= give URL_PARAM_NOT_SUPPORTED; the no-query control keeps BINDER. No generated artifact carries that TSDoc text: a git grep over packages/spec outside src and CHANGELOG.md, content/docs and skills returns 0 hits. The PR body, draft state and labels were not touched. main moved to c35436c75 but on none of this PR's paths, so it was not merged and the lockfile is unchanged.",
      "remaining_0_17_4_hits": "`git grep -n \"0\\.17\\.4\" -- packages/` at a2d5d53c4 returns 10 lines; positive control `git grep -n \"libsql/core@0\\.18\\.0\" -- packages/` returns 9 (7 in driver-turso/src, 2 in spec). Lines that STAY: (a) 8 in CHANGELOG.md files, release-owned and never edited in a code PR. Each records a measurement in an already-published release entry and is still true of that release: driver-turso CHANGELOG.md:159, 174, 1432, 1535, 1555; service-datasource CHANGELOG.md:2349; spec CHANGELOG.md:15745, 28094. (b) 2 in service-package: src/index.ts:192 and src/mysql2-tuple.test.ts:172, both 'Measured on `@libsql/client` 0.17.4, `result.rows` is a real array...'. That is a dated attestation, not a 'pinned by this tree' live reading, so it stays true. The rows shape was also re-measured identical on 0.18.0 last round (rows is an array, rows[0] a plain object). service-package does not depend on @libsql/client. Lines that GO: none remain in non-CHANGELOG source with a live-reading phrase.",
      "item4_libsql": "Unchanged from round 0: LIFTED to ^0.18.0, premise held. This round extends the restamp to the two spec sites.",
      "tests": "`pnpm --filter @objectstack/spec exec vitest run --project local --maxWorkers=2 src/data/driver/driver-credential-refusal.test.ts` gives 1 file, 152 passed, exit 0. Full turbo build first (72/72 tasks), because the gates read dist. The four authToken behaviours were re-measured on the installed @libsql/core 0.18.0 (see summary). The round-0 package suites still stand for the unchanged code.",
      "gates": "`node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands packages/spec/src/data/driver/common.zod.ts packages/spec/src/data/driver/driver-credential-refusal.test.ts` at a2d5d53c4 derived 79 commands; all 79 exit 0, with exit codes captured before any pipe. `--ran` over those two paths gives 'Run reconciliation — 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN'. These include check:api-surface, check:docs, check:authorable-surface, check:spec-docblock-symbol-anchors, check:type-check-coverage and check:type-check-debt. Each of the 18 filtered `pnpm --filter ... run check:*` logs echoes its script name. Full-branch union at the new head: the no-path derivation (54 paths against f20f669e1) gives 117 commands. The 38 not among the 79 were also run at a2d5d53c4, all exit 0. `--ran` gives 'Run reconciliation — 117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN', a derived zero. CI on a2d5d53c4 at report time: 38 check runs, 35 success, 2 skipped, 1 in_progress.",
      "mcp_calls": "0 — no MCP GitHub tool was called",
      "api_writes": "1 this round — a fleet-write relay stroke (POST /repos/objectstack-ai/objectstack/dispatches) running post-stamped, which does POST /repos/objectstack-ai/objectstack/issues/21094/comments (this report). No PR body, draft or label write. git push a2d5d53c4 is not REST.",
      "open_questions": [],
      "out_of_scope_findings": [],
      "deviations": [
        "The worktree had been removed (node_modules, then `git worktree remove`, no --force) as round 0's cleanup step. For this round it was recreated at the same path on the same branch: `git worktree add ../objectstack-issue-21094 claude/issue-21094-prod-deps-group`, at 56e421979, which matched origin. Then `pnpm install --frozen-lockfile`.",
        "turbo re-added its block to AGENTS.md during the build and the gate runs. Restored 2 times with `git restore --source=HEAD --staged --worktree AGENTS.md`. `git diff --cached --name-only` before the commit listed only the two spec files, and commit a2d5d53c4 touches only them.",
        "main moved from f20f669e1 to c35436c75 (6 commits), none on this PR's paths, so it was not merged, per instruction 4."
      ],
      "line_budget": "n/a — no skills/** or line-ratcheted ledger; this round +2/-2 in 2 files; PR diff now 54 files vs main",
      "files_changed": "this round: packages/spec/src/data/driver/common.zod.ts; packages/spec/src/data/driver/driver-credential-refusal.test.ts (PR total 54: round 0's 52 plus these 2)"
    }

    Generated by Claude Code

  9. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Merge queue ejected PR #21162 — signature and first diagnosis

    Recorded 2026-10-01T11:55Z by the PM seat (session_018gA1pE6eJtwHhqx72G8U9X). The full triage is on PR #21162.


    Generated by Claude Code

  10. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 21094,
      "patch_round": 2,
      "status": "done",
      "branch": "claude/issue-21094-prod-deps-group",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/21162",
      "head": "0f87e8488",
      "session": "session_018gA1pE6eJtwHhqx72G8U9X",
      "premise_still_valid": true,
      "summary": "Patch round 2 fixes the merge-queue ejection (triage 5930776004 / 5930785114) with two commits, both pushed, no rebase, amend or force. (1) 4e92c58bc merges origin/main at e35c40a52, the commit where #21160 landed. There was no textual conflict, but the merged lockfile was broken: `pnpm install --frozen-lockfile` failed locally with exactly the queue signature, ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY ... no entry for 'tsx@4.23.12'. (2) 0f87e8488 lifts the tsx devDependency #21160 added to packages/drivers/driver-turso/package.json from ^4.23.12 to ^4.23.15, with an exact-match guard. A grep then finds no `\"tsx\": \"^4.23.12\"` in any package.json; all 27 tsx declarations read ^4.23.15. It regenerates pnpm-lock.yaml with `pnpm install --lockfile-only` (pnpm 10.31.0), never by hand. Result: a fixed point (a second lockfile-only run is byte-identical), frozen install passes, and the lockfile blob is 30ba2147. The tsx lift is a devDependency, so the changeset text and package list are unchanged. The PR body, draft state and labels were not touched.",
      "lockfile_vs_new_main": "Resolved name@version pairs (packages: section) compared with main e35c40a52: 25 names change, DOWN: 0. They are the same 25 as round 0 against the old base: @libsql/client and @libsql/core 0.17.4 to 0.18.0; zod +4.6.5; @modelcontextprotocol/sdk 1.30.0 to 1.31.0; hono 4.13.7 to 4.13.12; mongodb +7.7.0; jose 6.2.7 and 6.2.8 to 6.2.12; @noble/hashes 2.3.0 to 2.4.0; @noble/ciphers +2.4.0; react, react-dom, @types/react and @types/react-dom +19.3.0; tsx 4.23.12 to 4.23.15; yaml +2.9.1; chalk 6.0.0 to 6.0.1; sql.js 1.14.1 to 1.14.2; pinyin-pro 3.29.1 to 3.29.4. Dedupes onto copies already present: @hono/node-server 2.0.12, ws 8.21.1, @types/ws 8.18.1 and eventsource-parser 3.1.0 are removed. New transitive copies: bson 7.3.3 and @mongodb-js/saslprep 1.5.5 (with mongodb 7.7.0), scheduler 0.28.0 (with react-dom 19.3.0). Re-confirmed: nodemailer 10.0.13 only. better-auth, @better-auth/core, sso, scim and oauth-provider are 1.7.3 only, all 5 importer entries resolve 1.7.3, the overrides block is unchanged, and the lockfile has 0 occurrences of 1.7.6. @libsql/client and @libsql/core are 0.18.0 only, with 0 occurrences of 0.17. The resolved set equals round 0's OSV-scanned lockfile (blob 70547c67): 0 names differ, so that scan's 'No issues found' covers the same versions. CI's online OSV step remains authoritative.",
      "tsx_copies": "1 resolved copy, tsx@4.23.15: one packages entry plus one snapshots entry, and all 27 importer declarations give `version: 4.23.15`. 0 occurrences of tsx@4.23.12.",
      "census_0_17_x": "`git grep -n '0\\.17\\.[0-9]' -- packages/ content/docs skills ':!**/CHANGELOG.md'` at 0f87e8488 returns 2 lines, both STAY as dated attestations: packages/services/service-package/src/index.ts:192 and src/mysql2-tuple.test.ts:172, 'Measured on `@libsql/client` 0.17.4, `result.rows` is a real array ...'. Neither claims the pinned version; the rows shape was re-measured identical on 0.18.0 in round 0, and service-package does not depend on libsql. GO: none. #21160 brought no 0.17.x string. Its libsql readings are anchored to commits ('Measured on `main` @ `2f3e79351`', and the reverse-verification note recorded in its PR), so they stay true. Positive control: `git grep -o '0\\.18\\.0'` gives 23 occurrences in driver-turso/src (13 in turso-driver.ts, which #21160's merge left in place) and 2 in packages/spec/src/data/driver, unchanged from round 1.",
      "item4_libsql": "Unchanged: LIFTED to ^0.18.0. #21160's new and rewritten driver-turso tests were written against 0.17.4 and run here on 0.18.0, all passing: turso-remote-autonumber-generation 27/27, turso-remote-autonumber-concurrency 1/1, turso-autonumber-resync 3/3, turso-autonumber-batch-resync 5/5, turso-update-missing-id 10/10. The concurrency test runs two child processes, each on 0.18.0's pooled native file: client, so it is the one most exposed to 0.18.0's only code change. It passed and was not skipped; its own measurement line reads '[turso-remote-autonumber-concurrency] pids 6303/6304 · 400 writes · 400 distinct · 13 writer change(s)', so the two writers overlapped.",
      "tests": "At 0f87e8488, after a full turbo build (72/72 tasks): `pnpm --filter @objectstack/driver-turso exec vitest run --maxWorkers=2` gives 82 files, 2218 passed / 33 skipped / 0 failed, and `pnpm --filter @objectstack/driver-turso run typecheck` (tsc --noEmit) passes; lock VERDICT command-exit 0. The 33 skipped are the same constructor-parity cases as round 0. Locally, `pnpm install --frozen-lockfile` fails (exit 1) on the merge commit 4e92c58bc, reproducing the queue signature, and passes on 0f87e8488.",
      "gates": "This round's paths, `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands packages/drivers/driver-turso/package.json pnpm-lock.yaml`, derive 52 commands. The full-branch union (no paths: 54 paths against merge base e35c40a52) derives 117, a superset. All 117 ran at 0f87e8488, all exit 0, exit codes captured before any pipe; `pnpm check:vendor-export-contract` also exit 0. `--ran` over the two paths: 'Run reconciliation — 52 derived, 52 run, 0 NOT-MEASURED, 0 UNRUN'. `--ran` over the union: 'Run reconciliation — 117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN', a derived zero. The union includes check:override-consistency, check:vendor-export-contract-resolve and check-osv-exemptions. All 19 filtered `pnpm --filter ... run check:*` logs echo their script name. CI on 0f87e8488 at report time: 38 check runs listed, 36 success, 2 skipped (the queue run is the authoritative one).",
      "mcp_calls": "0 — no MCP GitHub tool was called",
      "api_writes": "1 this round — a fleet-write relay stroke (POST /repos/objectstack-ai/objectstack/dispatches) running post-stamped, which does POST /repos/objectstack-ai/objectstack/issues/21094/comments (this report). No PR body, draft or label write. The git push of 4e92c58bc and 0f87e8488 is not REST.",
      "open_questions": [],
      "out_of_scope_findings": [],
      "deviations": [
        "For the reviewer, the regeneration's one change beyond tsx: `pnpm install --lockfile-only` on the merged tree returned packages/apps/account's vitest snapshot to main's esbuild 0.28.1 peer variant. That undoes the dedupe round 0's filtered `pnpm update ... hono` had made there; the extra vitest/vite/@vitest/mocker snapshots for that variant come back. Against main, this PR no longer changes that importer's esbuild variant. The only lines touching it differ in the tsx, yaml and @noble/hashes versions inside its peer suffix. The round-0 deviation about that side effect is therefore moot at this head.",
        "The PR body (unedited, per instruction) is stale against this head in three readings: '63 range moves' is now 64 across the same 43 manifests (driver-turso's new tsx line); 'Lockfile blob 70547c67' is now 30ba2147, with the same resolved set; and '52 paths' is now 54 (the two round-1 spec files). Its 'HEAD 56e421979' gate readings are superseded by this report's readings at 0f87e8488.",
        "The worktree was recreated at the same path on the same branch (`git worktree add ../objectstack-issue-21094 claude/issue-21094-prod-deps-group` at a2d5d53c4, which matched origin), after round 1's cleanup had removed it. Then `pnpm install --frozen-lockfile`.",
        "AGENTS.md: after the merge, turbo.json carries #21151's `\"agentGuidance\": false`, and turbo wrote no block this round. `git status --porcelain` was empty after the build, the gates and the tests; 0 restores were needed, and neither commit lists AGENTS.md.",
        "main has since moved to 327391c3a (1 commit, not on this PR's paths); not merged again."
      ],
      "line_budget": "n/a — no skills/** or line-ratcheted ledger; this round's own commit is 2 files (driver-turso package.json +1/-1, pnpm-lock.yaml +58/-3); PR diff vs main now 54 files +640/-511, under the 5,000-line bound; no governed path",
      "files_changed": "this round: packages/drivers/driver-turso/package.json; pnpm-lock.yaml (plus merge commit 4e92c58bc bringing main e35c40a52). PR total vs main: 54 files (43 package.json, pnpm-lock.yaml, 7 driver-turso src files, 2 packages/spec/src/data/driver files, .changeset/21094-prod-deps-group.md)"
    }

    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratedependenciesPull requests that update a dependency filedomain:devxpriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions