Repository navigation
deps: take the 2026-10 production-dependency group without the better-auth family (replaces Dependabot #21029) #21094
Description
Activity
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsTriage: first grade —
dependencies·priority:p2·domain:devx·area:devpath·pm:queue. The maintainer-directed production-dependency group, without better-auth andnextTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-01T07:03Z. ⛔ Not a claim, ⛔ not a dispatch.Why p2. It is maintainer-directed (the card quotes 「按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地」). Its measured risks are named: the better-auth override split,
nodemailer's downgrade, and@libsql/client0.18's premise.Routing. The lockfile and workspace dependencies are
domain:devx, as #21055 was.Direction. It is the card's own scope, confirmed, item by item. Two points stand out:
@libsql/client0.18: measure the premise first. If any documented claim fails, keep^0.17.3and report the fork. ⛔ Do not force it.- Run what chore(deps)(deps): bump the production-dependencies group with 27 updates #21029 never ran: the eight packages shard 4/6 did not reach, the gates after
check:vendor-export-contract, and the OSV step.
Serial.
pnpm-lock.yamlis a hot file. #21102 (the #21024 re-lock) and #21055's remnants touch it, so whichever lands second mergesmainand regenerates the lockfile with the tooling.
Generated by Claude Code
- addedarea:devpathThe road — create, dev, verify, publish/install, connect an agent, iterateThe road — create, dev, verify, publish/install, connect an agent, iteratedependenciesPull requests that update a dependency filePull requests that update a dependency filepriority:p2Medium: important, M3Medium: important, M3
on Oct 1, 2026 objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionspm:queue→pm:blocked: serial wait on #21102Read 2026-10-01T08:12Z · PM session
session_018gA1pE6eJtwHhqx72G8U9X(the maintainer's direct-dispatch session: 「相关卡片你使用项目经理技能派发处理」).- Why. deps: re-lock Dependabot #21024 so nodemailer stays at 10.0.12 or later, then land it #21102 is in flight (claimed by
domain:devx#1, comment 5927184697). It re-lockspnpm-lock.yamlon chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 16 updates #21024's branch. This card is alsoarea:devpath, and its file surface includespnpm-lock.yaml. The state table allows at most one card in flight perarea:*unless file surfaces are disjoint. Here they are not, so this card waits. That is stricter than the triage note's "whichever lands second regenerates", and the stricter reading is the one applied. - Unlock. deps: re-lock Dependabot #21024 so nodemailer stays at 10.0.12 or later, then land it #21102 closes when chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 16 updates #21024 merges; the PM seat landing chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 16 updates #21024 closes it then. The
Blocked-by: #21102line in the body is what the unlock scan reads. - Order after unlock. When it unlocks, this card goes first: it is
priority:p2, and cli: move to the @oclif/core 5 line, with plugin-help 7 and plugin-plugins 7 in the same commit (replaces Dependabot #21034, #21031, #21035) #21125 is not graded yet.
Generated by Claude Code
- Why. deps: re-lock Dependabot #21024 so nodemailer stays at 10.0.12 or later, then land it #21102 is in flight (claimed by
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsClaim: PM loop round 2
Session:session_018gA1pE6eJtwHhqx72G8U9X
Account:os-bill(the seat's linked user asGET /useranswers it; the card's assignee from this act)
Branch:claude/issue-21094-prod-deps-group
Worktree:objectstack-issue-21094
Domain:domain:devx
Seat: domain:devx#3 (the maintainer's direct-dispatch session; it holds no seat post, so #3 collides with no post: objectstack devx seats 1 and 2 are #6023 and #20163)
Provenance:- Who: the maintainer.
- Verbatim: 「相关卡片你使用项目经理技能派发处理」, after 「按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地」.
- Where: session
session_018gA1pE6eJtwHhqx72G8U9X, 2026-10-01.
File surface: the card body's "Expected file surface", re-derived atorigin/main1bd14c9848: - The 44 manifests chore(deps)(deps): bump the production-dependencies group with 27 updates #21029 changed, minus
apps/docs/package.json([finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055 / fix(deps): take the fix for next GHSA-vcvr-r3jv-pc5j (critical) and dompurify GHSA-p98j-92pf-mc4p #21083 already tooknext). plugin-auth/package.jsonchanges only its non-better-auth lines (@noble/hashes,jose,hono,tsx). The five better-auth lines and thepnpm-workspace.yamloverrides stay as they are.pnpm-lock.yaml, regenerated by the tooling fromorigin/main(⛔ no hand edit).packages/drivers/driver-turso/src/**, for card item 4 only.- One
.changeset/21094-prod-deps-group.md. - Stop on a breach and explain it in the report.
Container & model:M(a lockfile regeneration plus a premise-gated re-measure of the documented 0.17.4 libsql behaviours, whose verdict decides the libsql leg),mode:subagent,model: opus.dispatch-gates --tierat1bd14c9848: no path-derived mandate.
Clause-②: no
Thread-read: 5927479567
Serial constraints cleared: - Read at 2026-10-01T09:04Z on
origin/main1bd14c9848. - deps: re-lock Dependabot #21024 so nodemailer stays at 10.0.12 or later, then land it #21102 is closed
completed(chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 16 updates #21024 merged as840ec9dab3), so thearea:devpathlockfile wait is over. - Of the 11 open PRs, none touches any path on this surface or
packages/drivers/driver-turso/**. - Of the 27
pm:dispatchedcards' claims, one shares a package: driver-turso remote: generate auto_number values on the RemoteTransport — the #6944 appetite door now has measured demand (a hosted HotCRM environment cannot create an account: 501) #21113 (domain:engine) claimspackages/drivers/driver-turso/src/remote-transport.ts. That is disjoint from this card'sturso-driver.tsand its tests, so it is ordinary concurrency: mergemainright before opening the PR. - cli: move to the @oclif/core 5 line, with plugin-help 7 and plugin-plugins 7 in the same commit (replaces Dependabot #21034, #21031, #21035) #21125 (oclif,
area:devpath, samepnpm-lock.yaml) is re-blocked on this card.
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsCorrection to this card's item 5 (Changeset), from the PM seat that wrote it
Read 2026-10-01T09:05Z. Item 5 says "After exclusion 1,
plugin-authis not among them." That is wrong.plugin-authalso declares@noble/hashesandjoseindependencies, and #21029 moves both:^2.3.0to^2.4.0and^6.2.8to^6.2.12. Excluding the five better-auth lines does not take the package out.Measured over #21029's manifest diff against its merge base: excluding
apps/docsand the better-auth lines, 19 published packages have adependenciesrange that moves:@objectstack/cliandcreate-objectstack@objectstack/connector-mcp@objectstack/core,@objectstack/objectql,@objectstack/rest,@objectstack/runtimeand@objectstack/spec@objectstack/driver-mongodb,@objectstack/driver-sqlite-wasmand@objectstack/driver-turso@objectstack/mcp@objectstack/metadata-core,@objectstack/metadata-protocoland@objectstack/metadata@objectstack/plugin-auth,@objectstack/plugin-hono-serverand@objectstack/plugin-pinyin-search@objectstack/service-settings
The
patchchangeset names those 19. If item 4's premise fails and@libsql/clientstays on^0.17.3,driver-tursostill moves because ofzod. The dispatched dev re-derives the list from its own diff, and this comment is not a substitute for that.
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 21094, "status": "done", "branch": "claude/issue-21094-prod-deps-group", "pr": "https://github.com/objectstack-ai/objectstack/pull/21162", "session": "session_018gA1pE6eJtwHhqx72G8U9X", "premise_still_valid": true, "summary": "Draft PR #21162 (head 56e421979) takes the 2026-10 production-dependency group. Dependabot #21029's 63 range moves were re-applied one at a time onto current main, each guarded by an exact-match check, across 43 manifests. apps/docs (next) and the five better-auth lines in plugin-auth were left out; better-auth stays at 1.7.3 and pnpm-workspace.yaml is untouched. The lockfile was regenerated with pnpm 10.31.0. Compared pair by pair with merge base b616c0a6, no resolved version went DOWN, and nodemailer stays at 10.0.13. Item 4: @libsql/client is lifted to ^0.18.0 because the premise holds. All 21 sites stamped 0.17.4 in driver-turso/src re-measure identically on 0.18.0 and are restamped (version pin, docblocks, and the four refusal messages). A patch changeset names the 19 published packages whose dependencies ranges move, re-derived from this diff; the list matches PM correction 5928286488, plugin-auth included. One step beyond H3: plain `pnpm install --lockfile-only` left hono at 4.13.7, below the published ^4.13.9, because the hono override rewrites declarations to ^4.13.5 and lockfile inertia held 4.13.7. A filtered `pnpm update --lockfile-only --no-save hono` over the three hono importers moved the single hono copy to 4.13.12. That touched no manifest and no override (see deviations).", "item4_libsql": "LIFTED to ^0.18.0. The premise held, measured three ways before any driver edit. (1) npm-pack diff: @libsql/core 0.17.4 vs 0.18.0 differs only in package.json's version. @libsql/client differs only in lib-esm/sqlite3.js, lib-cjs/sqlite3.js, sqlite3.d.ts and package.json: a connection pool for the local file: client. http.js, ws.js and node.js are byte-identical, and so are the installed @libsql/hrana-client 0.10.0 and native libsql 0.5.29. (2) One probe script run against side-by-side installs gives identical output except the version strings and the syncUrl count in sqlite3.js (3 to 4, the new pool-size line). Readings on 0.18.0: expandConfig maps WSS to wss, Ws to ws, LIBSQL to https (control) and FILE: to file; :memory: expands to file::memory:; isInMemoryConfig is true for file::memory: and its query form, false for the file:./x.db control. createClient gives URL_INVALID for ./data/app.db, data/app.db, /abs/app.db, :MEMORY:, empty and libsql:host, and URL_SCHEME_NOT_SUPPORTED for sqlite:, memory:// and a C: path. Remote sync() rejects SYNC_NOT_SUPPORTED on https and ws. :memory:+syncUrl throws URL_INVALID 'Embedded replica must use file for local db'. Line counts: syncUrl in http.js 0, ws.js 0 (control authToken 6 and 6); ws.js fetch 0, timeout 0; hrana ws/*.js+index.js timeout 0 (control http fetch 15). The api.d.ts docblock 'remote clients ignore it' is byte-identical. (3) driver-turso suite: 0.17.4 at base, 2210 passed / 33 skipped. 0.18.0 before the restamp, 2209 passed / 1 failed / 33 skipped, per-test outcomes identical except the version pin. After the restamp at 56e421979, 2210 passed / 33 skipped. Every claim: held. The pin moved to 0.18.0 by design.", "tests": "All exit 0, read from vitest/turbo summary lines with exit codes captured before any pipe. driver-turso full suite as in item4_libsql, at 56e421979 after merge and full rebuild, plus `pnpm --filter @objectstack/driver-turso run typecheck` passing. H4's eight packages at cf1d700b (pre-merge), via turbo test (45/45 tasks): rest 250 files 4728 passed / 248 skipped; driver-sql 205 files 3303 passed / 188 skipped; plugin-email 31/510; plugin-approvals 52/804; plugin-webhooks 13/160; trigger-schedule 8/170; connector-mcp 3/23; client-react 3/34. Packages whose own deps moved, at cf1d700b (41/41 tasks): driver-mongodb 30 files 675 passed / 172 skipped; mcp 32/344; plugin-hono-server 27/324; plugin-auth 115/2472; service-settings 33/584; plugin-pinyin-search 2/21; driver-sqlite-wasm 36/675; driver-memory 69/1613; service-analytics 155/3526 (10 skipped); create-objectstack 16/247; @objectstack/hono 5/122. Also `pnpm --filter @objectstack/cli exec vitest run --project unit` 242 files / 3432 passed, and `@objectstack/spec` `--project local` 591 files / 17368 passed. Typecheck via turbo over the 19 movers plus client-react, hono and lint: 80/80 tasks. OSV: osv-scanner v2.3.8, built from the Go module proxy because api.osv.dev is egress-denied, run on the offline npm DB over lockfile blob 70547c67 with osv-scanner.toml loaded: 1388 packages, 'No issues found', exit 0. Its positive control (same lockfile, hono rewritten to 4.12.32) gave exit 1 with 8 hono advisories including GHSA-8j4g-w8fx-2239. z.properties: `git grep -n -E \"z\\.properties\\(\" -- packages/` 0 lines (exit 1); control z.object( 1825. NOT MEASURED: driver-mongodb live-mongod suites, because fastdl.mongodb.org is egress-denied (CONNECT 403). NOT MEASURED locally: the 72 Lint & Repo Gates steps after check:vendor-export-contract, which belong to CI; the vendor-export-contract step itself passed locally. No ablation applies: there is no new guard, only re-measurement.", "gates": "`node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands` (no paths) at HEAD 56e421979 derived 100 commands over 52 paths against merge base f20f669e1, identical to the pre-merge derivation. All 100 exit 0, plus `pnpm check:vendor-export-contract` exit 0 ('VERDICT: PASS — vendor export contract (installed workspace), 1 edge(s) verified'). `--ran` gives 'Run reconciliation — 100 derived, 100 run, 0 NOT-MEASURED, 0 UNRUN' with an exit code on every line. Pre-merge, two gates refused on the shallow clone: check-engine-split-ratio --days 90 (exit 2) and check-plugin-teardown-shape --self-test (exit 3). That is PREREQUISITE NOT MET, not red; after `git fetch --shallow-since=2026-06-26 origin main` both exit 0. The seven filtered `pnpm --filter @objectstack/spec run check:*` logs each echo their script name. CI on 56e421979 at report time: 35 check runs, 13 success, 2 skipped, 20 in_progress.", "mcp_calls": "0 — no MCP GitHub tool was called", "api_writes": "3 — each a fleet-write relay stroke (POST /repos/objectstack-ai/objectstack/dispatches) executed as objectstack-fleet[bot]: (1) pr_create -> POST /repos/objectstack-ai/objectstack/pulls (#21162, draft forced, body read back byte-identical 13513/13513); (2) label-write --assign os-bill -> POST /repos/objectstack-ai/objectstack/issues/21162/assignees (read-back matches; size/m was added by another actor); (3) post-stamped -> POST /repos/objectstack-ai/objectstack/issues/21094/comments (this report). Zero label writes: no label is named and a changeset exists. git push is not REST.", "open_questions": [], "out_of_scope_findings": [ "carrier: none · noted, not filed — packages/spec/src/data/driver/common.zod.ts:269 (the TSDoc of CREDENTIAL_URL_QUERY_PARAMS, 'measured ... in the versions pinned by this tree') and driver-credential-refusal.test.ts:325 name @libsql/core@0.17.4. Re-measured on 0.18.0, the behaviour is identical: ?authToken= overrides the config token, auth%54oken is decoded, AuthToken and token give URL_PARAM_NOT_SUPPORTED, and the no-query control keeps the config token. Only the version label goes stale. Editing packages/spec src would add 27 gate families beyond this derivation (bounded-fix condition 4 fails). The edit is two version strings, 0.17.4 to 0.18.0, for whoever next touches those files.", "carrier: none · noted, not filed — libsql 0.18.0 pools the local sqlite3 client with a single connection for syncUrl. From reading the code (not measured), a second replica sync() now queues behind an uncancelled first one that outlived TursoDriverConfig.timeout, where on 0.17.4 both ran concurrently on one native handle. No driver docblock claims either behaviour.", "carrier: PM (filing, per its mid-run message) · noted, not filed — turbo 2.11.5 agentGuidance appends a managed block to the root AGENTS.md on every repository-scoped turbo run in an agent session." ], "deviations": [ "Lockfile, beyond H3's single command: after `pnpm install --lockfile-only`, also ran `pnpm --filter @objectstack/plugin-hono-server --filter @objectstack/plugin-auth --filter @objectstack/hono update --lockfile-only --no-save hono` (commit 12a5ae80). This was needed because the `hono` override (selector below 5.0.0, target ^4.13.5) left hono at 4.13.7, below plugin-hono-server's published ^4.13.9. Side effect, found when reading the hunks: the vitest snapshot of the `packages/apps/account` importer moved from the esbuild 0.28.1 peer copy to the 0.28.2 copy already present (up, not down). esbuild 0.28.1 stays in the lockfile for other importers. An unfiltered `pnpm update -r` was tried and reverted (`git checkout HEAD -- pnpm-lock.yaml`) because it dropped knex's mysql2/pg/tedious peer links in two importers. To undo: revert 12a5ae80; plain install output was 338da254's lockfile.", "Environment side effect (PM message): turbo re-added its block to AGENTS.md after turbo runs. Restored 7 times with `git restore --source=HEAD --staged --worktree AGENTS.md`. `git status --porcelain` was empty before every commit, and no commit on the branch lists AGENTS.md (checked per commit with `git show --name-only`). Some gate and test runs executed while the block was present in the working tree; all were green.", "Shared .git deepened (additive): `git fetch --shallow-since=2026-06-26 origin main` for the two shallow-refused gates.", "The H4 and direct-mover package suites ran at cf1d700b, before merging main at f20f669e1. After the merge: full rebuild, the driver-turso suite and typecheck, and the full 100-gate union at 56e421979. main has since moved to 2488b98b4 (2 commits, neither on this PR's paths); not re-merged.", "Claim comment 5928265691 says '44 manifests ... minus apps/docs' and the dispatch says 43. #21029 touched 44 including apps/docs, so 43 land here, matching the dispatch.", "Commit trailers use AGENTS.md's model-free pair (Claude-Session + Co-authored-by: Claude), not the harness reminder's model-named form. The PR body footer follows AGENTS.md's session-URL form.", "PR body omission (body written once, not PATCHed): the lockfile bullet's step 2 does not name the side effect above. Correction for the seat, if wanted: append \"Side effect: `packages/apps/account`'s vitest snapshot moves from the esbuild 0.28.1 peer copy to the 0.28.2 copy already present.\" to that bullet." ], "line_budget": "n/a — no skills/** or line-ratcheted ledger in the diff; PR diff 52 files +626/-552 vs main (under the 5,000-line class-(c) bound); no governed surface", "files_changed": "52: 43 package.json (examples/app-showcase, examples/app-todo, root, packages/{adapters/hono, cli, client-react, client, connectors/connector-mcp, core, create-objectstack, drivers/driver-memory, drivers/driver-mongodb, drivers/driver-sqlite-wasm, drivers/driver-turso, lint, mcp, metadata-core, metadata-protocol, metadata, objectql, plugins/{embedder-openai, knowledge-memory, knowledge-ragflow, organizations, plugin-approvals, plugin-audit, plugin-auth, plugin-dev, plugin-email, plugin-hono-server, plugin-pinyin-search, plugin-security, plugin-sharing, plugin-webhooks}, rest, runtime, services/{service-analytics, service-automation, service-cluster, service-knowledge, service-settings, service-storage}, spec}); pnpm-lock.yaml; packages/drivers/driver-turso/src/{turso-driver.ts, turso-authtoken-url-channel.test.ts, turso-driver-remote-url-replica-refusal.test.ts, turso-driver-timeout.test.ts, turso-driver-unrecognised-url-refusal.test.ts, turso-driver-uppercase-ws-scheme-timeout-refusal.test.ts, turso-driver-ws-timeout-refusal.test.ts}; .changeset/21094-prod-deps-group.md" }
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsReview: REWORK, patch round 1, PR #21162 (head
56e4219798)Reviewed 2026-10-01T11:05Z by the PM seat (
session_018gA1pE6eJtwHhqx72G8U9X) against GitHub and the branch.Holds as reported, verified at the head:
- Shape: the PR is a draft against
main. Its body opensFixes #21094, with no other closing keyword. The assignee isos-bill. - Scope: 52 files.
- No
AGENTS.md,turbo.json,pnpm-workspace.yaml,apps/docs/package.jsonor other governed path is in the diff. plugin-auth's five better-auth lines are still1.7.3.
- No
- Lockfile: compared pair by pair against the merge base
f20f669e17, 0 versions go down.nodemailer@10.0.13,hono@4.13.12,better-auth@1.7.3.- Only
@libsql/client@0.18.0and@libsql/core@0.18.0remain; no 0.17.4 copy.
- Changeset: it names exactly the 19 packages of correction 5928286488, all
patch. - Item 4: the premise is measured three ways and holds, so the lift is right.
The one REWORK item. The PR makes published text false; the review checklist calls that a must-fix in this round.
packages/spec/src/data/driver/common.zod.tsships in@objectstack/spec. That package is one of this changeset's 19, so the text ships in the same release.- Its TSDoc for
CREDENTIAL_URL_QUERY_PARAMSsays it was measured "in the versions pinned by this tree" and names`@libsql/core@0.17.4`. - After this PR the tree pins only 0.18.0, so the label becomes false. The behaviour it describes does not: the os-dev's report re-measured it as identical on 0.18.0.
- The fix: restamp that label, and its echo in
driver-credential-refusal.test.ts, to the version actually measured. Nothing else changes. - "Out of scope: 27 gate families" does not apply. It is the rule for an adjacent defect the PR did not cause; this PR causes this one.
Owed after the patch round:
.changesetprose is on this diff, and the patch round adds published spec source (packages/spec/src/**, non-test). Both are contract-review surfaces, so the PR also owes aCONTRACT_REVIEW_TIERreview record before it queues. The seat runs that review on the patched head.Noted from the report: the PR body's lockfile bullet does not mention that
packages/apps/account's vitest snapshot moved from the esbuild 0.28.1 peer copy to the 0.28.2 copy already present (upward, and tool-generated). It is recorded here; the body stays as written.
Generated by Claude Code
- Shape: the PR is a draft against
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 21094, "patch_round": 1, "status": "done", "branch": "claude/issue-21094-prod-deps-group", "pr": "https://github.com/objectstack-ai/objectstack/pull/21162", "session": "session_018gA1pE6eJtwHhqx72G8U9X", "premise_still_valid": true, "summary": "Patch round 1, per verdict 5930050869, is one commit, a2d5d53c4, now pushed and the PR head. It restamps the @libsql/core version label from 0.17.4 to 0.18.0 in two places: the TSDoc of CREDENTIAL_URL_QUERY_PARAMS (packages/spec/src/data/driver/common.zod.ts:269) and its echo in driver-credential-refusal.test.ts:325. Nothing else in packages/spec changed; the diff is 2 files, +2/-2. The commit body cites the 0.18.0 re-measurement, run again in this round against the repo's installed @libsql/core 0.18.0. With config authToken 'BINDER': url ?authToken=URLTOK gives URLTOK (the URL overrides); ?auth%54oken=URLTOK gives URLTOK (the key is percent-decoded); ?AuthToken= and ?token= give URL_PARAM_NOT_SUPPORTED; the no-query control keeps BINDER. No generated artifact carries that TSDoc text: a git grep over packages/spec outside src and CHANGELOG.md, content/docs and skills returns 0 hits. The PR body, draft state and labels were not touched. main moved to c35436c75 but on none of this PR's paths, so it was not merged and the lockfile is unchanged.", "remaining_0_17_4_hits": "`git grep -n \"0\\.17\\.4\" -- packages/` at a2d5d53c4 returns 10 lines; positive control `git grep -n \"libsql/core@0\\.18\\.0\" -- packages/` returns 9 (7 in driver-turso/src, 2 in spec). Lines that STAY: (a) 8 in CHANGELOG.md files, release-owned and never edited in a code PR. Each records a measurement in an already-published release entry and is still true of that release: driver-turso CHANGELOG.md:159, 174, 1432, 1535, 1555; service-datasource CHANGELOG.md:2349; spec CHANGELOG.md:15745, 28094. (b) 2 in service-package: src/index.ts:192 and src/mysql2-tuple.test.ts:172, both 'Measured on `@libsql/client` 0.17.4, `result.rows` is a real array...'. That is a dated attestation, not a 'pinned by this tree' live reading, so it stays true. The rows shape was also re-measured identical on 0.18.0 last round (rows is an array, rows[0] a plain object). service-package does not depend on @libsql/client. Lines that GO: none remain in non-CHANGELOG source with a live-reading phrase.", "item4_libsql": "Unchanged from round 0: LIFTED to ^0.18.0, premise held. This round extends the restamp to the two spec sites.", "tests": "`pnpm --filter @objectstack/spec exec vitest run --project local --maxWorkers=2 src/data/driver/driver-credential-refusal.test.ts` gives 1 file, 152 passed, exit 0. Full turbo build first (72/72 tasks), because the gates read dist. The four authToken behaviours were re-measured on the installed @libsql/core 0.18.0 (see summary). The round-0 package suites still stand for the unchanged code.", "gates": "`node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands packages/spec/src/data/driver/common.zod.ts packages/spec/src/data/driver/driver-credential-refusal.test.ts` at a2d5d53c4 derived 79 commands; all 79 exit 0, with exit codes captured before any pipe. `--ran` over those two paths gives 'Run reconciliation — 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN'. These include check:api-surface, check:docs, check:authorable-surface, check:spec-docblock-symbol-anchors, check:type-check-coverage and check:type-check-debt. Each of the 18 filtered `pnpm --filter ... run check:*` logs echoes its script name. Full-branch union at the new head: the no-path derivation (54 paths against f20f669e1) gives 117 commands. The 38 not among the 79 were also run at a2d5d53c4, all exit 0. `--ran` gives 'Run reconciliation — 117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN', a derived zero. CI on a2d5d53c4 at report time: 38 check runs, 35 success, 2 skipped, 1 in_progress.", "mcp_calls": "0 — no MCP GitHub tool was called", "api_writes": "1 this round — a fleet-write relay stroke (POST /repos/objectstack-ai/objectstack/dispatches) running post-stamped, which does POST /repos/objectstack-ai/objectstack/issues/21094/comments (this report). No PR body, draft or label write. git push a2d5d53c4 is not REST.", "open_questions": [], "out_of_scope_findings": [], "deviations": [ "The worktree had been removed (node_modules, then `git worktree remove`, no --force) as round 0's cleanup step. For this round it was recreated at the same path on the same branch: `git worktree add ../objectstack-issue-21094 claude/issue-21094-prod-deps-group`, at 56e421979, which matched origin. Then `pnpm install --frozen-lockfile`.", "turbo re-added its block to AGENTS.md during the build and the gate runs. Restored 2 times with `git restore --source=HEAD --staged --worktree AGENTS.md`. `git diff --cached --name-only` before the commit listed only the two spec files, and commit a2d5d53c4 touches only them.", "main moved from f20f669e1 to c35436c75 (6 commits), none on this PR's paths, so it was not merged, per instruction 4." ], "line_budget": "n/a — no skills/** or line-ratcheted ledger; this round +2/-2 in 2 files; PR diff now 54 files vs main", "files_changed": "this round: packages/spec/src/data/driver/common.zod.ts; packages/spec/src/data/driver/driver-credential-refusal.test.ts (PR total 54: round 0's 52 plus these 2)" }
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsMerge queue ejected PR #21162 — signature and first diagnosis
Recorded 2026-10-01T11:55Z by the PM seat (
session_018gA1pE6eJtwHhqx72G8U9X). The full triage is on PR #21162.- Signature. Queue run 36857772834 failed at step
Install dependencieswithERR_PNPM_LOCKFILE_MISSING_DEPENDENCY Broken lockfile: no entry for 'tsx@4.23.12' in pnpm-lock.yaml. Four jobs carry the same first error. - Diagnosis. A deterministic lockfile conflict with feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160, which was queued ahead and is not a flake. feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 adds
tsx ^4.23.12(resolved to 4.23.12) to driver-turso, and this card's PR removes thetsx@4.23.12entry. Not re-queued. - Next. Patch round 2 starts after feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 lands: merge
main, lift driver-turso's newtsxto^4.23.15, and regenerate the lockfile with pnpm. A fresh contract-review record is then owed on the new head.
Generated by Claude Code
- Signature. Queue run 36857772834 failed at step
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 21094, "patch_round": 2, "status": "done", "branch": "claude/issue-21094-prod-deps-group", "pr": "https://github.com/objectstack-ai/objectstack/pull/21162", "head": "0f87e8488", "session": "session_018gA1pE6eJtwHhqx72G8U9X", "premise_still_valid": true, "summary": "Patch round 2 fixes the merge-queue ejection (triage 5930776004 / 5930785114) with two commits, both pushed, no rebase, amend or force. (1) 4e92c58bc merges origin/main at e35c40a52, the commit where #21160 landed. There was no textual conflict, but the merged lockfile was broken: `pnpm install --frozen-lockfile` failed locally with exactly the queue signature, ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY ... no entry for 'tsx@4.23.12'. (2) 0f87e8488 lifts the tsx devDependency #21160 added to packages/drivers/driver-turso/package.json from ^4.23.12 to ^4.23.15, with an exact-match guard. A grep then finds no `\"tsx\": \"^4.23.12\"` in any package.json; all 27 tsx declarations read ^4.23.15. It regenerates pnpm-lock.yaml with `pnpm install --lockfile-only` (pnpm 10.31.0), never by hand. Result: a fixed point (a second lockfile-only run is byte-identical), frozen install passes, and the lockfile blob is 30ba2147. The tsx lift is a devDependency, so the changeset text and package list are unchanged. The PR body, draft state and labels were not touched.", "lockfile_vs_new_main": "Resolved name@version pairs (packages: section) compared with main e35c40a52: 25 names change, DOWN: 0. They are the same 25 as round 0 against the old base: @libsql/client and @libsql/core 0.17.4 to 0.18.0; zod +4.6.5; @modelcontextprotocol/sdk 1.30.0 to 1.31.0; hono 4.13.7 to 4.13.12; mongodb +7.7.0; jose 6.2.7 and 6.2.8 to 6.2.12; @noble/hashes 2.3.0 to 2.4.0; @noble/ciphers +2.4.0; react, react-dom, @types/react and @types/react-dom +19.3.0; tsx 4.23.12 to 4.23.15; yaml +2.9.1; chalk 6.0.0 to 6.0.1; sql.js 1.14.1 to 1.14.2; pinyin-pro 3.29.1 to 3.29.4. Dedupes onto copies already present: @hono/node-server 2.0.12, ws 8.21.1, @types/ws 8.18.1 and eventsource-parser 3.1.0 are removed. New transitive copies: bson 7.3.3 and @mongodb-js/saslprep 1.5.5 (with mongodb 7.7.0), scheduler 0.28.0 (with react-dom 19.3.0). Re-confirmed: nodemailer 10.0.13 only. better-auth, @better-auth/core, sso, scim and oauth-provider are 1.7.3 only, all 5 importer entries resolve 1.7.3, the overrides block is unchanged, and the lockfile has 0 occurrences of 1.7.6. @libsql/client and @libsql/core are 0.18.0 only, with 0 occurrences of 0.17. The resolved set equals round 0's OSV-scanned lockfile (blob 70547c67): 0 names differ, so that scan's 'No issues found' covers the same versions. CI's online OSV step remains authoritative.", "tsx_copies": "1 resolved copy, tsx@4.23.15: one packages entry plus one snapshots entry, and all 27 importer declarations give `version: 4.23.15`. 0 occurrences of tsx@4.23.12.", "census_0_17_x": "`git grep -n '0\\.17\\.[0-9]' -- packages/ content/docs skills ':!**/CHANGELOG.md'` at 0f87e8488 returns 2 lines, both STAY as dated attestations: packages/services/service-package/src/index.ts:192 and src/mysql2-tuple.test.ts:172, 'Measured on `@libsql/client` 0.17.4, `result.rows` is a real array ...'. Neither claims the pinned version; the rows shape was re-measured identical on 0.18.0 in round 0, and service-package does not depend on libsql. GO: none. #21160 brought no 0.17.x string. Its libsql readings are anchored to commits ('Measured on `main` @ `2f3e79351`', and the reverse-verification note recorded in its PR), so they stay true. Positive control: `git grep -o '0\\.18\\.0'` gives 23 occurrences in driver-turso/src (13 in turso-driver.ts, which #21160's merge left in place) and 2 in packages/spec/src/data/driver, unchanged from round 1.", "item4_libsql": "Unchanged: LIFTED to ^0.18.0. #21160's new and rewritten driver-turso tests were written against 0.17.4 and run here on 0.18.0, all passing: turso-remote-autonumber-generation 27/27, turso-remote-autonumber-concurrency 1/1, turso-autonumber-resync 3/3, turso-autonumber-batch-resync 5/5, turso-update-missing-id 10/10. The concurrency test runs two child processes, each on 0.18.0's pooled native file: client, so it is the one most exposed to 0.18.0's only code change. It passed and was not skipped; its own measurement line reads '[turso-remote-autonumber-concurrency] pids 6303/6304 · 400 writes · 400 distinct · 13 writer change(s)', so the two writers overlapped.", "tests": "At 0f87e8488, after a full turbo build (72/72 tasks): `pnpm --filter @objectstack/driver-turso exec vitest run --maxWorkers=2` gives 82 files, 2218 passed / 33 skipped / 0 failed, and `pnpm --filter @objectstack/driver-turso run typecheck` (tsc --noEmit) passes; lock VERDICT command-exit 0. The 33 skipped are the same constructor-parity cases as round 0. Locally, `pnpm install --frozen-lockfile` fails (exit 1) on the merge commit 4e92c58bc, reproducing the queue signature, and passes on 0f87e8488.", "gates": "This round's paths, `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands packages/drivers/driver-turso/package.json pnpm-lock.yaml`, derive 52 commands. The full-branch union (no paths: 54 paths against merge base e35c40a52) derives 117, a superset. All 117 ran at 0f87e8488, all exit 0, exit codes captured before any pipe; `pnpm check:vendor-export-contract` also exit 0. `--ran` over the two paths: 'Run reconciliation — 52 derived, 52 run, 0 NOT-MEASURED, 0 UNRUN'. `--ran` over the union: 'Run reconciliation — 117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN', a derived zero. The union includes check:override-consistency, check:vendor-export-contract-resolve and check-osv-exemptions. All 19 filtered `pnpm --filter ... run check:*` logs echo their script name. CI on 0f87e8488 at report time: 38 check runs listed, 36 success, 2 skipped (the queue run is the authoritative one).", "mcp_calls": "0 — no MCP GitHub tool was called", "api_writes": "1 this round — a fleet-write relay stroke (POST /repos/objectstack-ai/objectstack/dispatches) running post-stamped, which does POST /repos/objectstack-ai/objectstack/issues/21094/comments (this report). No PR body, draft or label write. The git push of 4e92c58bc and 0f87e8488 is not REST.", "open_questions": [], "out_of_scope_findings": [], "deviations": [ "For the reviewer, the regeneration's one change beyond tsx: `pnpm install --lockfile-only` on the merged tree returned packages/apps/account's vitest snapshot to main's esbuild 0.28.1 peer variant. That undoes the dedupe round 0's filtered `pnpm update ... hono` had made there; the extra vitest/vite/@vitest/mocker snapshots for that variant come back. Against main, this PR no longer changes that importer's esbuild variant. The only lines touching it differ in the tsx, yaml and @noble/hashes versions inside its peer suffix. The round-0 deviation about that side effect is therefore moot at this head.", "The PR body (unedited, per instruction) is stale against this head in three readings: '63 range moves' is now 64 across the same 43 manifests (driver-turso's new tsx line); 'Lockfile blob 70547c67' is now 30ba2147, with the same resolved set; and '52 paths' is now 54 (the two round-1 spec files). Its 'HEAD 56e421979' gate readings are superseded by this report's readings at 0f87e8488.", "The worktree was recreated at the same path on the same branch (`git worktree add ../objectstack-issue-21094 claude/issue-21094-prod-deps-group` at a2d5d53c4, which matched origin), after round 1's cleanup had removed it. Then `pnpm install --frozen-lockfile`.", "AGENTS.md: after the merge, turbo.json carries #21151's `\"agentGuidance\": false`, and turbo wrote no block this round. `git status --porcelain` was empty after the build, the gates and the tests; 0 restores were needed, and neither commit lists AGENTS.md.", "main has since moved to 327391c3a (1 commit, not on this PR's paths); not merged again." ], "line_budget": "n/a — no skills/** or line-ratcheted ledger; this round's own commit is 2 files (driver-turso package.json +1/-1, pnpm-lock.yaml +58/-3); PR diff vs main now 54 files +640/-511, under the 5,000-line bound; no governed path", "files_changed": "this round: packages/drivers/driver-turso/package.json; pnpm-lock.yaml (plus merge commit 4e92c58bc bringing main e35c40a52). PR total vs main: 54 files (43 package.json, pnpm-lock.yaml, 7 driver-turso src files, 2 packages/spec/src/data/driver files, .changeset/21094-prod-deps-group.md)" }
Generated by Claude Code
- added a commit that references this issue
on Oct 7, 2026
Filing-gate class: ③ maintainer-directed task.
Body last written 2026-10-01T09:03Z: the serial wait on #21102 is over (#21024 merged as 840ec9d; #21102 closed completed).
Acting reader: the triage seat grades this card (domain / area / priority); the lane seat it names dispatches one
os-dev.Dedup:
repo:objectstack-ai/objectstack is:issue "21029" OR "production-dependencies" OR "@libsql/client@0.18", open and closed: 160 hits by relevance; the only one in scope is #21055 (thenext+dompurifyOSV fix), which this card deliberately excludes. No card exists for this group.Filed by: PM seat, session
session_018gA1pE6eJtwHhqx72G8U9X.Maintainer ruling (verbatim)
Given in session
session_018gA1pE6eJtwHhqx72G8U9Xon 2026-10-01, in reply to the seat's risk read of #21024 and #21029. The recommendation it accepts: close #21029, carry its safe part on this card, and leave the better-auth family where it is.What to land
Dependabot's #21029 (closed in favour of this card) bumped 27 production dependencies. Take them, with these exceptions and corrections.
better-auth,@better-auth/core,@better-auth/oauth-provider,@better-auth/scimand@better-auth/ssostay at1.7.3inpackages/plugins/plugin-auth/package.json, and the family's override targets inpnpm-workspace.yamlstay untouched. A lift is a separate reviewed edit (see the overrides note inpnpm-workspace.yaml, bug(plugin-auth): published 17.1.0/17.2.0/17.3.0 float@better-auth/coreto 1.7.3, which droppedcreateLocalAccountIssuer— a freshobjectstack dev --seed-adminnever creates the system tables and never seeds #16186), and the maintainer deferred it.check:vendor-export-contractandcheck-override-consistencywere both red on exactly that.next: excluded. [finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055 owns raisingapps/docs'snextto 16.3.6 or later. If [finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055 merges first, mergemainand leavenextalone.nodemailerDOWN from 10.0.12 to 10.0.11. The change was lockfile-only;plugin-emaildeclares^10.0.2.requireTLS-over-ignoreTLSbehaviour fix(deps): take the fix for the seven OSV advisories turning Validate Package Dependencies red #20564's changeset documented to operators.nodemailerresolves to 10.0.12 or later.@libsql/client0.17.x to 0.18.x: a ruling gated on a premise.packages/drivers/driver-tursoto^0.18.0.@libsql/client@0.17.4re-measures identically on the resolved 0.18.x.origin/main63d1a7c:src/turso-driver.ts: 12 citations, including refusal message text at lines 1001, 1061, 1384 and 1417.src/turso-authtoken-url-channel.test.ts: the measurement docblock at lines 17-18 and the version pin at line 281.src/turso-driver-remote-url-replica-refusal.test.ts,src/turso-driver-timeout.test.ts,src/turso-driver-unrecognised-url-refusal.test.ts,src/turso-driver-uppercase-ws-scheme-timeout-refusal.test.tsandsrc/turso-driver-ws-timeout-refusal.test.ts.git grep -n -E "0\.17\.[0-9]" -- packages/drivers/driver-turso/src^0.17.3, finish the rest of this card, and report the fork with the differing measurement.patchchangeset naming every published package whosedependenciesrange moves. After exclusion 1,plugin-authis not among them. Do not useskip-changeset: these ranges reach consumers.Measure what #21029 never measured
#21029's red jobs stopped early, so these were never run. Run them here:
rest,driver-sql,plugin-email,plugin-approvals,plugin-webhooks,trigger-schedule,connector-mcpandclient-react.Lint & Repo Gatesstopped atcheck:vendor-export-contract; every gate after it is unmeasured.Validate Package Dependencieswas never reached.Notes from the risk read (not acceptance criteria)
zod4.6.5 removes the standalonez.properties()schema.git grep "z\.properties("overpackages/gives 0 hits at 63d1a7c.mongodb7.6: the live-mongod suites are opt-in (OS_TEST_MONGODB_MEMORY_SERVER_ENABLED). Consider running them once.next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055 (in flight) also touchesapps/docs/package.jsonandpnpm-lock.yaml. Seven open Dependabot PRs touchpnpm-lock.yamltoo: chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 16 updates #21024 and chore(deps)(deps-dev): bump @vitest/coverage-v8 from 4.1.11 to 5.0.2 #21030 to chore(deps)(deps-dev): bump @oclif/plugin-plugins from 5.4.87 to 7.0.3 #21035. Mergemainright before opening the PR.Expected file surface
package.jsonthat chore(deps)(deps): bump the production-dependencies group with 27 updates #21029 touched, minusplugin-auth's better-auth lines andapps/docs'snext.pnpm-lock.yaml, regenerated.packages/drivers/driver-turso/src/**, for item 4 only..changesetfile.Generated by Claude Code