Skip to content

chore(deps): take the 2026-10 production-dependency group without the better-auth family (#21094) - #21162

Merged
objectstack-fleet[bot] merged 8 commits into
mainfrom
claude/issue-21094-prod-deps-group
Oct 1, 2026
Merged

objectstack-fleet[bot] merged 8 commits into
mainfrom
claude/issue-21094-prod-deps-group

Conversation

@objectstack-fleet

@objectstack-fleet objectstack-fleet Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #21094

Clause-②: no

Takes the 2026-10 production-dependency group that Dependabot opened as #21029 (closed in favour of this card), without the better-auth family and without next. Maintainer ruling, verbatim:

按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地

What lands

Resolved versions against the merge base

Every changed name@version pair in the packages: section, compared with main at e35c40a52: 25 names change. DOWN: 0.

package merge base this branch
@libsql/client / @libsql/core 0.17.4 0.18.0
zod 4.6.1 4.6.5 (4.6.1 kept by apps/docs only)
@modelcontextprotocol/sdk 1.30.0 1.31.0
hono 4.13.7 4.13.12
mongodb 7.5.0 7.7.0 (7.5.0 kept by mongodb-memory-server-core only)
jose 6.2.7, 6.2.8 6.2.12
@noble/hashes 2.3.0 2.4.0
@noble/ciphers 2.3.0 2.4.0 (2.3.0 kept by better-auth 1.7.3 only)
react / react-dom / @types/react / @types/react-dom 19.2.x 19.3.0 (19.2.x kept by apps/docs only)
tsx 4.23.12 4.23.15
yaml 2.9.0 2.9.1 (2.9.0 kept by the apps/docs fumadocs tree only)
chalk 6.0.0 6.0.1
sql.js 1.14.1 1.14.2
pinyin-pro 3.29.1 3.29.4
deduped onto a newer copy already present @hono/node-server 2.0.12, ws 8.21.1, @types/ws 8.18.1, eventsource-parser 3.1.0 removed (2.1.1, 8.22.0, 8.18.2, 3.1.1 stay)
new transitive copies beside the old ones none bson 7.3.3 and @mongodb-js/saslprep 1.5.5 (with mongodb 7.7.0), scheduler 0.28.0 (with react-dom 19.3.0)

nodemailer stays at 10.0.13, main's version and at least the required 10.0.12. Dependabot's regeneration had moved it down to 10.0.11.

Item 4: @libsql/client lifted to ^0.18.0, because the premise holds

The premise was measured before any driver edit, three ways.

  1. Package diff. npm pack of both releases. @libsql/core 0.17.4 and 0.18.0 differ only in package.json (the version). @libsql/client differs only in lib-esm/sqlite3.js, lib-cjs/sqlite3.js, lib-esm/sqlite3.d.ts and package.json. The change is a connection pool for the local file: client. http.js, ws.js and node.js are byte-identical. Installed side by side, @libsql/hrana-client 0.10.0 and native libsql 0.5.29 (with @libsql/linux-x64-gnu) are byte-identical too.
  2. Executed probe, same script against both installs. Output is identical except for the version strings and one count: syncUrl occurrences in sqlite3.js go from 3 to 4 (the new pool-size line).
  3. The driver's own suite. At base with 0.17.4: 81 files, 2210 passed, 33 skipped. With 0.18.0, before the restamp: 2209 passed, 1 failed, 33 skipped. Per-test outcomes are identical except the version pin (expected '0.18.0' to be '0.17.4'). After the restamp: 2210 passed, 33 skipped. At 0f87e8488, with feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's tests merged in: 2218 passed, 33 skipped, 0 failed.
site (at base) claim 0.18.0 reading verdict
turso-authtoken-url-channel.test.ts:17-18 client / core / native versions, range client 0.18.0, core 0.18.0, native libsql 0.5.29; range now ^0.18.0. Answers 1-4 (live wire, child-process replica endpoint) pass, 7/7 non-pin cases, as 8/8 did on 0.17.4 held, restamped
turso-authtoken-url-channel.test.ts:281 version pin 0.18.0 pin moved
turso-driver-remote-url-replica-refusal.test.ts:28, turso-driver.ts:1288, :1384 (message) no embedded replica for a remote url syncUrl lines: http.js 0, ws.js 0, control authToken lines 6 / 6. https and ws clients' sync() reject SYNC_NOT_SUPPORTED. :memory: + syncUrl throws URL_INVALID ("Embedded replica must use file for local db"). File 27/27 on both versions held
turso-driver-timeout.test.ts:9, turso-driver.ts:152 HTTP arm rides Config.fetch; replica sync() is native http.js (one config.fetch site) and hrana-client byte-identical. Timeout file 5/5, supplied-client refusal file 13/13 on both held
turso-driver.ts:871 Config.timeout is the busy timeout; "remote clients ignore it" core api.d.ts docblock byte-identical held
turso-driver-unrecognised-url-refusal.test.ts:26, turso-driver.ts:1313, :1417 (message) refusals of urls the client rejects URL_INVALID for ./data/app.db, data/app.db, /abs/app.db, :MEMORY:, empty, libsql:host (bare paths "not in a valid format"). URL_SCHEME_NOT_SUPPORTED for sqlite:, memory://, C:\data\app.db. File 42/42 on both held
turso-driver-uppercase-ws-scheme-timeout-refusal.test.ts:15, :26, turso-driver.ts:932 expandConfig lowercases the scheme before the switch WSS://… gives wss, Ws://… gives ws, control LIBSQL://… gives https. _createClient(expandConfig(config, true)) present (1 hit). File 20/20 on both held
turso-driver-ws-timeout-refusal.test.ts:10, turso-driver.ts:963, :1001 (message) the WS client takes no fetch and no timeout ws.js: fetch 0, timeout 0. hrana ws/*.js + index.js timeout 0, control fetch over http/*.js 15. File 11/11 on both held
turso-driver.ts:1061 (message) a built client's transport cannot be re-seamed config.fetch is read once, inside _createClient in http.js (byte-identical) held
turso-driver.ts:1212 the client folds scheme case and opens each spelling FILE:./x.db gives file, Wss:// gives wss, LIBSQL:// gives https. createClient opens each (http / ws / file) held
turso-driver.ts:1244 :memory: expands to file::memory:; isInMemoryConfig file::memory:. true for file::memory: and file::memory:?cache=shared, control false for file:./x.db held

After the edit, git grep -n -E "0\.17\.[0-9]" -- packages/drivers/driver-turso/src returns 0 lines (exit 1). The control is the 23 0.18.0 occurrences in the same 7 files.

What #21029 never measured

  • Test Core shard 4's eight unreached packages, measured at cf1d700b, before the main merge: rest 250 files, 4728 passed / 248 skipped. driver-sql 205 files, 3303 passed / 188 skipped. plugin-email 31 files, 510 passed. plugin-approvals 52 files, 804 passed. plugin-webhooks 13 files, 160 passed. trigger-schedule 8 files, 170 passed. connector-mcp 3 files, 23 passed. client-react 3 files, 34 passed. Turbo ran 45 of 45 tasks, exit 0.
  • Lint & Repo Gates from check:vendor-export-contract on: pnpm check:vendor-export-contract reads VERDICT: PASS — vendor export contract (installed workspace), 1 edge(s) verified (better-auth 1.7.3), and the -resolve variant passes on the registry. The 72 later steps of that job were not run here. They belong to CI's run on this PR. The families this diff derives are below.
  • OSV. osv-scanner v2.3.8, built from the Go module proxy because this container's egress refuses api.osv.dev. It ran on the offline npm database over lockfile blob 70547c67 (its resolved set is identical to the current 30ba2147), with the repo's osv-scanner.toml loaded: 1388 packages, No issues found, exit 0. Positive control: the same lockfile with hono rewritten to 4.12.32 gives exit 1 and 8 advisories on hono, among them GHSA-8j4g-w8fx-2239. CI's online step is the authoritative reading.
  • zod 4.6.5 and z.properties(): git grep -n -E "z\.properties\(" -- packages/ returns 0 lines; control z.object(, 1825 lines.
  • mongodb live suites: NOT MEASURED. They need a mongod download from fastdl.mongodb.org, which this container's egress refuses (CONNECT 403). The default driver-mongodb suite passes: 30 files, 675 passed, 172 skipped (the five opt-in live files).

Gates and tests

Gate families derived by node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands (no paths, change set from git) at HEAD 0f87e8488 (54 paths against merge base e35c40a52): 117 commands. All 117 exit 0, and so does pnpm check:vendor-export-contract. Exit codes were captured before any pipe. --ran reconciliation: 117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN, a derived zero with an exit code on every line.

Package suites, all exit 0:

Acceptance notes

  • Duplicate copies left by the exclusions: zod 4.6.1, react 19.2.8 and yaml 2.9.0 are kept only by the excluded apps/docs tree. @noble/ciphers 2.3.0 is kept only by the excluded better-auth 1.7.3. mongodb 7.5.0 is kept only by the test harness mongodb-memory-server-core 11.3.0.
  • libsql 0.18.0's one behaviour change, from reading the code (not measured): the local client now pools connections, with one connection for :memory: and for embedded replicas. On a replica, a second sync() therefore waits for the first to release the connection. On 0.17.4 the two ran at once on the same native handle. With timeout set, a sync that outlives the window keeps running natively, uncancelled, so the next periodic sync queues behind it. No driver docblock claims either behaviour.
  • The remaining 0.17.4 stamps stay: outside CHANGELOG.md, only service-package index.ts:192 and mysql2-tuple.test.ts:172 name 0.17.4 ("Measured on @libsql/client 0.17.4"). That is a dated attestation and stays true; the result.rows shape was re-measured identical on 0.18.0.
  • Environment side effect, nothing committed: turbo 2.11.5 appends a managed block to AGENTS.md whenever an agent runs a repository-scoped turbo command. It was restored after each turbo run with git restore --source=HEAD --staged --worktree AGENTS.md. No commit on this branch touches AGENTS.md.
  • Merge-queue ejection and its fix: feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 added driver-turso's tsx at 4.23.12 while this branch removes tsx@4.23.12. The two lockfiles merged into one that pnpm install --frozen-lockfile refuses. Fixed by merging main at e35c40a52, lifting that tsx line, and regenerating the lockfile with pnpm.

Generated by Claude Code

claude added 5 commits October 1, 2026 09:20
… better-auth family

Re-applies Dependabot's production-dependencies manifest moves onto
current main, minus apps/docs (next is owned elsewhere) and minus the
five better-auth family lines, which stay at 1.7.3 with their override
targets. The lockfile is regenerated by `pnpm install --lockfile-only`
(pnpm 10.31.0) from main's lockfile, never by hand.

Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X
Co-authored-by: Claude <noreply@anthropic.com>
`pnpm install --lockfile-only` keeps hono at 4.13.7: the workspace
override `hono@<5.0.0` rewrites every declaration to `^4.13.5`, which
4.13.7 still satisfies, so lockfile inertia leaves CI testing a version
below the `^4.13.9` that plugin-hono-server publishes. Re-resolved with
`pnpm --filter <the three hono importers> update --lockfile-only
--no-save hono`, which moves the single hono copy to 4.13.12 (what a
downstream `^4.13.9` install resolves today) without touching the
override or any manifest.

Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X
Co-authored-by: Claude <noreply@anthropic.com>
…0.18.0

Every behaviour driver-turso documents as measured against
@libsql/client 0.17.4 was re-measured on the resolved 0.18.0 and holds
identically: @libsql/core, hrana-client 0.10.0 and native libsql 0.5.29
are byte-identical across the two releases apart from version strings,
the client's http/ws/node entries are unchanged, and the only code delta
(the local sqlite3 client's connection pool) touches none of the
documented readings. The version pin, the docblocks and the refusal
message text now name the version actually measured.

Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions github-actions Bot added the size/m label Oct 1, 2026
@github-actions github-actions Bot added dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation tests tooling labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 19 package(s): @objectstack/cli, @objectstack/connector-mcp, @objectstack/core, create-objectstack, @objectstack/driver-mongodb, @objectstack/driver-sqlite-wasm, @objectstack/driver-turso, @objectstack/mcp, @objectstack/metadata-core, @objectstack/metadata-protocol, @objectstack/metadata, @objectstack/objectql, @objectstack/plugin-auth, @objectstack/plugin-hono-server, @objectstack/plugin-pinyin-search, @objectstack/rest, @objectstack/runtime, @objectstack/service-settings, @objectstack/spec, touching 5 documentable anchor(s). ⚠️ 19 changed file(s) yielded no anchor (packages/cli/package.json, packages/connectors/connector-mcp/package.json, packages/core/package.json, …), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files.

2 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/data-modeling/drivers.mdx (via authToken (literal, a string literal in a comment on a changed line))
  • content/docs/plugins/packages.mdx (via authToken (literal, a string literal in a comment on a changed line))

⛔ 2 release-owned page(s) also name something this change touched. These are read-only:

  • content/docs/releases/v17/17-1.mdx (via authToken (literal, a string literal in a comment on a changed line))
  • content/docs/releases/v17/17-4.mdx (via TursoDriverConfig (symbol, a top-level interface))

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

What this run could not see
  • 19 changed file(s) yielded no anchor (packages/cli/package.json, packages/connectors/connector-mcp/package.json, packages/core/package.json, …) — pages documenting those are invisible to this run
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 159 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json e35c40a52597c8ca7527e6dd5bc753488dd52bbf → packageMentionDocs.

Which tree this was computed on

This run read content/docs from e0d43f711484d3e392c0c43663afeb276cf7b923 — the merge of head 0f87e8488985230663c0d5ede5c0929d71da204a into base e35c40a52597c8ca7527e6dd5bc753488dd52bbf, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin e0d43f711484d3e392c0c43663afeb276cf7b923 && git checkout e0d43f711484d3e392c0c43663afeb276cf7b923
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin e35c40a52597c8ca7527e6dd5bc753488dd52bbf 0f87e8488985230663c0d5ede5c0929d71da204a && git checkout -B drift-repro e35c40a52597c8ca7527e6dd5bc753488dd52bbf && git merge --no-ff 0f87e8488985230663c0d5ede5c0929d71da204a

node scripts/docs-audit/affected-docs.mjs --json e35c40a52597c8ca7527e6dd5bc753488dd52bbf

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs e35c40a52597c8ca7527e6dd5bc753488dd52bbf → pass the list as
args.docs, on the commit named under Which tree this was computed on.

… 0.18.0 this tree now pins

The TSDoc of CREDENTIAL_URL_QUERY_PARAMS says each entry is measured
"in the versions pinned by this tree" and named @libsql/core 0.17.4;
with the client lifted to ^0.18.0 the tree pins only core 0.18.0, so the
label would have been false in the release that ships it. Its echo in
driver-credential-refusal.test.ts moves with it.

Re-measured on the installed @libsql/core 0.18.0 (expandConfig, with a
config-level authToken 'BINDER'):
- url ?authToken=URLTOK          -> authToken URLTOK (the URL overrides)
- url ?auth%54oken=URLTOK        -> authToken URLTOK (key percent-decoded)
- url ?AuthToken= / ?token=      -> URL_PARAM_NOT_SUPPORTED
- control, no query string       -> authToken BINDER
Identical to the 0.17.4 reading; core 0.17.4 and 0.18.0 differ only in
their package.json version.

Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X
Co-authored-by: Claude <noreply@anthropic.com>
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Review: ACCEPT, patch round 1, PR #21162 (head a2d5d53c4e)

Reviewed 2026-10-01T11:35Z by the PM seat (session_018gA1pE6eJtwHhqx72G8U9X) against GitHub and the branch.

The REWORK item (5930050869) is done, verified at the head:

  • a2d5d53c4 is one commit, 2 files, +2/−2: the CREDENTIAL_URL_QUERY_PARAMS TSDoc in packages/spec/src/data/driver/common.zod.ts and its echo in driver-credential-refusal.test.ts. Both now read `@libsql/core@0.18.0`. Nothing else in packages/spec moved.
  • The commit body records the 0.18.0 re-measurement of the four expandConfig behaviours: ?authToken= overrides the config token, a percent-encoded key is decoded, ?AuthToken=/?token= are refused, and the no-query control keeps the config token.
  • The PR is now 54 files against main, and none is on a governed path.

The remaining 0.17.4 text, counted at the head:

  • git grep -n '0\.17\.4' -- packages/ returns 10 lines. Control: libsql/core@0\.18\.0 returns 9 lines in 6 files.
  • Eight of the ten are in CHANGELOG.md files: driver-turso ×5, service-datasource ×1, spec ×2. Each records a measurement in a release entry that has already shipped, and stays true of that release.
  • Two are in service-package: src/index.ts:192 and src/mysql2-tuple.test.ts:172. Both read "Measured on @libsql/client 0.17.4". That records when a measurement was taken; it makes no claim about what the tree pins, so this PR does not make it false. service-package does not depend on @libsql/client. Stays.
  • Outside packages/ (lockfile excluded): 0 hits.

CI: a red TypeScript Type Check on the superseded head 56e4219798 came from typecheck-workspace/typecheck-consumers being cancelled when this head was pushed, not from a failure. It does not apply to a2d5d53c4.

Still owed: this diff touches published spec source (packages/spec/src/**, non-test) and .changeset prose, both contract-review surfaces. The PR carries needs:contract-review until a CONTRACT_REVIEW_TIER record for this head is on file. It stays a draft until that record reads PASS and every check on the head is green or an expected skip.


Generated by Claude Code

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: a2d5d53c4ef82c67329d2c04cf05d66d59de4948
Local-runs: none

Inputs read: card #21094 (body and all 7 comments), PR #21162 (body, 54-file list, both PR comments), the net diff origin/main...a2d5d53c4 (628/554 lines, origin/main at bafb8c9498), and the 42 check-run rows on the head. The dispatch order and the dispatching seat's conclusions were not inputs; the 19-package list below is re-derived from the manifests, not copied from the card's correction comment.

① Derived judgments

  1. Consumer-facing dependency floors (the accept-set of a consumer install). Derived mechanically from every changed package.json at the head against origin/main: 19 non-private packages move a dependencies range; 21 non-private packages move only devDependencies, which ships nothing; 3 manifests are private (root, examples/app-showcase, examples/app-todo). No peerDependencies or optionalDependencies entry moves. The 19: @objectstack/cli, create-objectstack, @objectstack/connector-mcp, @objectstack/core, @objectstack/objectql, @objectstack/rest, @objectstack/runtime, @objectstack/spec, @objectstack/driver-mongodb, @objectstack/driver-sqlite-wasm, @objectstack/driver-turso, @objectstack/mcp, @objectstack/metadata-core, @objectstack/metadata-protocol, @objectstack/metadata, @objectstack/plugin-auth, @objectstack/plugin-hono-server, @objectstack/plugin-pinyin-search, @objectstack/service-settings. Every move is upward inside the same caret major. RIGHT.
  2. Card exclusions. The five better-auth lines in plugin-auth/package.json stay 1.7.3 and the head lockfile's plugin-auth importer resolves each to 1.7.3; pnpm-workspace.yaml is not in the diff and its override block is unchanged. apps/docs/package.json is not in the diff; the apps/docs importer keeps next 16.3.6, react 19.2.8 and zod 4.6.1. RIGHT.
  3. Lockfile. nodemailer resolves 10.0.13 (floor 10.0.12). Every changed name@version in the packages: section moves up or dedupes onto a newer copy already present: @hono/node-server 2.0.12, ws 8.21.1, @types/ws 8.18.1 and eventsource-parser 3.1.0 go, and 2.1.1, 8.22.0, 8.18.2 and 3.1.1 remain at the head; esbuild 0.28.1 and 0.28.2 both remain. hono resolves 4.13.12 against the override-rewritten specifier ^4.13.5, which satisfies the published ^4.13.9, so the copy CI certifies is one a consumer install can resolve. Resolved versions going DOWN: 0. RIGHT.
  4. @libsql/client ^0.17.3 → ^0.18.0 (driver-turso), the card's premise-gated item. The PR body records the premise measured three ways before the edit (package diff of both releases, one probe script over side-by-side installs, the driver's own suite) with a per-site table, and the head restamps all 21 lines in 7 driver-turso/src files plus the 2 spec sites. At the head, a grep for 0.17.x over driver-turso/src, spec/src, content/docs and skills returns 0 lines; control: 15 libsql/...@0.18.0 stamps in driver-turso and 2 in spec. The two 0.17.4 lines left under packages/ outside CHANGELOG.md (service-package/src/index.ts:192, service-package/src/mysql2-tuple.test.ts:172) are dated attestations ("Measured on ... 0.17.4"), not "pinned by this tree" claims, and service-package does not depend on @libsql/client; they stay true. CHANGELOG.md hits are release-owned and untouched. RIGHT.
  5. Published text, driver-turso. turso-driver.ts changes 8 docblock citations and 4 refusal-message strings, each a version citation only; no export is added, removed or re-typed. The TursoDriverConfig.timeout TSDoc (ships in the .d.ts) claims for the replica arm that a sync outliving the window rejects while the native sync is not cancelled, only no longer awaited; that holds on 0.18.0, whose change is confined to the local file: client's connection pool. RIGHT.
  6. Published text, spec. @objectstack/spec ships src/**/*.zod.ts; common.zod.ts re-labels one TSDoc line of CREDENTIAL_URL_QUERY_PARAMS from @libsql/core@0.17.4 to 0.18.0, so its "in the versions pinned by this tree" sentence is true again at this head. No .describe(), schema or export changes, so no accept-set change; TypeScript Type Check (which carries check:api-surface, check:docs, check:authorable-surface) is green on the head. RIGHT.
  7. Changeset prose claim about the driver. "The driver creates that client only for an embedded replica, and calls only sync() on it" was read against connect(), disconnect() and sync() at the head: in local/replica mode a @libsql/client is built only under syncUrl; the driver's own calls on it are sync() and, at teardown, close(). Right in substance (the operation the new pool serialises is sync()); the omission of close() is a precision nit, not a false claim. Remote mode's HTTP/WebSocket clients are byte-identical between the two releases per the PR's package diff. RIGHT.
  8. Governed surfaces and size. None of the 54 paths is under docs/adr/, .claude/, skills/, AGENTS.md, CLAUDE.md or docs/NORTH-STAR.md; Governed Surface Queue Guard is green. 1,182 changed lines, under the 5,000-line class. No content/docs/releases/ or CHANGELOG.md edit. RIGHT.
  9. Not re-derived here. The PR's claim that its 63 manifest moves equal Dependabot chore(deps)(deps): bump the production-dependencies group with 27 updates #21029's minus the exclusions is the PR's own diff-equality assertion; chore(deps)(deps): bump the production-dependencies group with 27 updates #21029 is outside this review's input set. The surface is judged on the card's named inclusions and exclusions, all of which hold at the head.

② Semver level

  • .changeset/21094-prod-deps-group.md declares patch for exactly the 19 packages derived in ① (set equality checked in both directions). Each body bullet names the exact FROM → TO range the manifests carry (zod ^4.6.1 → ^4.6.5 on 11 packages, @libsql/client ^0.17.3 → ^0.18.0, @modelcontextprotocol/sdk ^1.30.0 → ^1.30.1, chalk ^6.0.0 → ^6.0.1, yaml ^2.9.0 → ^2.9.1, tsx ^4.23.12 → ^4.23.15, mongodb ^7.5.0 → ^7.6.0, sql.js ^1.14.1 → ^1.14.2, @noble/hashes ^2.3.0 → ^2.4.0, jose ^6.2.8 → ^6.2.12, hono ^4.13.5 → ^4.13.9, pinyin-pro ^3.29.1 → ^3.29.4, @noble/ciphers ^2.3.0 → ^2.4.0), and the better-auth exclusion is stated.
  • patch is the right level: no export, key or schema moves; every floor rises inside its caret major; the only consumer-observable text change is the version citation inside four refusal messages.
  • Clause-②: no, with no arm, on both the PR body and the changeset body: right, since nothing authorable widens or narrows, so no ADR-0087 disposition marker is owed. Check Changeset and Lint & Repo Gates (which carries check:adr-0087-registration) are green on the head.
  • Not skip-changeset: right, the ranges reach consumers. Fixes #21094 is right: the libsql leg was lifted, not forked, so nothing on the card is deferred.

③ Boundary flags

  • open_questions: empty in both os-dev reports. Nothing to answer.
  • Round-0 out-of-scope finding, spec TSDoc and its test echo naming @libsql/core@0.17.4: answered by the REWORK ruling and closed by the patch-round commit, which restamps both sites at this head.
  • Round-0 out-of-scope finding, libsql 0.18.0 pools the local sqlite3 client (one connection beside syncUrl), so a second replica sync() queues behind a first that outlived the timeout window, a reading rather than a measurement: no published text claims concurrent replica syncs. The timeout TSDoc and the sync() docblock claim only that the awaited promise rejects at the window and the native sync is not cancelled, both still true; the periodic setInterval sync makes no ordering claim; the changeset discloses the pooling change to consumers. Not a contract defect, not escalated. Measuring the queueing is a new card if the maintainer wants it, not a block on this one.
  • Round-0 out-of-scope finding, turbo appending a managed block to AGENTS.md during runs: environmental, carrier PM; no commit on the branch touches AGENTS.md and the file list confirms it. Not a contract matter.
  • Deviation, hono resolved by a filtered pnpm update --lockfile-only --no-save hono after the plain install left 4.13.7 below the published ^4.13.9: tool-generated, no manifest or override edited, and it closes the declared-versus-certified split the card names for better-auth rather than opening one; check-override-consistency sits inside the green Lint & Repo Gates. The side effect (packages/apps/account esbuild peer copy 0.28.1 to 0.28.2) is upward. Accepted.
  • Deviation, mongodb live-mongod suites NOT MEASURED (egress): the card lists them under notes, not acceptance; Test Core shards are green. Recorded as not measured.
  • Check-runs on the head: 42 rows, 38 after grouping by name, ci-failure reads GREEN (exit 0). Every required context is success: Lint & Repo Gates, TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance (live PG + MySQL), Governed Surface Queue Guard. Skipped conclusions, each named: Auto Label and Check PR Size on the second workflow run 36856403739 (the labeled event after the ACCEPT comment), both of which succeeded on the push-triggered run 36853321134 on this same head; Packed-tarball smoke (opt-in) on both runs (opt-in); Registry canary: ${{ matrix.template }} (opt-in matrix). None is a failure.

Implemented-by: claude/issue-21094-prod-deps-group
Reviewed-by: session_018gA1pE6eJtwHhqx72G8U9X

VERDICT: PASS

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

⛔ merge queue 构建失败 — 先分诊,再决定要不要重排

队列构建 36857772834 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集),
所以失败的测试可能在本 PR 没碰过的包里 —— 那不是重排能修的。每次盲目重排都会让排在后面的所有 PR 重建一轮。

失败的 job(日志抽取,best effort):

  • Dogfood Verify CLI — 失败步骤: Install dependencies(日志不可读,点进 job 看)
  • Build Core — 失败步骤: Install dependencies(日志不可读,点进 job 看)
  • Build Docs — 失败步骤: Install dependencies(日志不可读,点进 job 看)
  • Dogfood Regression Gate (2/3) — 失败步骤: Install dependencies(日志不可读,点进 job 看)

↳ 失败原因 是判读的关键:超时(Test timed out in … / Hook timed out in …)多半是负载/时序,不是本 PR 的回归;
断言(AssertionError: …)才指向真实的行为改变。两者的 FAIL 行长得一模一样,只有这一行能区分。

⚠️ 断言这一侧有一类例外,判据是断言在测什么,不是它是不是 AssertionError。 断言的对象是产品行为(一个值、一个形状、一次拒收)⇒ 照上面读:真实的行为改变,去查,⛔ 不要重排掉;
断言的对象是这次实验自身的有效性前提(跑完的耗时、负载下的先后、任何只在时间预算内才成立的条件)⇒ 它跟超时是同一类,同样对负载敏感,重排一次是合法的判别手段。
识别是机械的:断言的消息或它比较的值本身点名了一段时长、一个时间戳、一个耗时计数。实测过的一对 —— AssertionError: SecurityPlugin.init() ran: expected false to be true 测的是产品行为(真回归);
AssertionError: this run took over a second, so second-precision stamps could have differed too: expected 1006 to be less than 1000 测的是实验前提:它守护的那条不变式当时是绿的,同一个 head 原样重排一次即成功。
穿着 AssertionError 外衣的时间测量,仍然是时间测量。(⛔ 这只改「怎么读一次红」,不改「哪些测试可以重排」——后者由别处管。)

跨 PR 相同签名(24h,按失败测试文件聚合):

  • ⚠️ 本次没有可用的聚合签名(日志里没有能解析出测试文件名的 FAIL 行)—— 这不是「没有同签名的其他 PR」,是这一轮没测到。跨 PR 聚合本次不可用,请手工比对其他 PR 的同类评论。
  • ⚠️ 24h 评论账本没读完(超过 5 页仍未读到窗口尽头),所以上面的「不同 PR 数」是下界,不是全量。

历史信号:

  • 本 PR 过去 24h 无队列失败记录(首次)。
  • 过去 24h 队列共有 0 个失败构建(不含本次)。

分诊清单:

  1. 失败测试在本 PR 改动的包里 → 真回归,修 PR。
  2. 失败测试与本 PR 无关 → 看上面的「跨 PR 相同签名」;已有汇总 issue ⇒ flaky/环境问题实锤,去那张 issue 上谈,修好前重排只会再烧一轮全队列。
  3. 两者都不是 → 可能与同组 PR 语义冲突;等前面的 PR 落地或失败出队后再重排一次即可,不要连续重排。

Generated by Claude Code · merge-queue-triage workflow (#4859)

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Merge-queue ejection: triage, PR #21162 (head a2d5d53c4e)

Triaged 2026-10-01T11:54Z by the PM seat (session_018gA1pE6eJtwHhqx72G8U9X), from the job logs of queue run 36857772834.

Signature. The failing step is Install dependencies (pnpm install --frozen-lockfile). Four jobs fail with the same first error line: Build Core, Build Docs, Dogfood Verify CLI and Dogfood Regression Gate (2/3).

ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY  Broken lockfile: no entry for 'tsx@4.23.12' in pnpm-lock.yaml

The queue ref was gh-readonly-queue/main/pr-21162-e35c40a5…. It is built on #21160's queue entry (e35c40a5), which sits on main f0cc16e8d.

First diagnosis: a deterministic lockfile conflict with #21160, which is queued ahead. Not a flake.

  • feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 adds "tsx": "^4.23.12" to packages/drivers/driver-turso devDependencies. Its lockfile importer resolves that to version: 4.23.12.
  • This PR lifts tsx to 4.23.15 and removes the tsx@4.23.12 package entries.
  • The two lockfile diffs merge with no textual conflict. The result points an importer at an entry that no longer exists.
  • No commit on main since this PR's base f20f669e17 touches pnpm-lock.yaml or any package.json. So the break comes from that one interaction, which depends only on the order the two PRs land.
  • Not re-queued. A re-queue builds the same merge and fails the same way.

Remedy: patch round 2, after #21160 lands on main.

  1. Merge origin/main into the branch: a merge commit, no rebase, no force-push. feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 also edits driver-turso/src/turso-driver.ts. Any conflict there keeps both sides: feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's change and this PR's 0.18.0 restamps.
  2. Lift the tsx devDependency that feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 adds to driver-turso from ^4.23.12 to ^4.23.15, the same lift this PR applies to every other manifest, so the tree keeps one tsx copy. It is a devDependency, so the changeset does not change.
  3. Regenerate the lockfile with pnpm, never by hand. Confirm pnpm install --frozen-lockfile passes, and that no resolved version goes down against the new main.
  4. Re-grep the text feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 brings in for 0.17.x libsql stamps that this PR's lift would make false, then re-run the gates and push.

Contract review: pnpm-lock.yaml has no merge=os-regen attribute, so the new head is not a pure-regeneration move. The PASS record 5930638280 does not carry over, and the new head owes a fresh CONTRACT_REVIEW_TIER record before it is queued again.


Generated by Claude Code

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 1, 2026
claude added 2 commits October 1, 2026 12:11
…d regenerate the lockfile

Main's driver-turso change added `"tsx": "^4.23.12"` with a lockfile
importer at 4.23.12, while this branch lifts tsx to ^4.23.15 everywhere
and drops the tsx@4.23.12 entries. The two lockfiles merged as text into
one that `pnpm install --frozen-lockfile` refuses
(ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY: no entry for 'tsx@4.23.12'),
reproduced locally on the merge commit. The new declaration takes the
same lift, and the lockfile is regenerated with `pnpm install
--lockfile-only` (pnpm 10.31.0), never edited by hand: a fixed point,
frozen install passes, one tsx copy (4.23.15) for all 27 declarations,
and no resolved version goes down against main e35c40a.

The regeneration also returns packages/apps/account's vitest snapshot to
the esbuild 0.28.1 peer variant main carries, undoing the dedupe an
earlier `pnpm update` on this branch had made there.

Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X
Co-authored-by: Claude <noreply@anthropic.com>
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Review: ACCEPT, patch round 2, PR #21162 (head 0f87e84889)

Reviewed 2026-10-01T12:47Z by the PM seat (session_018gA1pE6eJtwHhqx72G8U9X) against GitHub and the branch. This round fixes the merge-queue ejection triaged in 5930776004.

Verified at the head:

  • History. 4e92c58bc is a true merge commit (parents a2d5d53c4 and e35c40a52, the commit where feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 landed), followed by 0f87e8488. Nothing was rebased, amended or force-pushed. This round's own commit touches 2 files: driver-turso/package.json (tsx ^4.23.12 → ^4.23.15) and pnpm-lock.yaml.
  • tsx. The lockfile has one copy, tsx@4.23.15 (one packages entry plus one snapshots entry), and 0 occurrences of tsx@4.23.12. No package.json still declares "tsx": "^4.23.12".
  • Lockfile against the new main (e35c40a52). Resolved name@version pairs in the packages section: 25 names change and 0 go down. That set equals this PR's round-1 change against its old base f20f669e17, so the merge and regeneration added nothing beyond the reviewed set plus the intended tsx alignment.
  • packages/apps/account. The extra snapshot lines are its vitest peer variant returning to esbuild@0.28.1, which is what main carries. Against main that importer's esbuild variant no longer changes, so the round-1 note about it is moot.
  • CI on 0f87e8488. ci-failure reads GREEN: 38 of 38 completed, none failed. check-expected-skips reads OK: 2 skipped, both on the register (Packed-tarball smoke (opt-in), Registry canary).
  • 0.17.x census. It is unchanged: the only remaining non-CHANGELOG hits are the two dated service-package attestations ruled to stay in round 1. feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 brought in no 0.17.x text.
  • feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's tests on libsql 0.18.0. The os-dev report runs its new and rewritten driver-turso tests on 0.18.0, all passing. That includes the two-process remote-autonumber concurrency test (400 writes, 400 distinct values). CI's Test Core on this head is green.

PR body. The repo squash-merges with the PR body as the commit message. The body's lockfile-blob, range-count, path-count and gate-head readings were refreshed to this head before this verdict.

Still owed: pnpm-lock.yaml has no merge=os-regen attribute, so this head move is not a pure regeneration and the round-1 PASS record (5930638280) does not carry over. The PR carries needs:contract-review until a fresh CONTRACT_REVIEW_TIER record for 0f87e8488… reads PASS. Only then does auto-merge go back on.


Generated by Claude Code

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 0f87e8488985230663c0d5ede5c0929d71da204a
Local-runs: none

Inputs read at 2026-10-01T12:58Z: card #21094 (body and all 9 comments, the three os-dev reports and the PM verdicts included), PR #21162 (body, 54-file list, all 6 PR comments, the round-1 record 5930638280 on the superseded head included), the net diff of the head against its merge base e35c40a52 (54 files, +640/-511), and the 49 check-run rows on the head. Every number below was re-derived from the git objects (git show, git diff, git grep against the merge base and the head), not copied from the dispatch or the dev reports; #21029 is outside the input set and nothing is derived from it. Nothing was installed, built, run or re-run.

① Derived judgments

  1. Consumer-facing dependency floors. Over the 43 changed manifests at the head against the merge base: 19 non-private packages move a dependencies range; 21 non-private packages move only devDependencies, which ships nothing; 3 manifests are private (root, examples/app-showcase, examples/app-todo). No peerDependencies or optionalDependencies entry moves, and no manifest key outside the four dependency sections changes. The 19: @objectstack/cli, create-objectstack, @objectstack/connector-mcp, @objectstack/core, @objectstack/objectql, @objectstack/rest, @objectstack/runtime, @objectstack/spec, @objectstack/driver-mongodb, @objectstack/driver-sqlite-wasm, @objectstack/driver-turso, @objectstack/mcp, @objectstack/metadata-core, @objectstack/metadata-protocol, @objectstack/metadata, @objectstack/plugin-auth, @objectstack/plugin-hono-server, @objectstack/plugin-pinyin-search, @objectstack/service-settings. Every move is upward inside its caret; one is judged separately in item 4 because a caret on a 0.x pins the minor. RIGHT.
  2. Card exclusions. The five better-auth lines in packages/plugins/plugin-auth/package.json stay 1.7.3; the head lockfile's plugin-auth importer resolves better-auth, @better-auth/core, @better-auth/sso, @better-auth/scim and @better-auth/oauth-provider to 1.7.3 on specifier 1.7.3; the lockfile carries 0 occurrences of 1.7.6; pnpm-workspace.yaml is not in the diff and its override targets for the family read 1.7.3 at the head; the lockfile's overrides: block is byte-identical to the merge base's. apps/docs/package.json is not in the diff and next resolves 16.3.6 only. RIGHT.
  3. Lockfile. Resolved name@version pairs in the packages: section, merge base against head: 1382 to 1388 entries, 25 names change, no name appears or disappears, and versions going DOWN: 0. nodemailer resolves 10.0.13 (floor 10.0.12). hono resolves 4.13.12, inside both the override-rewritten ^4.13.5 and the published ^4.13.9, so the copy CI certifies is one a consumer install resolves. tsx resolves to the single copy 4.23.15 with 0 occurrences of tsx@4.23.12, which is exactly the merge-queue ejection signature (ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY on tsx@4.23.12) removed; the round-2 commit lifts the tsx devDependency feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 added to driver-turso to ^4.23.15 so the tree keeps one copy. Four names dedupe onto a newer copy already present (@hono/node-server 2.0.12, ws 8.21.1, @types/ws 8.18.1 and eventsource-parser 3.1.0 go; 2.1.1, 8.22.0, 8.18.2 and 3.1.1 stay); esbuild is not among the changed names, so the round-0 side effect on packages/apps/account is gone at this head. RIGHT.
  4. @libsql/client ^0.17.3 → ^0.18.0 (driver-turso), the premise-gated item. This is the one range move whose old and new accept-sets are disjoint (^0.17.3 admits 0.17.x only, ^0.18.0 admits 0.18.x only), so it is judged on the card's premise, not on the caret. The PR body records the premise measured three ways before the edit (a package diff of both releases confined to the local file: client, one probe script over side-by-side installs, the driver's own suite with per-test parity), and Test Core on this head ran that suite on 0.18.0, feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's two-process concurrency test included. The head restamps all 21 citation lines in 7 driver-turso/src files and the 2 spec sites; a git grep for 0.17.x over packages/, content/docs and skills at the head, CHANGELOG.md excluded, returns 2 lines, both in service-package ("Measured on @libsql/client 0.17.4"), dated attestations in a package that does not depend on libsql, true as written; control: 17 libsql/...@0.18.0 stamps across the 9 restamped files. CHANGELOG.md hits are release-owned and untouched. RIGHT.
  5. Published text, driver-turso. turso-driver.ts changes 8 docblock citations and 4 refusal-message strings, each a version citation only; no export is added, removed or re-typed, and the manifest moves are @libsql/client and zod (dependencies) and tsx (dev) only. RIGHT.
  6. Published text, spec. @objectstack/spec's files ships src/**/*.zod.ts, so the one restamped TSDoc line on CREDENTIAL_URL_QUERY_PARAMS in common.zod.ts is published text; its "in the versions pinned by this tree" sentence is true at this head, closing the round-0 defect. No .describe(), schema or export changes; TypeScript Type Check (api-surface, docs, authorable-surface) is green on the head. RIGHT.
  7. Changeset prose claim about the driver. "The driver creates that client only for an embedded replica, and calls only sync() on it": at the head the local createClient({ url, authToken, encryptionKey, syncUrl, concurrency }) sits under if (this.tursoConfig.syncUrl) alone; the driver's own calls on it are sync() (bounded by timeout) and close() at teardown. Right in substance, since the operation the new pool serialises is sync(); the omission of close() is a precision nit, not a false claim. RIGHT.
  8. Governed surfaces, fork, size. None of the 54 paths matches the six register rows (docs/adr/**, .claude/**, skills/**, AGENTS.md, CLAUDE.md, docs/NORTH-STAR.md); Governed Surface Queue Guard is green; head repo equals base repo; 1,151 changed lines, under the 5,000-line class; no content/docs/releases/ or CHANGELOG.md edit. RIGHT.
  9. What chore(deps)(deps): bump the production-dependencies group with 27 updates #21029 never measured, read off this head's check-runs. Test Core (4/6) success. Lint & Repo Gates success with 196 of 198 steps success: Vendor export contract is step 🔗 Broken links detected in documentation #122 and every gate step after it is green; the 2 skipped steps are the "gates never ran" reporter pair, which fire only when a tail was left unrun. Validate Package Dependencies success with step [WIP] Add Chinese version of the documentation #13 Audit dependencies for known vulnerabilities (OSV-Scanner) success; its step feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14 List outdated packages skipped is a report step, not a gate. RIGHT.
  10. History shape. 8 commits from the merge base: two true merge commits (56e421979, 4e92c58bc), no rebase or force-push; the round-2 commit touches driver-turso/package.json and pnpm-lock.yaml only; the merge base equals the PR's recorded base sha. RIGHT.
  11. Not re-derived. The PR's claim that its manifest moves equal chore(deps)(deps): bump the production-dependencies group with 27 updates #21029's minus the exclusions is its own diff-equality assertion; chore(deps)(deps): bump the production-dependencies group with 27 updates #21029 is outside this review's inputs. The surface is judged on the card's named inclusions and exclusions, all of which hold at the head.

② Semver level

  • .changeset/21094-prod-deps-group.md declares patch for exactly the 19 packages derived in ① (set equality checked in both directions: derived minus declared and declared minus derived are both empty). Each body bullet names a FROM → TO range the manifests carry, and the bullets attribute tsx and yaml to @objectstack/cli alone, which is the only package carrying them in dependencies (every other tsx and yaml move is dev). The better-auth exclusion is stated.
  • patch is the right level: no export, key or schema moves; the only consumer-observable text change is the version citation inside four refusal messages; and the card's item 5 rules patch for every package whose dependencies range moves. The libsql 0.x minor is disclosed to consumers in the changeset body (the pooling change and the re-measured behaviours), which is what a floor move inside the driver's unchanged API owes.
  • Clause-②: no, with no arm, on both the PR body and the changeset body: right, since nothing authorable widens or narrows, so no ADR-0087 disposition marker is owed. Check Changeset (3 of 3 rows success) and Lint & Repo Gates (which carries the changeset-family and ADR-0087 gates) are green on the head.
  • Not skip-changeset: right, the ranges reach consumers. Fixes #21094 is right: the libsql leg was lifted, not forked, so nothing on the card is deferred.

③ Boundary flags

  • open_questions: empty in all three os-dev reports (rounds 0, 1 and 2). Nothing to answer.
  • Round-0 out-of-scope finding, spec TSDoc and its test echo naming @libsql/core@0.17.4: answered by the REWORK ruling and closed by a2d5d53c4, present at this head (①.6).
  • Round-0 out-of-scope finding, libsql 0.18.0 pools the local client so a second replica sync() may queue behind a first that outlived the timeout window (a reading, not a measurement): no published text claims concurrent replica syncs; the timeout TSDoc and sync() claim only that the awaited promise rejects at the window and the native sync is not cancelled, both still true; the periodic setInterval sync makes no ordering claim; the changeset discloses the pooling change; feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's two-process concurrency test passed on 0.18.0 inside Test Core. Not a contract defect, not escalated; measuring the queueing is a new card if the maintainer wants it.
  • Round-0 out-of-scope finding, turbo appending a managed block to AGENTS.md during runs: environmental, carried by the PM; no commit on the branch touches AGENTS.md (the file list and git diff --name-only agree), and the round-2 report records that turbo.json carries agentGuidance: false after the merge. Not a contract matter.
  • Deviation, round 0, hono resolved by a filtered pnpm update --lockfile-only --no-save hono after the plain install left 4.13.7 below the published ^4.13.9: tool-generated, no manifest or override edited, and it closes the declared-versus-certified split the card names for better-auth rather than opening one; Verify overrides are reflected in published manifests and Verify the declared ranges cannot resolve past our import surface are green steps of Validate Package Dependencies. Accepted. Its esbuild side effect is gone at this head (①.3).
  • Deviation, round 2, the merge of main at e35c40a52 plus the tsx lift and lockfile regeneration: pnpm-lock.yaml has no merge=os-regen row in .gitattributes, so this head is not a pure regeneration and the round-1 record did not carry over; this record is the fresh one it owes. The PR body was refreshed to this head (64 moves, blob 30ba2147, 54 paths, gate readings at 0f87e8488) before the round-2 ACCEPT, so the round-2 "stale body" deviation is answered.
  • Deviation, mongodb live-mongod suites NOT MEASURED (egress): the card lists them under notes, not acceptance; Test Core shards are green. Recorded as not measured.
  • Deviation, the shared .git deepened by a --shallow-since fetch for two shallow-refused gates: environmental, additive. Not a contract matter.
  • Check-runs on the head: 49 rows, 38 after grouping by name, ci-failure reads GREEN (exit 0, "all 38 check-run(s) completed, none failed"). Every required context is success: Lint & Repo Gates, TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance (live PG + MySQL), Governed Surface Queue Guard. Skipped conclusions, each named and each on the expected-skips roster: Auto Label and Check PR Size on the two labeled-event runs 36864095476 and 36864295314 (both success on the push-triggered run 36860277632 of this same head); Packed-tarball smoke (opt-in) on runs 36860277770 and 36864295257 (the opt-in label is absent); the registry-canary matrix row on run 36860277555, reported under its unexpanded matrix-template name as a pre-expansion skip does (its sibling Scaffold with repo dist is success). None is a failure.
  • PR state read, not written: non-draft, mergeable_state clean, auto-merge not armed, needs:contract-review carried. This record makes no label, draft, auto-merge or body write.

Implemented-by: claude/issue-21094-prod-deps-group
Reviewed-by: session_018gA1pE6eJtwHhqx72G8U9X

VERDICT: PASS

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation protocol:data size/m tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

deps: take the 2026-10 production-dependency group without the better-auth family (replaces Dependabot #21029)

2 participants