DEVIATIONS.md staleness pass: D-DEP-1, D-DEP-2, D-PKG-2 contradict ratified amendments #337
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub#337
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Child of #331 (audit findings 3225/3226/3227, commit
70d29dd). The DEVIATIONS.md ledger contradicts itself: D-DEP-1 claims 'exactly three modules' but x/crypto is the ratified fourth (AGENTS.md law 1, 17_ssh.md 17.1; go.mod has 4 direct requires). D-DEP-2 claims 'zero npm runtime dependencies' but D-WEB-6/D-WEB-7 (same file, in force) allow solid-js + @solidjs/router + marked@18.0.11 + dompurify@3.4.15. D-PKG-2 claims the node stage runs ONLY esbuild but D-WEB-6 reinstated the full vite build (Dockerfile node:22 runs pnpm run build = vite + esbuild). Fix: amend the three entries (superseded-by chains + current truth) in one docs-only change. No code behavior at stake.These are accepted deviations. The laws should be updated.
Staleness pass ready for review: #343 (branch fix/issue-337, docs-only, DEVIATIONS.md only — D-DEP-1 four-module budget, D-DEP-2 superseded-by D-WEB-6 amended-by D-WEB-7, D-PKG-2 vite+esbuild node stage). All facts verified against go.mod, web/package.json, Dockerfile, Makefile, 17_ssh.md 17.1. Not merging per instructions.
Review of PR #343 (branch fix/issue-337, docs-only DEVIATIONS.md staleness pass for #337):
SCOPE OK: 1 file changed (DEVIATIONS.md, 4+/4-). No code touched. Last-updated bumped 2026-09-01 -> 2026-09-11.
VERIFIED EACH ENTRY AGAINST SOURCE OF TRUTH (main checkout, read-only):
LAW 12: doc-only catch-up to already-landed decisions (17.1, D-WEB-6/7); no new code/doc disagreement introduced; consolidation file updated as required.
NITS (non-blocking, not pushing to keep review read-only): D-DEP-2 title keeps the stale budget words in bold without strikethrough (file convention elsewhere uses
..for dead text, cf. D-PKG-2); skimmer must read to SUPERSEDED. D-WEB-6 body sentence runtime = exactly solid-js + @solidjs/router is pre-D-WEB-7 wording, but D-WEB-7 amendment is in force alongside it — out of #337 scope. Suggest follow-up polish, not a merge blocker.RECOMMENDATION: ready to merge.
Correction to my review above: pinned versions are marked 18.0.11 and dompurify 3.4.15 (I transposed them). Verification and ready-to-merge recommendation stand.
Fixed by PR #343 (review clean; all three entries verified true against go.mod/package.json/Dockerfile/17_ssh; no old truths left in force), merged. Closing.