DEVIATIONS.md staleness pass: D-DEP-1, D-DEP-2, D-PKG-2 contradict ratified amendments #337

Closed
opened 2026-09-11 17:22:38 +00:00 by crueber · 5 comments
Owner

Child of #331 (audit findings 3225/3226/3227, commit 70d29dd). The DEVIATIONS.md ledger contradicts itself: D-DEP-1 claims 'exactly three modules' but x/crypto is the ratified fourth (AGENTS.md law 1, 17_ssh.md 17.1; go.mod has 4 direct requires). D-DEP-2 claims 'zero npm runtime dependencies' but D-WEB-6/D-WEB-7 (same file, in force) allow solid-js + @solidjs/router + marked@18.0.11 + dompurify@3.4.15. D-PKG-2 claims the node stage runs ONLY esbuild but D-WEB-6 reinstated the full vite build (Dockerfile node:22 runs pnpm run build = vite + esbuild). Fix: amend the three entries (superseded-by chains + current truth) in one docs-only change. No code behavior at stake.

Child of #331 (audit findings 3225/3226/3227, commit 70d29dd). The DEVIATIONS.md ledger contradicts itself: D-DEP-1 claims 'exactly three modules' but x/crypto is the ratified fourth (AGENTS.md law 1, 17_ssh.md 17.1; go.mod has 4 direct requires). D-DEP-2 claims 'zero npm runtime dependencies' but D-WEB-6/D-WEB-7 (same file, in force) allow solid-js + @solidjs/router + marked@18.0.11 + dompurify@3.4.15. D-PKG-2 claims the node stage runs ONLY esbuild but D-WEB-6 reinstated the full vite build (Dockerfile node:22 runs pnpm run build = vite + esbuild). Fix: amend the three entries (superseded-by chains + current truth) in one docs-only change. No code behavior at stake.
Author
Owner

These are accepted deviations. The laws should be updated.

These are accepted deviations. The laws should be updated.
Author
Owner

Staleness pass ready for review: #343 (branch fix/issue-337, docs-only, DEVIATIONS.md only — D-DEP-1 four-module budget, D-DEP-2 superseded-by D-WEB-6 amended-by D-WEB-7, D-PKG-2 vite+esbuild node stage). All facts verified against go.mod, web/package.json, Dockerfile, Makefile, 17_ssh.md 17.1. Not merging per instructions.

Staleness pass ready for review: #343 (branch fix/issue-337, docs-only, DEVIATIONS.md only — D-DEP-1 four-module budget, D-DEP-2 superseded-by D-WEB-6 amended-by D-WEB-7, D-PKG-2 vite+esbuild node stage). All facts verified against go.mod, web/package.json, Dockerfile, Makefile, 17_ssh.md 17.1. Not merging per instructions.
Author
Owner

Review of PR #343 (branch fix/issue-337, docs-only DEVIATIONS.md staleness pass for #337):

SCOPE OK: 1 file changed (DEVIATIONS.md, 4+/4-). No code touched. Last-updated bumped 2026-09-01 -> 2026-09-11.

VERIFIED EACH ENTRY AGAINST SOURCE OF TRUTH (main checkout, read-only):

  • D-DEP-1 (four modules + 17.1): TRUE. go.mod direct requires are exactly chi v5.3.2, BurntSushi/toml v1.6.0, x/crypto v0.56.0, x/net v0.58.0 (only indirects are x/sys, x/text). docs/go/17_ssh.md 17.1 (2026-09-02) allows x/crypto/ssh as fourth module, user-directed. Matches AGENTS.md L1. Chain two->three->four preserved, status in-force (supersedes three-module budget). No remaining in-force three-module claim (only historical-chain mention).
  • D-DEP-2 (superseded by D-WEB-6, amended by D-WEB-7): TRUE. web/package.json dependencies are exactly solid-js, @solidjs/router, marked 3.4.15 pinned, dompurify 18.0.11 pinned; devDeps are vite, vite-plugin-solid, tailwindcss, @tailwindcss/vite, esbuild; no TypeScript anywhere. D-WEB-6 and D-WEB-7 both exist and in-force. Status coherent (superseded, not in-force). Old zero-runtime truth survives only as labeled Historical/chain text.
  • D-PKG-2 (node runs full vite+esbuild): TRUE. Dockerfile web stage is node:22-alpine + pnpm 11, runs pnpm run build (= build:ui vite SPA -> dist/ + build:sdk esbuild sdk/src -> dist/repos.js, per web/package.json scripts); Go stage embeds dist/. Makefile web/build targets agree. Old esbuild-only/raw-embed truth survives only as labeled Historical text. Status in-force with full supersession chain.

LAW 12: doc-only catch-up to already-landed decisions (17.1, D-WEB-6/7); no new code/doc disagreement introduced; consolidation file updated as required.

NITS (non-blocking, not pushing to keep review read-only): D-DEP-2 title keeps the stale budget words in bold without strikethrough (file convention elsewhere uses .. for dead text, cf. D-PKG-2); skimmer must read to SUPERSEDED. D-WEB-6 body sentence runtime = exactly solid-js + @solidjs/router is pre-D-WEB-7 wording, but D-WEB-7 amendment is in force alongside it — out of #337 scope. Suggest follow-up polish, not a merge blocker.

RECOMMENDATION: ready to merge.

Review of PR #343 (branch fix/issue-337, docs-only DEVIATIONS.md staleness pass for #337): SCOPE OK: 1 file changed (DEVIATIONS.md, 4+/4-). No code touched. Last-updated bumped 2026-09-01 -> 2026-09-11. VERIFIED EACH ENTRY AGAINST SOURCE OF TRUTH (main checkout, read-only): - D-DEP-1 (four modules + 17.1): TRUE. go.mod direct requires are exactly chi v5.3.2, BurntSushi/toml v1.6.0, x/crypto v0.56.0, x/net v0.58.0 (only indirects are x/sys, x/text). docs/go/17_ssh.md 17.1 (2026-09-02) allows x/crypto/ssh as fourth module, user-directed. Matches AGENTS.md L1. Chain two->three->four preserved, status in-force (supersedes three-module budget). No remaining in-force three-module claim (only historical-chain mention). - D-DEP-2 (superseded by D-WEB-6, amended by D-WEB-7): TRUE. web/package.json dependencies are exactly solid-js, @solidjs/router, marked 3.4.15 pinned, dompurify 18.0.11 pinned; devDeps are vite, vite-plugin-solid, tailwindcss, @tailwindcss/vite, esbuild; no TypeScript anywhere. D-WEB-6 and D-WEB-7 both exist and in-force. Status coherent (superseded, not in-force). Old zero-runtime truth survives only as labeled Historical/chain text. - D-PKG-2 (node runs full vite+esbuild): TRUE. Dockerfile web stage is node:22-alpine + pnpm 11, runs pnpm run build (= build:ui vite SPA -> dist/ + build:sdk esbuild sdk/src -> dist/repos.js, per web/package.json scripts); Go stage embeds dist/. Makefile web/build targets agree. Old esbuild-only/raw-embed truth survives only as labeled Historical text. Status in-force with full supersession chain. LAW 12: doc-only catch-up to already-landed decisions (17.1, D-WEB-6/7); no new code/doc disagreement introduced; consolidation file updated as required. NITS (non-blocking, not pushing to keep review read-only): D-DEP-2 title keeps the stale budget words in bold without strikethrough (file convention elsewhere uses ~~..~~ for dead text, cf. D-PKG-2); skimmer must read to SUPERSEDED. D-WEB-6 body sentence runtime = exactly solid-js + @solidjs/router is pre-D-WEB-7 wording, but D-WEB-7 amendment is in force alongside it — out of #337 scope. Suggest follow-up polish, not a merge blocker. RECOMMENDATION: ready to merge.
Author
Owner

Correction to my review above: pinned versions are marked 18.0.11 and dompurify 3.4.15 (I transposed them). Verification and ready-to-merge recommendation stand.

Correction to my review above: pinned versions are marked 18.0.11 and dompurify 3.4.15 (I transposed them). Verification and ready-to-merge recommendation stand.
Author
Owner

Fixed by PR #343 (review clean; all three entries verified true against go.mod/package.json/Dockerfile/17_ssh; no old truths left in force), merged. Closing.

Fixed by PR #343 (review clean; all three entries verified true against go.mod/package.json/Dockerfile/17_ssh; no old truths left in force), merged. Closing.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
crueber/walhub#337
No description provided.