Repository navigation
chore(deps): take the 2026-10 production-dependency group without the better-auth family (#21094) - #21162
Conversation
… better-auth family Re-applies Dependabot's production-dependencies manifest moves onto current main, minus apps/docs (next is owned elsewhere) and minus the five better-auth family lines, which stay at 1.7.3 with their override targets. The lockfile is regenerated by `pnpm install --lockfile-only` (pnpm 10.31.0) from main's lockfile, never by hand. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
`pnpm install --lockfile-only` keeps hono at 4.13.7: the workspace override `hono@<5.0.0` rewrites every declaration to `^4.13.5`, which 4.13.7 still satisfies, so lockfile inertia leaves CI testing a version below the `^4.13.9` that plugin-hono-server publishes. Re-resolved with `pnpm --filter <the three hono importers> update --lockfile-only --no-save hono`, which moves the single hono copy to 4.13.12 (what a downstream `^4.13.9` install resolves today) without touching the override or any manifest. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
…0.18.0 Every behaviour driver-turso documents as measured against @libsql/client 0.17.4 was re-measured on the resolved 0.18.0 and holds identically: @libsql/core, hrana-client 0.10.0 and native libsql 0.5.29 are byte-identical across the two releases apart from version strings, the client's http/ws/node entries are unchanged, and the only code delta (the local sqlite3 client's connection pool) touches none of the documented readings. The version pin, the docblocks and the refusal message text now name the version actually measured. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
…y ranges move Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 19 package(s): 2 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
⛔ 2 release-owned page(s) also name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 159 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin e0d43f711484d3e392c0c43663afeb276cf7b923 && git checkout e0d43f711484d3e392c0c43663afeb276cf7b923
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin e35c40a52597c8ca7527e6dd5bc753488dd52bbf 0f87e8488985230663c0d5ede5c0929d71da204a && git checkout -B drift-repro e35c40a52597c8ca7527e6dd5bc753488dd52bbf && git merge --no-ff 0f87e8488985230663c0d5ede5c0929d71da204a
node scripts/docs-audit/affected-docs.mjs --json e35c40a52597c8ca7527e6dd5bc753488dd52bbf
|
… 0.18.0 this tree now pins The TSDoc of CREDENTIAL_URL_QUERY_PARAMS says each entry is measured "in the versions pinned by this tree" and named @libsql/core 0.17.4; with the client lifted to ^0.18.0 the tree pins only core 0.18.0, so the label would have been false in the release that ships it. Its echo in driver-credential-refusal.test.ts moves with it. Re-measured on the installed @libsql/core 0.18.0 (expandConfig, with a config-level authToken 'BINDER'): - url ?authToken=URLTOK -> authToken URLTOK (the URL overrides) - url ?auth%54oken=URLTOK -> authToken URLTOK (key percent-decoded) - url ?AuthToken= / ?token= -> URL_PARAM_NOT_SUPPORTED - control, no query string -> authToken BINDER Identical to the 0.17.4 reading; core 0.17.4 and 0.18.0 differ only in their package.json version. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
Review: ACCEPT, patch round 1, PR #21162 (head
|
Contract reviewServed-tier: Inputs read: card #21094 (body and all 7 comments), PR #21162 (body, 54-file list, both PR comments), the net diff ① Derived judgments
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS |
⛔ merge queue 构建失败 — 先分诊,再决定要不要重排队列构建 36857772834 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集), 失败的 job(日志抽取,best effort):
跨 PR 相同签名(24h,按失败测试文件聚合):
历史信号:
分诊清单:
Generated by Claude Code · merge-queue-triage workflow (#4859) |
Merge-queue ejection: triage, PR #21162 (head
|
Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
…d regenerate the lockfile Main's driver-turso change added `"tsx": "^4.23.12"` with a lockfile importer at 4.23.12, while this branch lifts tsx to ^4.23.15 everywhere and drops the tsx@4.23.12 entries. The two lockfiles merged as text into one that `pnpm install --frozen-lockfile` refuses (ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY: no entry for 'tsx@4.23.12'), reproduced locally on the merge commit. The new declaration takes the same lift, and the lockfile is regenerated with `pnpm install --lockfile-only` (pnpm 10.31.0), never edited by hand: a fixed point, frozen install passes, one tsx copy (4.23.15) for all 27 declarations, and no resolved version goes down against main e35c40a. The regeneration also returns packages/apps/account's vitest snapshot to the esbuild 0.28.1 peer variant main carries, undoing the dedupe an earlier `pnpm update` on this branch had made there. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
Review: ACCEPT, patch round 2, PR #21162 (head
|
Contract reviewServed-tier: Inputs read at 2026-10-01T12:58Z: card #21094 (body and all 9 comments, the three os-dev reports and the PM verdicts included), PR #21162 (body, 54-file list, all 6 PR comments, the round-1 record 5930638280 on the superseded head included), the net diff of the head against its merge base ① Derived judgments
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS |
… Node, re-arming the reroute probe CONTROL leg (objectstack-ai#21356) Fixes objectstack-ai#21308 Clause-②: no ## What this changes `tsx` 4.23.15 moved its ESM-API registration out of a `dist/` chunk and into `dist/esm/api/index.cjs`, two directories deeper. It did not rebase three file-relative specifiers. On a Node without tsx's `module.registerHooks` path, the CommonJS build of `tsx/esm/api` then calls `module.register()` with a hooks URL that names `dist/esm/api/esm/index.mjs`, a file that does not exist. `@oclif/core`'s `ts-path` is the caller in this repo. It swallows the error, logs `Could not find tsx`, and stays on `dist/`. This PR adds a `pnpm patch` of `tsx@4.23.15` that points the three specifiers back at the files 4.23.14 resolved. No version moves. - `patches/tsx@4.23.15.patch`: new, written by `pnpm patch` / `pnpm patch-commit`. - `pnpm-workspace.yaml`: the `patchedDependencies` entry and its note, next to the existing `tsup@8.5.1` entry. - `pnpm-lock.yaml`: regenerated by `pnpm install`, not edited by hand. - `packages/cli/test/published-entry-node-env-source-reroute.test.ts`: a docblock pointer only. No leg, assertion or bound changes. ## Measured ### H0: CI's reading of the CONTROL leg is NOT MEASURED (log hosts unreachable) Both log hosts refused this session at CONNECT (`gateway answered 403`): - `productionresultssa14.blob.core.windows.net`, the job logs of all six `Test Core` shards of run 36964705223 on 6091136; - `results-receiver.actions.githubusercontent.com`, the run log zip. `node scripts/pm/ci-failure.mjs --run 36964705223` exited 2 with `job log NOT RETRIEVED`. What was measured instead is the mechanism that decides it. tsx 4.23.12, 4.23.14 and 4.23.15 all take the synchronous `registerHooks` path only on Node 22.22.3+, 24.11.1+, 25.1.0+ or 26+ (version table `[[22,22,3],[24,11,1],[25,1,0],[26,0,0]]`). That path never reaches the broken specifier. Node 22.22.3 was released on 2026-05-13. CI's `setup-node` asks for `node-version: '22'`, and the dev containers run v22.22.0. Same tree (6091136), unpatched tsx: | Node | `published-entry-node-env-source-reroute.test.ts` | |---|---| | v22.22.0 | 1 failed (CONTROL), 4 passed | | v22.22.3 (official tarball, sha256 checked against `SHASUMS256.txt`) | 5 passed | So CI arms the leg if its runner resolved `'22'` to 22.22.3 or later. The runner's actual version is in the log this session could not read. ### H1: confirmed, with a version bound `DEBUG=oclif:config:ts-path` on v22.22.0, CONTROL preload, the test's own env (no `NODE_PATH`): ```text Could not find tsx. Skipping tsx registration for .../packages/cli. Error [ERR_MODULE_NOT_FOUND]: Cannot find module '.../tsx/dist/esm/api/esm/index.mjs' imported from .../tsx/dist/esm/api/index.cjs ``` Next it logs `Cannot find module 'ts-node'`, and `tsPath` returns the `dist/` path. In the tarballs, 4.23.12, 4.23.13 and 4.23.14 keep the `register()` call in `dist/register-*.cjs`, where it resolves. 4.23.15 inlines it into `dist/esm/api/index.cjs`, which grows from 1,298 to 16,770 bytes. The `.mjs` build of `tsx/esm/api` is unaffected. oclif reaches the `.cjs` build because it locates the module with `require.resolve`. ### H2: holds `npm view tsx dist-tags` gives `latest` as 4.23.15 (2026-09-20). There is no newer release, so no UP move (remedy d) exists. ### A second casualty of the same defect On v22.22.0 with unpatched tsx, `bin/run-dev.js` also lands on `dist/commands`. That file is the CLI's SOURCE entry, the one `runServe` and the other spawning tests launch (104 test files under `packages/cli` mention it). `tsx bin/run-dev.js --version` under `DEBUG=oclif:config:ts-path` logs `Could not find tsx` and never `Found source directory`. With the patch it logs `Found source directory for .../dist/commands at .../src/commands`. So on such a Node, source-entry tests have measured the build output rather than `src/` since objectstack-ai#21162. The same patch fixes this with nothing added. ## Why (b), and not (a) or (c) **(a)** pins tsx down to 4.23.14. That is a DOWN move and needs a ruling, and measurement does not make it the only sound remedy. Not taken. **(c)** reworks the CONTROL leg. To arm without oclif's own tsx registration, the child would need a test-only change to how it resolves `tsx/esm/api`: a `Module._resolveFilename` shim in the preload, or `--conditions=import` on the child. That fails the second acceptance criterion as measured. The absence legs do not load the preload, so on v22.22.0 with unpatched tsx, deleting the declaration leaves them green (row 4 below). Arming them too would put the shim in every leg, and then every leg measures a resolution no real install has. **(b)** patches the component that fails. The test's behaviour is unchanged, and both acceptance criteria hold on v22.22.0 and on v22.22.3. Four axes: - **Real business need:** measured. Two consumers break on Node below 22.22.3. One is this probe's CONTROL leg. The other is the source entry `bin/run-dev.js`, which is the larger one, because the CLI's spawning tests silently ran `dist/`. The published CLI is not reached: `bin/run.js` sets `settings.enableAutoTranspile = false`, so oclif never registers tsx there, and nothing in `packages/**` source imports `tsx/esm/api`. - **Long-term soundness:** the patch is a workaround for an upstream packaging defect, and it has a cost. It replaces one 16 KB minified line, which nobody can review by eye. The token comparison below is how to review it. The key names the exact version, so a tsx bump fails `pnpm install` (`ERR_PNPM_UNUSED_PATCH`, the same rule the `tsup@8.5.1` entry records), and the patch cannot outlive its reason silently. Retire it when a tsx release resolves the three paths itself, or when the toolchain's Node floor reaches 22.22.3. (c) would carry a test shim with no such tripwire. After an upstream fix it would become dead code that still makes every leg diverge from a real install. - **Making AI mistakes harder:** (b) gives the probe one meaning in every environment. Today the same file is green in CI and red in the dev containers, and three devs reported that red in passing, without a card, because it read as "environment". (c) adds a second resolution dialect inside a test fixture, which is the consumer-side tolerance that contract-first rules out. - **Startup focus:** no new gate, no new dependency, no version movement. Three tracked files, plus the lockfile the tooling wrote. ## CONTROL leg and reverse verification (Node v22.22.0 unless stated) | tree | tsx | declaration in `bin/run.js` | `development` / `test` legs | CONTROL (development, neutralised) | |---|---|---|---|---| | 6091136 (main) | unpatched | present | pass | FAIL: output is only `@objectstack/cli/17.6.0 linux-x64 node-v22.22.0` | | cc0c05b | patched | present | pass | pass: card signature present, exit non-zero | | cc0c05b | patched | deleted | FAIL x2: `expected '(node:...) [MODULE_NOT_FOUND] Warni...' not to contain 'Cannot find module './registry''` | pass | | cc0c05b, `packages/cli/node_modules/tsx` linked to the pristine 4.23.15 | unpatched | deleted | pass (vacuous: 1 failed, 4 passed) | FAIL | | 8569d5f (final) | patched | present | pass | pass (5 passed) | | 8569d5f, Node v22.22.3 | patched | present | pass | pass (5 passed) | `scripts/ablation-replace.mjs --delete` removed the declaration (anchor 1 to 0, blob `569e6b6f` to `40a368ce`). The same tool restored it and showed the blob equal to HEAD's, with `git diff HEAD` empty. The tsx link swap ran under an EXIT/INT/TERM trap, and `readlink` confirmed the restore. `bin/run.js` runs unbuilt, so no `dist/` step is involved. ## Reviewing the patch The patch replaces one minified line. Review it with this comparison, which splits the pristine and the patched file on commas and prints every token that differs: ```sh npm pack tsx@4.23.15 && tar xzf tsx-4.23.15.tgz node -e 'const fs=require("fs");const a=fs.readFileSync(process.argv[1],"utf8").split(","),b=fs.readFileSync(process.argv[2],"utf8").split(",");let n=0;for(let i=0;i!==a.length;i++)if(a[i]!==b[i]){n++;console.log("-",a[i].slice(-60));console.log("+",b[i].slice(-60))}console.log(n,"of",a.length,"differ")' package/dist/esm/api/index.cjs node_modules/.pnpm/tsx@4.23.15_patch_hash=4d1d35da1809be2a945519cb26890e48107810b9b66c6913a6a89abb5ad6a1e6/node_modules/tsx/dist/esm/api/index.cjs ``` Output: ```text - se=[new URL("loader.mjs" + se=[new URL("../../loader.mjs" - new URL("esm/index.mjs" + new URL("../index.mjs" - essageChannel;R.register(`./esm/index.mjs?${_.randomUUID()}` + e.MessageChannel;R.register(`../index.mjs?${_.randomUUID()}` 3 of 514 comma-separated tokens differ ``` The `register()` specifier is the one that breaks things. The two `new URL(...)` entries feed tsx's `isTsxImport` set and carry the same wrong base. They are fixed in the same patch because they are the same defect, in the same file, with the same mechanical change. Both rebased targets exist on disk (`dist/esm/index.mjs`, `dist/loader.mjs`). No test here reaches those two entries, because no child in this suite passes a TypeScript preload ahead of an absolute tsx loader path. ## Lockfile `pnpm install` regenerated it. With the tsx patch hash normalised away, every removed line equals an added line, except for the three new `patchedDependencies` lines. 0 versions moved, 0 DOWN, 0 packages added or removed. Ten snapshot keys change only by the hash suffix: `tsx` itself, and the peer suffix of `tsup`, `postcss-load-config`, `fumadocs-mdx`, `vite` x2, `vitest` x2 and `@vitest/mocker` x2. `pnpm install --frozen-lockfile` passes on the final head. ## Verification - `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands` at 8569d5f derives 58 commands from 4 paths. All 58 were run with exit codes captured before any pipe, and all exited 0. `--ran` reports 58 derived, 58 run, 0 NOT-MEASURED. (In an earlier pass at 6a22902, `check:dual-build-cjs-loads` answered PREREQUISITE NOT MET while sibling packages had no `dist/`. Once those were built it passed: 105 entry points across 66 packages.) - `@objectstack/cli` unit tier at 6a22902: 244 files, 3461 tests passed. - `@objectstack/cli` integration tier at 6a22902, two runs under the verify lock: 71 files, 607 tests passed, 1 skipped. The skip is the existing `it.skipIf` in `test/migrate-meta-default-range.test.ts`, a file this branch does not touch. - `pnpm --filter @objectstack/cli typecheck` at 6a22902: exit 0, `check:test-typecheck` included. - 6a22902 to 8569d5f is two merges of `main`: objectstack-ai#21317 (plugin-security), objectstack-ai#21335 (objectql, rest, plugin-auth), and two docs-only commits (objectstack-ai#21337, objectstack-ai#21343). None touches a CLI file, the lockfile, `pnpm-workspace.yaml` or tsx, so the CLI tiers were not re-run for them. The packages the merge touched (objectql, plugin-auth, rest) were rebuilt. Then the reroute file (5 passed on v22.22.0, 5 passed on v22.22.3) and all 58 gates were re-run on 8569d5f. - Not run here: `pnpm lint` (repo-wide, CI's run). **skip-changeset:** nothing published moves. `@objectstack/cli` ships only `dist`, `README.md` and `CHANGELOG.md`, so the test file is not published. `patches/`, `pnpm-workspace.yaml` and `pnpm-lock.yaml` are root files no package ships. The CLI's dependency range on tsx is unchanged. ## Acceptance notes - The dev containers run Node v22.22.0, while CI's `setup-node` floats on `'22'`. That gap is why the same file read red in three dev containers and green in `Test Core`. Observation only, no card. Carrier: none. - Upstream: whether tsx already has an issue or fix in flight was not read, because this session cannot reach `privatenumber/tsx` through the API. The retirement condition is in the `pnpm-workspace.yaml` note. - Published reach: `@objectstack/cli` depends on `tsx ^4.23.15` at runtime, so a customer on Node 22.0 to 22.22.2 installs the defective build. No published code path calls `require('tsx/esm/api')`, so no public entry point reaches it. Measured by a grep of `packages/**` source and by the published entry's `enableAutoTranspile = false`. - `packages/cli/README.md` and `packages/cli/package.json` belong to objectstack-ai#21310 and are not touched. --- _Generated by [Claude Code](https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
Fixes #21094
Clause-②: no
Takes the 2026-10 production-dependency group that Dependabot opened as #21029 (closed in favour of this card), without the better-auth family and without
next. Maintainer ruling, verbatim:What lands
9b0de7de73to its headc0b7dd923e) were re-applied one line at a time onto currentmain. The 64th is thetsxdevDependency feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 added topackages/drivers/driver-turso/package.json, lifted from^4.23.12to^4.23.15after feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 was merged in. Each move matched the exact old spelling or the script refused. Excluded:apps/docs/package.json(nextbelongs to [finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055 / fix(deps): take the fix for next GHSA-vcvr-r3jv-pc5j (critical) and dompurify GHSA-p98j-92pf-mc4p #21083) and the five better-auth family lines inpackages/plugins/plugin-auth/package.json, which stay at1.7.3.pnpm-workspace.yamlis not touched. Check, taken before the feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 merge: the sorted-/+lines of this branch's manifest diff equal chore(deps)(deps): bump the production-dependencies group with 27 updates #21029's lines minus those exclusions (diffexit 0, 126 lines).pnpm-lock.yaml, regenerated with the tooling in three steps (pnpm 10.31.0, thepackageManagerpin), never by hand:pnpm install --lockfile-only, starting from main's lockfile.pnpm --filter @objectstack/plugin-hono-server --filter @objectstack/plugin-auth --filter @objectstack/hono update --lockfile-only --no-save hono. Step 1 lefthonoat 4.13.7, below the^4.13.9thatplugin-hono-servernow publishes. The workspace override forhono(selector below 5.0.0) rewrites every declaration to^4.13.5, which 4.13.7 still satisfies, so lockfile inertia kept the old version. CI would have certified 4.13.7 while a downstream install gets 4.13.12. That is the declared-versus-tested split the card names for better-auth. Step 2 moves the singlehonocopy to 4.13.12 without editing the override or any manifest. An unfilteredpnpm update -rwas tried and discarded: it also droppedknex'smysql2/pg/tediouspeer links in two importers.main(e35c40a52), lift driver-turso's newtsxline, and runpnpm install --lockfile-onlyagain.pnpm install --lockfile-onlyleaves it byte-identical, andpnpm install --frozen-lockfilepasses. Lockfile blob30ba2147. The resolved set is unchanged from the set the OSV scan below covered: 0 names differ.packages/drivers/driver-turso/src/**: the item-4 restamp, 21 lines in 7 files (below).packages/spec/src/data/driver/common.zod.tsanddriver-credential-refusal.test.ts: the@libsql/coreversion label is restamped from 0.17.4 to 0.18.0. The TSDoc ofCREDENTIAL_URL_QUERY_PARAMSsays it was measured "in the versions pinned by this tree", so leaving 0.17.4 would have made it false. The behaviour was re-measured identical on the installed 0.18.0:?authToken=overrides the config token,auth%54okenis decoded,AuthTokenandtokengiveURL_PARAM_NOT_SUPPORTED, and the control without a query keeps the config token..changeset/21094-prod-deps-group.md:patchfor the 19 published packages whosedependenciesrange moves. The list was re-derived from this diff and matches the PM correction on the card,plugin-authincluded (@noble/hashes,jose).Resolved versions against the merge base
Every changed
name@versionpair in thepackages:section, compared withmainate35c40a52: 25 names change. DOWN: 0.@libsql/client/@libsql/corezodapps/docsonly)@modelcontextprotocol/sdkhonomongodbmongodb-memory-server-coreonly)jose@noble/hashes@noble/ciphersreact/react-dom/@types/react/@types/react-domapps/docsonly)tsxyamlapps/docsfumadocs tree only)chalksql.jspinyin-pro@hono/node-server2.0.12,ws8.21.1,@types/ws8.18.1,eventsource-parser3.1.0bson7.3.3 and@mongodb-js/saslprep1.5.5 (withmongodb7.7.0),scheduler0.28.0 (withreact-dom19.3.0)nodemailerstays at 10.0.13, main's version and at least the required 10.0.12. Dependabot's regeneration had moved it down to 10.0.11.Item 4:
@libsql/clientlifted to^0.18.0, because the premise holdsThe premise was measured before any driver edit, three ways.
npm packof both releases.@libsql/core0.17.4 and 0.18.0 differ only inpackage.json(the version).@libsql/clientdiffers only inlib-esm/sqlite3.js,lib-cjs/sqlite3.js,lib-esm/sqlite3.d.tsandpackage.json. The change is a connection pool for the localfile:client.http.js,ws.jsandnode.jsare byte-identical. Installed side by side,@libsql/hrana-client0.10.0 and nativelibsql0.5.29 (with@libsql/linux-x64-gnu) are byte-identical too.syncUrloccurrences insqlite3.jsgo from 3 to 4 (the new pool-size line).expected '0.18.0' to be '0.17.4'). After the restamp: 2210 passed, 33 skipped. At0f87e8488, with feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's tests merged in: 2218 passed, 33 skipped, 0 failed.turso-authtoken-url-channel.test.ts:17-18libsql0.5.29; range now^0.18.0. Answers 1-4 (live wire, child-process replica endpoint) pass, 7/7 non-pin cases, as 8/8 did on 0.17.4turso-authtoken-url-channel.test.ts:2810.18.0turso-driver-remote-url-replica-refusal.test.ts:28,turso-driver.ts:1288,:1384(message)syncUrllines:http.js0,ws.js0, controlauthTokenlines 6 / 6.httpsandwsclients'sync()rejectSYNC_NOT_SUPPORTED.:memory:+syncUrlthrowsURL_INVALID("Embedded replica must use file for local db"). File 27/27 on both versionsturso-driver-timeout.test.ts:9,turso-driver.ts:152Config.fetch; replicasync()is nativehttp.js(oneconfig.fetchsite) and hrana-client byte-identical. Timeout file 5/5, supplied-client refusal file 13/13 on bothturso-driver.ts:871Config.timeoutis the busy timeout; "remote clients ignore it"api.d.tsdocblock byte-identicalturso-driver-unrecognised-url-refusal.test.ts:26,turso-driver.ts:1313,:1417(message)URL_INVALIDfor./data/app.db,data/app.db,/abs/app.db,:MEMORY:, empty,libsql:host(bare paths "not in a valid format").URL_SCHEME_NOT_SUPPORTEDforsqlite:,memory://,C:\data\app.db. File 42/42 on bothturso-driver-uppercase-ws-scheme-timeout-refusal.test.ts:15,:26,turso-driver.ts:932expandConfiglowercases the scheme before the switchWSS://…giveswss,Ws://…givesws, controlLIBSQL://…giveshttps._createClient(expandConfig(config, true))present (1 hit). File 20/20 on bothturso-driver-ws-timeout-refusal.test.ts:10,turso-driver.ts:963,:1001(message)fetchand no timeoutws.js:fetch0,timeout0. hranaws/*.js+index.jstimeout0, controlfetchoverhttp/*.js15. File 11/11 on bothturso-driver.ts:1061(message)config.fetchis read once, inside_createClientinhttp.js(byte-identical)turso-driver.ts:1212FILE:./x.dbgivesfile,Wss://giveswss,LIBSQL://giveshttps.createClientopens each (http/ws/file)turso-driver.ts:1244:memory:expands tofile::memory:;isInMemoryConfigfile::memory:.trueforfile::memory:andfile::memory:?cache=shared, controlfalseforfile:./x.dbAfter the edit,
git grep -n -E "0\.17\.[0-9]" -- packages/drivers/driver-turso/srcreturns 0 lines (exit 1). The control is the 230.18.0occurrences in the same 7 files.What #21029 never measured
cf1d700b, before themainmerge:rest250 files, 4728 passed / 248 skipped.driver-sql205 files, 3303 passed / 188 skipped.plugin-email31 files, 510 passed.plugin-approvals52 files, 804 passed.plugin-webhooks13 files, 160 passed.trigger-schedule8 files, 170 passed.connector-mcp3 files, 23 passed.client-react3 files, 34 passed. Turbo ran 45 of 45 tasks, exit 0.Lint & Repo Gatesfromcheck:vendor-export-contracton:pnpm check:vendor-export-contractreadsVERDICT: PASS — vendor export contract (installed workspace), 1 edge(s) verified(better-auth 1.7.3), and the-resolvevariant passes on the registry. The 72 later steps of that job were not run here. They belong to CI's run on this PR. The families this diff derives are below.osv-scannerv2.3.8, built from the Go module proxy because this container's egress refusesapi.osv.dev. It ran on the offline npm database over lockfile blob70547c67(its resolved set is identical to the current30ba2147), with the repo'sosv-scanner.tomlloaded: 1388 packages,No issues found, exit 0. Positive control: the same lockfile withhonorewritten to 4.12.32 gives exit 1 and 8 advisories onhono, among them GHSA-8j4g-w8fx-2239. CI's online step is the authoritative reading.zod4.6.5 andz.properties():git grep -n -E "z\.properties\(" -- packages/returns 0 lines; controlz.object(, 1825 lines.mongodblive suites: NOT MEASURED. They need amongoddownload fromfastdl.mongodb.org, which this container's egress refuses (CONNECT 403). The defaultdriver-mongodbsuite passes: 30 files, 675 passed, 172 skipped (the five opt-in live files).Gates and tests
Gate families derived by
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands(no paths, change set from git) at HEAD0f87e8488(54 paths against merge basee35c40a52): 117 commands. All 117 exit 0, and so doespnpm check:vendor-export-contract. Exit codes were captured before any pipe.--ranreconciliation:117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN, a derived zero with an exit code on every line.Package suites, all exit 0:
cf1d700b:driver-mongodb,mcp32/344,plugin-hono-server27/324,plugin-auth115/2472,service-settings33/584,plugin-pinyin-search2/21,driver-sqlite-wasm36/675,driver-memory69/1613,service-analytics155/3526 (10 skipped),create-objectstack16/247,@objectstack/hono5/122. Also@objectstack/cli--project unit242/3432 and@objectstack/spec--project local591 files / 17368 passed.typecheck: the 19 moving packages plusclient-react,@objectstack/honoandlint. Turbo ran 80 of 80 tasks.0f87e8488, after the feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 merge and a full rebuild: thedriver-tursosuite (82 files) gives 2218 passed / 33 skipped / 0 failed. That includes feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's new tests, run on 0.18.0; its two-process concurrency test overlapped, with 400 writes and 400 distinct numbers.typecheckpasses, andpnpm install --frozen-lockfilepasses.Acceptance notes
zod4.6.1,react19.2.8 andyaml2.9.0 are kept only by the excludedapps/docstree.@noble/ciphers2.3.0 is kept only by the excluded better-auth 1.7.3.mongodb7.5.0 is kept only by the test harnessmongodb-memory-server-core11.3.0.:memory:and for embedded replicas. On a replica, a secondsync()therefore waits for the first to release the connection. On 0.17.4 the two ran at once on the same native handle. Withtimeoutset, a sync that outlives the window keeps running natively, uncancelled, so the next periodic sync queues behind it. No driver docblock claims either behaviour.CHANGELOG.md, onlyservice-packageindex.ts:192andmysql2-tuple.test.ts:172name 0.17.4 ("Measured on@libsql/client0.17.4"). That is a dated attestation and stays true; theresult.rowsshape was re-measured identical on 0.18.0.AGENTS.mdwhenever an agent runs a repository-scoped turbo command. It was restored after each turbo run withgit restore --source=HEAD --staged --worktree AGENTS.md. No commit on this branch touchesAGENTS.md.tsxat 4.23.12 while this branch removestsx@4.23.12. The two lockfiles merged into one thatpnpm install --frozen-lockfilerefuses. Fixed by mergingmainate35c40a52, lifting thattsxline, and regenerating the lockfile with pnpm.Generated by Claude Code