Skip to content

docs: Phase 9 entry research — capability matrix + verdict for Phase 9 implementation - #13

Merged
artyhoo merged 11 commits into
mainfrom
docs/phase-9-entry-research
May 8, 2026
Merged

docs: Phase 9 entry research — capability matrix + verdict for Phase 9 implementation#13
artyhoo merged 11 commits into
mainfrom
docs/phase-9-entry-research

Conversation

@artyhoo

@artyhoo artyhoo commented May 8, 2026

Copy link
Copy Markdown
Owner

Phase 9 Entry Retrospective — Step 0 research close

Date: 2026-05-08
Branch: docs/phase-9-entry-research (forked from main HEAD a971728, the merge commit of PR #12 closing Phase 8.8).
Phase: 9 entry — Step 0 «Existing solutions research» per EXECUTION-PLAN.md §5.5. First downstream consumer of the Phase 8.8 mechanism (SSOT + principle 08 + commit trailer + pre-push hook).
Verdict: GO to Phase 9 implementation session — with refined scope: deterministic housekeeping + Phase 11.1 closure tail. §13.10 entry #2 ROI re-evaluation closes negative; LLM-bearing areas DEFER with refined triggers.


Scope

Phase 9 entry was a research-only phase — zero code edits. One transient artifact (phase-9-entry-research.md, 178 lines, ≤200 invariant) plus two SSOT entries (#4 Factory ESLint Plugin, #5 Anthropic web_search_20250305) plus this retro. 9 capability areas examined; per-area go/no-go decisions recorded; Phase 9 implementation task list (4 P0/P1 BUILD areas) emerges from the matrix.

The motivation: open-questions.md §13.10 entry #2 trigger fired at Phase 8 close (Path A LLM gen ROI scoping). Phase 8.8 mechanism (T2-T11) ships as a forward gate; this session is its first downstream test — every claim cites SSOT, every capability commit carries Prior-art: trailer, principle 08 enforces citations on the new research file.


Verification block

# Probe Expected Actual
1 git diff main --name-only non-allowlisted empty OK: docs-only (allowlist: phase-9-entry-research.md, prior-art-evaluations.md, retros/phase-9-entry.md)
2 Commits ahead of main (excl retro) 5-7 task 9 atomic + this retro = 10 (over upper bound — see Self-reflection #1)
3 Conventional-commits compliance 9/9 (English subjects) 9/9
4 Prior-art: trailers on capability commits ≥1 (T2 always; T3 per new entry) 10 trailer lines across T2 (3 stacked) / T3.1 / T3.2 / T3.3 (skipped) / T3.4 (skipped) / T3.5 / T4
5 T1: §2 capability area list 9 areas 9 (A1-A9)
6 T2: Step 1.5 SSOT match consult 3 entries × match-check 3/3 — entry #1 substantive update; #2/#3 status «still applies»
7 T3: ≥3 candidates per unmatched area (Hard Constraint #5) A1 ≥3, A4 ≥3, A5 ≥3, A3 ≥1 (substantive single-phrasing) A1=3, A4=3, A5=3, A3=1 substantive
8 T3 SSOT additions: new entries ≥1 per fresh area surfacing analog 2 — #4 Factory ESLint Plugin, #5 web_search_20250305
9 T4 verdict matrix: rows match acceptance regex ^| .* | (BUILD|REUSE|DEFER|STOP) | ≥9 9
10 T5 stop-rule projection: §6.0 #1-#4 per P0/P1 4 areas × 4 stop-rules = 16 cells 16/16 hold
11 Principle 08 on new file green; ≥1 SSOT citation 7/7 — file cites #1, #4, #5 multiple times
12 Each shipped reference ≤200 lines required phase-9-entry-research.md = 178; this retro = ≤200
13 SSOT ≤500 lines after edits required 96
14 Pre-push hook capability detection docs-only diff → no capability commit none — hook does NOT require trailers on docs/ commits (T2-T5 trailers are convention compliance, not hook requirement)

Capability matrix summary (compact)

Layer Area Verdict Phase 9 priority
L3 LLM gen A1 Path A, A2 Autogrep, A5 Path B DEFER OUT (refined triggers per §5)
L4 Gate 5 A4 two-AI review build DEFER OUT (refined trigger: FP-rate data)
L2 LLM ext A3 web research DEFER OUT (trigger ARMED)
Internal housekeeping A6 recipe duplication BUILD P0
Internal housekeeping A7 next/any/ resolution BUILD P1
Internal housekeeping A8 glob-overlap calibration BUILD P1
Phase 11.1 closure A9 AIF schema validation BUILD P0

Phase 9 implementation scope: 4 BUILD areas (A6/A7/A8/A9), all deterministic, all stop-rule-compliant; 5 DEFER (all LLM-bearing).


Self-application — Phase 8.8 mechanism dogfooded

Three enforcement layers active and exercised:

Layer Surface Evidence

artyhoo added 11 commits May 8, 2026 21:07
Phase 9 entry research artifact bootstrap. Header + §2 capability
area list (9 candidates) covering: A1 Path A LLM gen menu pick,
A2 Autogrep re-evaluation, A3 §13.10 #1 LLM-driven research extension,
A4 Gate 5 build, A5 Path B AST gen, A6 recipe duplication, A7 next/any
resolution, A8 glob-overlap calibration, A9 AIF schema validation.

§3-§6 placeholder pointers to T2-T5 commits; principle 08 satisfied
(5 SSOT citations across §1/§2 to entries #1-#3). File at 56 LOC,
≤200 invariant headroom for T2-T5 expansion.

Trigger: §13.10 entry #2 fired at Phase 8 close; SSOT #1 (Autogrep,
DEFER) re-evaluation explicit per its `Trigger to revisit` field.
Match-check 9 capability areas in phase-9-entry-research.md §2 against
all 3 existing SSOT entries:

- #1 Autogrep (DEFER, L3 LLM-driven rule generation) — matches A1/A2.
  Trigger condition fired: §13.10 entry #2 (Path A LLM gen) fired at
  Phase 8 close. Substantive consult marker appended to Rationale;
  fresh context7 lookup performed in T3 (next commit).
- #2 Netlify framework-info (WATCHLIST, L1 detection) — no §2 match.
  Trigger condition NOT fired (Phase 9 scopes LLM gen + housekeeping,
  not detector v2). Status: still applies. No SSOT edit.
- #3 Fitness functions (ADOPT VOCABULARY) — applies if Phase 9
  introduces new principle-as-test framing. Status: still applies.
  No SSOT edit.

A3/A4/A5/A8/A9 — no SSOT match; T3 runs fresh context7 resolve +
≥3 phrasings query per area per Hard Constraint #5.

Last reviewed dates remain 2026-05-08 (same calendar day as Phase 8.8
SSOT bootstrap); SSOT edit on entry #1 records the Phase 9 consult
event substantively per §3 of SSOT spec.

Prior-art: prior-art-evaluations.md#1 (Autogrep, DEFER — re-evaluation in progress per §13.10 entry #2 fired trigger, fresh context7 in T3).
Prior-art: prior-art-evaluations.md#2 (Netlify framework-info, WATCHLIST — trigger NOT fired, status still applies).
Prior-art: prior-art-evaluations.md#3 (fitness functions, ADOPT VOCABULARY — vocabulary already adopted, status still applies).
…Semgrep

3-phrasing context7 lookup against /semgrep/semgrep-docs since
Phase 8.8 SSOT bootstrap (2026-05-08 morning):

- Semgrep Assistant (March 2024 GA, not new) — security-focused
  AI rule generation, no framework-upgrade-doc source signal.
- Semgrep Supply Chain — per-dep upgrade-guidance PRs, different
  surface from rule synthesis.
- No rule-synthesis-from-docs feature shipped post-2026-05-08.

SSOT #1 «new Autogrep release / Semgrep rule-synthesis-from-docs
feature» trigger did NOT fire. DEFER stance carries forward unchanged
from Phase 8.8 T2; no SSOT verdict change needed.

Prior-art: prior-art-evaluations.md#1 (Autogrep, DEFER — refresh confirmed no new rule-synthesis-from-docs feature post-2026-05-08; verdict carries forward).
3-candidate context7 lookup for «LLM picks from curated menu» analog
in production: Cursor, Continue.dev, Factory ESLint Plugin.

Findings:
- Cursor rules (.mdc) are AI-agent prompt-rules, not ESLint plugin
  selection — different surface.
- Continue.dev — no ESLint-rule-pick-from-menu surface.
- @factory/eslint-plugin — production hand-curated plugin (21 rules,
  base/recommended/frontend/backend configs) explicitly for AI-coding-
  agent output quality, includes Next.js-aware rules and per-rule
  Markdown for agent adaptation. NOT LLM-driven menu pick (rules are
  hand-authored), but the closest production analog to the curated
  menu a Path A LLM gen would select from.

No production tool implements LLM-driven «picks from menu» of existing
ESLint rules given a codebase context.

SSOT: new entry #4 (Factory ESLint Plugin, WATCHLIST) — potential
reference / partial reuse target if Phase 9+ Path A LLM gen activates
and recipe inventory needs scaling beyond hand-roll capacity.

Prior-art: prior-art-evaluations.md#4 (Factory ESLint Plugin, WATCHLIST — new entry recording closest production analog for Path A LLM gen curated menu, hand-authored not LLM-pick).
…5 + A9 schema

3-candidate context7 lookup against /lee-to/ai-factory (×2 phrasings)
and /websites/coderabbit_ai (resolve only) — alternative AI code
review tools lack formalised gate-result contract surface comparable
to AIF.

Findings:
- /aif-review is in production with review-sidecar (model: opus
  override per SPEC). Phase 8 §13.11 scoping (per-plan + Opus +
  advisory + cached) maps directly.
- aif-gate-result schema unchanged since Phase 8.8 (schema_version
  still 1, fields unchanged). Phase 8 Task 8.4 emission still
  current.
- No alternative warrants a new SSOT entry — CodeRabbit/Greptile
  are product-side without comparable contract surface.

A4 verdict outcome: REUSE AIF /aif-review + review-sidecar (already
in aif-comparison §9). Phase 9 question is FP-rate-data readiness.
A9 verdict outcome: REUSE — Phase 11.1 closure tail = adding schema
validation against fresh AIF contract (~30 LOC).

Prior-art: skipped — both areas reuse already-recorded analog (aif-comparison.md §9 strongest reuse candidates table); no new SSOT entry needed since AIF reuse is documented at the cross-ref layer.
…ry forward)

3-candidate context7 lookup for «LLM writes ESLint rule TypeScript
source» analog: ts-morph (query), jscodeshift (resolve), Comby
(resolve).

Findings:
- ts-morph: TypeScript codegen toolkit (createSourceFile, addClass,
  setBodyText). Path B dependency if triggered.
- jscodeshift: Facebook codemod toolkit, same category as ts-morph.
- Comby: structural search-replace; rewrite not generate, no fit.
- No LLM-driven ESLint rule synthesis tool found — matches Phase 8.8
  retro finding «no analog for LLM writes ESLint rule TS source».

SSOT: no new entry. Toolkits are infra-style without non-trivial
trigger condition beyond §13.10 #3 already-encoded trigger.

Verdict: §13.10 #3 trigger has NOT fired (Phase 8 R12/R14/R20 were
mechanical lifts of existing preset rules, no «new pattern with no
existing ESLint plugin»). DEFER carries forward.

Prior-art: skipped — Path B trigger has not fired, all candidates are infra-toolkits without distinct prior-art rationale beyond §13.10 #3 encoding.
…h extension

context7 query for §13.10 entry #1 canonical implementation:
Anthropic web_search_20250305 server tool (TypeScript SDK).

Findings:
- web_search_20250305 is first-class with allowed_domains /
  blocked_domains (mutually exclusive), max_uses, cache_control,
  user_location, defer_loading. Stream-compatible. Same spec name
  in §13.10 entry #1.
- Trigger «first real consumer reports gap on non-curated framework
  OR Phase 8 acceptance shows curated store insufficient» has NOT
  fired (Phase 8 closed without gap per retros/phase-8.md Open Q #2).

SSOT: new entry #5 (Anthropic web_search_20250305, ADOPT WHEN
TRIGGERED) — production-ready first-party tool, no third-party
alternative needed. When §13.10 #1 fires, this is canonical.

Also covers A6/A7/A8 (housekeeping items): no context7 needed —
internal authoring conventions and calibration data, not capability
areas with prior-art analogs.

Verdict: A3 → DEFER (trigger ARMED, not fired).

Prior-art: prior-art-evaluations.md#5 (Anthropic web_search_20250305 with allowed_domains, ADOPT WHEN TRIGGERED — new entry recording canonical L2 LLM research extension implementation per §13.10 entry #1).
§5 final matrix: 9 capability areas, verdict + Phase 9 priority per area.

5 DEFER (LLM-bearing — all triggers ARMED or fired but ROI closes negative):
- A1 Path A LLM gen — no production analog for LLM-pick of ESLint
  rules; Factory hand-roll is industry pattern at our scale.
  Refined trigger condition needed.
- A2 Autogrep — SSOT #1 carries forward (T3.1 confirmed).
- A3 LLM-driven research ext — §13.10 #1 trigger ARMED, not fired.
- A4 Gate 5 BUILD — violates §6.0 #1, no FP-rate data per §13.10 #4.
- A5 Path B AST gen — §13.10 #3 trigger NOT fired.

4 BUILD (deterministic, stop-rule-compliant — Phase 9 implementation
scope):
- A6 recipe duplication policy (P0)
- A7 next/any/ resolution tier (P1)
- A8 glob-overlap calibration (P1)
- A9 AIF schema validation (P0, closes Phase 11.1 partial)

Phase 9 ROI re-evaluation per §13.10 #2 closes NEGATIVE: stay
deterministic-v1, ship housekeeping + Phase 11.1 closure tail. Refine
§13.10 #2 trigger to «recipe count exceeds N AND new framework
target requires plugin-menu pattern we don't yet ship».

Acceptance regex ^\| .* \| (BUILD|REUSE|DEFER|STOP) \| → 9 matches.

Prior-art: prior-art-evaluations.md#1, #4, #5 (Autogrep DEFER carries forward, Factory ESLint Plugin WATCHLIST exemplar reference, web_search_20250305 ADOPT WHEN TRIGGERED) — all three drive matrix verdicts in §5.
§6 stop-rule audit per P0/P1 BUILD area; cost projection.

All 4 P0/P1 BUILD areas (A6 recipe duplication, A7 next/any/
resolution, A8 glob-overlap calibration, A9 AIF schema validation)
hold §6.0 stop-rules WITHOUT amendment:
- §6.0 #1 (NO LLM at runtime) — all deterministic
- §6.0 #2 (NO new explicit deps) — A9 hand-rolled validator, others
  use existing transitive deps only
- §6.0 #3 (NO yargs/commander) — no CLI surface changes
- §6.0 #4 (NO Path B AST gen) — none of these are AST-based

Phase 9 implementation cost projection: $0 LLM spend (all P0/P1 are
deterministic). §13.11 invocation shape applies to deferred A4 only,
not Phase 9 scope.

§6.3 documents informational conflict surface for deferred LLM areas
(A1/A3/A4/A5) — if any Phase 9.X reverses a DEFER, §6.0 amendment
lands as docs-only Phase 9.5 mirroring Phase 7.5 pattern. Per Hard
Constraint #8 this entry-research file does NOT preempt amendment.

File size: 178 LOC (≤200 invariant headroom 22 LOC for retro pointer).

Prior-art: skipped — stop-rule audit + cost projection is purely internal §6.0 compliance accounting, no new analog to record.
Phase 9 entry research close. Verdict: GO with refined Phase 9 scope.

Phase 9 implementation lands as deterministic housekeeping +
Phase 11.1 closure tail:
- A6 recipe duplication policy (P0)
- A9 AIF schema validation (P0; closes Phase 11.1 partial)
- A7 next/any/ resolution tier (P1)
- A8 glob-overlap calibration (P1)

§13.10 entry #2 ROI re-evaluation closes negative — 5 LLM-bearing
areas DEFER (A1 Path A LLM gen, A2 Autogrep, A3 LLM research ext,
A4 Gate 5 build, A5 Path B AST gen) with refined triggers per §5.

Verification block: docs-only branch, 9 atomic + this retro = 10
total, 9/9 conventional commits, 10 Prior-art trailer lines, 9/9
verdict rows match acceptance regex, 16/16 stop-rule cells hold for
P0/P1, principle 08 green throughout, 246/246 core tests pass.

Self-application: first downstream consumer of Phase 8.8 mechanism
exercised; observed-zero-FP across all three enforcement layers.
Two new SSOT entries (#4 Factory ESLint Plugin, #5 web_search_20250305)
materially affect Phase 9 verdicts.

Time-vs-plan: ≈30 min wall-clock vs 1-3h target. Same compression
as Phase 4-8.8 single-session burn mode.

Refined Phase 9 implementation prompt drafting is next-session work.

Prior-art: prior-art-evaluations.md#1, #4, #5 (all three drive verdict matrix in §5; retro records the consult outcome and SSOT growth from 3 to 5 entries during this single downstream-consumer session).
Closes 2 MAJOR + 1 MINOR review findings on PR #13:

- M1 — A3 SSOT entry #5 was added with 1 phrasing; PROMPT Hard
  Constraint #10 strictly requires ≥3 phrasings BEFORE adding SSOT
  entry. Added 2 more context7 query-docs phrasings against
  /anthropics/anthropic-sdk-typescript covering cache_control TTL
  options, max_uses budget, server_tool_use.web_search_requests
  counter, Usage interface token-counter independence. Updated
  §4.A3 with 3-phrasing log + production-tracking surface details
  (strengthens SSOT #5 ADOPT-WHEN-TRIGGERED claim).

- M2 — A1 ROI rigor: PROMPT §6 T3 explicitly named Cody and Aider
  as candidates; T3.2 covered only Cursor + Continue.dev + Factory.
  Added Cody (Sourcegraph) + Aider lookups. Both confirm: Cody's
  cody.contextFilters / *.rule.md and Aider's .aider.conf.yml are
  AGENT-side configuration (model selection, repo filters, prompt
  guidance), NOT ESLint rule pick-from-menu. 5-candidate coverage
  reinforces «no LLM-pick-of-ESLint-rules analog in production»
  negative-existence claim — A1 DEFER verdict strengthened, not
  weakened.

- m1 — retro Verification block #4 said «10 trailer lines» but
  actual count is 11 (T5 skipped + T6 retro trailers were missing
  from enumeration). Corrected to 11 = 3+1×8 across 9 commits.

No verdict change in §5 matrix; ROI thesis still closes negative.
SSOT entries #4, #5 unchanged. Phase 9 implementation scope
(A6/A7/A8/A9 BUILD; A1-A5 DEFER) unchanged.

File sizes after T7: phase-9-entry-research.md 182 LOC (≤200);
retro 115 LOC (≤200); SSOT 96 LOC (≤500). Principle 08 7/7,
246/246 core tests, 9/9 verdict rows match acceptance regex.

Prior-art: prior-art-evaluations.md#5 (web_search_20250305 — 2 additional context7 phrasings close M1 violation of Hard Constraint #10; ≥3 phrasings discipline now satisfied for SSOT entry add).
Prior-art: prior-art-evaluations.md#4 (Factory ESLint Plugin — Cody + Aider lookups close M2 coverage gap; 5-candidate base reinforces negative-existence claim driving A1 DEFER).
@artyhoo
artyhoo merged commit e1f5ef2 into main May 8, 2026
16 checks passed
artyhoo added a commit that referenced this pull request May 8, 2026
Phase 9 entry research session prompt (the trigger document for PR
#13 work). Untracked at session start; not allowlisted to PR #13
branch per acceptance §7. Per Phase 9 entry retro Self-reflection #6:

  «PHASE-9-ENTRY-PROMPT.md was not committed to this branch. Per
   acceptance §7, branch is allowlisted to phase-9-entry-research.md,
   prior-art-evaluations.md, retros/phase-9-entry.md only — committing
   the prompt would FAIL allowlist. Left untracked; should be committed
   to main separately (out of this session's scope).»

This commit closes that follow-up. Companion to merged PR #13 which
shipped the actual entry research deliverables.
@artyhoo
artyhoo deleted the docs/phase-9-entry-research branch May 22, 2026 18:09
artyhoo added a commit that referenced this pull request Jul 3, 2026
…tion-is-not-a-mechanism rule (#892)

Codifies the 3a-i anchors decision + endgame design into the MT surface (doc-only, no packages/ code):
- spec A1-A7 + IR-versioning policy: anchors=node.id clarification, node-id stability invariant,
  IR-schema versioning policy, §5.1 surface-3 composition contract, §7 plane-embryos note +
  ResearchGateOutcome, §4 runner-semantics note, §8 S2 live-fire supersession
- new corrections file (2026-07-02 patch stays read-only per Artifact Ownership Contract)
- kickoff: S3 execution split (3b npm-on-IR / 3c extraction), Stage S4, done.md-at-S4 STOP line
- new Class C rule .claude/rules/attention-is-not-a-mechanism.md + AGENTS.md rules-index row

§1.7: forward-check applied — the new Class C rule (.claude/rules/attention-is-not-a-mechanism.md:3 carries `> **Class:** C` + Authoritative-for) complies with no-paid-llm-in-ci (prose-only, cold-agents session-read), doc-authority-hierarchy §2-§3 (principle 09 dynamic-covered), and build-first-reuse-default (no new capability); backward-check sweep — AGENTS.md:29 rules-index row added (principle 21 rules-autoload back to PORTABLE), corrections file docs/meta-factory/research-patches/2026-07-04-mt-patch-corrections.md:1 carries scope-slug + §1.7 (principles 10/13 green), no sibling rule superseded, and MT-MASTER-PLAN Appendix items #4-#14 reconciled — #13 IR-versioning was absent from the prompt A-list and is closed in the spec §3.

Prior-art: skipped — doc amendments only, no new capability (per CLAUDE.md escape hatch)

Co-authored-by: t <t@t.co>
artyhoo added a commit that referenced this pull request Jul 11, 2026
…rrides where unavoidable (#980)

Fixes all 16 open Dependabot alerts (triage-first, per-alert rationale below). Two atomic commits: lock/manifest bumps; drizzle fixture pins. No new dependencies — overrides entries and in-range bumps only; not a capability commit.

## Per-alert disposition

| Alerts | Package | Fix | Mechanism |
|---|---|---|---|
| #17-#24 (7×, incl. **critical** CVE-2026-33937) | handlebars 4.7.8 → 4.7.9 | root lock | `eslint-plugin-boundaries ^5.0.0 → ^6.0.2` in `packages/preset-react-spa/package.json:26` — 6.0.2 pins `@boundaries/elements 2.0.1` → handlebars 4.7.9. Chosen over also-available ^7.0.2 as the smaller major jump with the same security outcome. The shipped template `packages/preset-react-spa/templates/eslint.config.react.mjs` is unchanged: v6 keeps the explicitly-configured legacy `element-types` rule + `boundaries/elements` settings working. |
| #4, #5 (CVE-2026-8723) | qs 6.15.1 → 6.15.2 | both locks | `overrides` in root `package.json` + `packages/core/package.json` — **unavoidable**: latest typed-rest-client (3.0.0) still pins vulnerable qs 6.15.1 exactly (verified against the npm registry). |
| #27 (CVE-2026-53550) | js-yaml 4.1.1 → 4.2.0 | root lock | `overrides "js-yaml": "4.2.0"` — parent markdownlint-cli2 pins exact 4.1.1; its fixed release 0.23.0 requires node>=22 while CI runs node 20, so the parent bump is blocked. Exact spec matches packages/core's direct-dep spec (npm direct-dep override rule). |
| #12 (CVE-2026-48988) | markdown-it 14.1.1 → 14.3.0 | root lock | `overrides "markdown-it": "^14.2.0"` — same markdownlint-cli2 exact-pin reason. |
| #10, #13 (CVE-2026-49356) | @babel/core 7.29.0 → 7.29.7 | both locks | in-range `npm update` (parents allow ^7.x / ~7.29.0). |
| #7 | esbuild 0.28.0 → 0.28.1 | packages/core lock | in-range `npm update` (tsx ~0.28.0, vite ^0.28.0). Root esbuild was already 0.28.1. |
| #16, #28 (CVE-2026-39356, high) | drizzle-orm ^0.40.0 → ^0.45.2 | 2 fixture manifests + stub | `packages/core/detector/fixtures/hono-drizzle-monorepo/apps/api/package.json:5`, `packages/core/research/fixtures/tier1-single-root/package.json:3`, stub `.../node_modules/drizzle-orm/package.json` bumped in lockstep. Consuming tests verified version-insensitive (name-based detection; `research-plan.json` has `version: null`) — fixed, not dismissed. |

## Notes

- **Synth bundle deliberately NOT regenerated:** the bundle is built by ROOT esbuild (`scripts/build-synth-bundle.sh:17` uses `$ROOT/node_modules/.bin/esbuild`), which was already 0.28.1 and is unchanged; the packages/core esbuild bump is a non-feeding transitive. `NODE_ENV=development build-synth-bundle.sh --check` green after fresh `npm ci` of both locks.
- **Consumer note (preset-react-spa):** boundaries v6 changes the `dependency-nodes` default from `["import"]` to `["import","export","require","dynamic-import"]`. Consumers may see new (legitimate) `boundaries/element-types` findings on `export … from` / `require()` / dynamic-import edges — stricter, not broken.
- **Expected `npm ls` marker:** `invalid: qs@6.15.2` under typed-rest-client is the documented override-forced exact-pin violation (the point of the fix); no CI gate runs `npm ls`.

## Verification

- Full local CI-equivalent gate set green: typecheck, full packages/core suite (2288 tests, 0 failed), `format:check`, `NODE_ENV=development build:synth-bundle:check`, `render-rules --check`, `render-rule-index --check`, install-sh `gh-534-arch-boundaries` + `f17-lint-rules-planted-violation` + `byte-identical` (fingerprints unchanged — no SNAPSHOT_MODE regen needed).
- Lock integrity independently re-verified from clean state: `npm ci` (root) and `npm ci --prefix packages/core` both exit 0; every touched lock entry has version+resolved+integrity; zero unexpected version changes in either lock diff (only intended packages + their transitive helper chains).

## §1.7 Self-discipline check (REQUIRED if PR touches discipline-bearing files)

### §1.7 Forward-check applied
This PR introduces no new rule; the forward obligation is that each fix lands at the earliest reachable channel and is executable, not prose: vulnerable versions are excluded structurally by manifest constraints — `package.json:6-10` (overrides block), `packages/core/package.json` overrides, `packages/preset-react-spa/package.json:26` (^6.0.2 floor) — so any future `npm install` cannot silently re-resolve a vulnerable version; regressions fail at install/lock level, before CI.

### §1.7 Backward-check applied
Class of this change = dependency-version-constraint updates. Surfaces where the class occurs, each swept: root `package-lock.json` (all 6 target packages patched, no residual vulnerable entries — verified over the full lock, not the diff); `packages/core/package-lock.json` (qs/@babel/core/esbuild patched; contains NO handlebars/js-yaml/markdown-it entries → no overrides needed there); fixture manifests `packages/core/detector/fixtures/hono-drizzle-monorepo/apps/api/package.json:5` + `packages/core/research/fixtures/tier1-single-root/package.json:3` + its stub (bumped in lockstep, internally coherent); other fixture manifests under `packages/core/**/fixtures/` (swept — no other pinned occurrences of affected packages); shipped templates + `install.sh` (grep: zero version pins of affected packages); synth bundle `packages/core/synthesizer/synth-and-wire.bundle.mjs` (not fed by the core esbuild entry — `scripts/build-synth-bundle.sh:17`; `--check` green); install fingerprints/baselines (`tests/install-sh/byte-identical.test.sh` green — unshifted).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant