Repository navigation
Expand file tree
/
Copy pathpackage.json
More file actions
53 lines (53 loc) · 5.01 KB
/
Copy pathpackage.json
File metadata and controls
53 lines (53 loc) · 5.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
{
"name": "deckgauge",
"version": "0.0.1",
"license": "FSL-1.1-ALv2",
"private": true,
"engines": {
"node": ">=24",
"pnpm": ">=9"
},
"packageManager": "pnpm@9.0.0",
"scripts": {
"dev": "turbo run dev",
"build": "turbo run build",
"//prisma-engines": "@prisma/engines' postinstall downloads a NATIVE schema engine from binaries.prisma.sh. Prisma 7's client runtime needs no engine, but the CLI still fetches one, and on this network every Linux target of that download returns HTTP 200 with a zero-byte body (darwin passes; it is a content block on Linux binaries, not a host block). That failure aborted `pnpm install --frozen-lockfile` in every Docker image, so api/web/worker could not build at all. Skipping the postinstall is safe because nothing INSIDE a container runs the Prisma CLI any more: `prisma generate` and `prisma migrate deploy` both run on the HOST, where the darwin engine downloads fine, and the generated client is portable TypeScript copied into the image. See scripts/deploy-staging.sh and packages/db/prisma.config.ts.",
"//test": "EVERY workspace is now in the gate. @deckgauge/db was excluded because its vitest config called dotenv on the root .env, whose DATABASE_URL is the LIVE staging Postgres on :5433, while two of its suites create and deleteMany. That config now derives a per-checkout database like apps/api and apps/worker, and packages/db/src/test-support/staging-unreachable.test.ts asserts by EXECUTION \u2014 current_database(), not the configuration \u2014 that no suite there can reach staging. The `test:db-unsafe` escape hatch is gone with the danger it named. Never reintroduce a filter here without a named, executable reason.",
"//test-strict": "DECKGAUGE_TEST_STRICT_INTEGRATION=1 is what lets the gate tell a suite that PASSED from a suite that never ran: an unavailable integration capability becomes a NAMED FAILURE from each package's integration-coverage.test.ts instead of a silent skip. It is set HERE, on the script the merge gate runs, because a strict mode nobody runs is the defect restated. A single package (`pnpm --filter @deckgauge/api test`) stays lenient and skips with the same text. The variable is also declared in turbo.json's `test` task: turbo 2 runs strict env mode, so an undeclared variable neither reaches vitest nor enters the cache key \u2014 and a cached non-strict result replayed into a strict run is the same lie by another route.",
"//test-concurrency": "--concurrency=1 is load-bearing twice over, not a performance knob. (1) packages/db and apps/api both write the `organizations` table in the SAME per-checkout database, and apps/api's two deployment-wide suites CLEAR that table to assert `exactly one exists` \u2014 the collision apps/api/src/test-support/exclusive-deployment.ts predicted would arrive the moment another package started creating organizations. In parallel they corrupt each other's fixtures. (2) nine packages' vitest workers at once starved this host's 5.9GB VM until Postgres was unreachable, which reads as catastrophic product breakage rather than as resource starvation.",
"test": "DECKGAUGE_TEST_STRICT_INTEGRATION=1 turbo run test --concurrency=1",
"typecheck": "turbo run typecheck",
"lint": "turbo run lint",
"check:compose": "bash scripts/check-bind-host.sh && bash scripts/check-compose-defaults.sh && bash scripts/check-pinned-env.sh",
"backup": "bash scripts/backup.sh",
"restore": "bash scripts/restore.sh",
"migrate:clickhouse": "pnpm --filter @deckgauge/db migrate:clickhouse",
"deckgauge:advisor": "pnpm --filter @deckgauge/advisor-bridge dev",
"advisor:start": "bash scripts/advisor-bridge.sh start",
"advisor:stop": "bash scripts/advisor-bridge.sh stop",
"advisor:status": "bash scripts/advisor-bridge.sh status"
},
"devDependencies": {
"@types/js-yaml": "^4.0.9",
"@types/node": "^24.10.1",
"eslint": "^10.10.0",
"eslint-config-prettier": "^10.1.8",
"nock": "^14.0.12",
"prettier": "^3.0.0",
"turbo": "^2.10.12",
"typescript": "^6.0.3",
"typescript-eslint": "^8.69.0",
"vitest": "^4.1.11"
},
"pnpm": {
"neverBuiltDependencies": [
"@prisma/engines"
],
"//overrides": "ONLY three remain, and each was verified to still be load-bearing by REMOVING it and re-auditing — an override whose upstream has caught up is dead weight that silently pins a version. postcss@8 (4 advisories return without it, via vite's tree), dompurify@3 (4, via monaco-editor) and uuid@11 (1, via bullmq). Ten others were retired here: js-yaml and brace-expansion@1/@5 became unnecessary at eslint 10, and fast-uri@2/@3, nanoid@3, form-data@4, browserslist@4, fflate@0.8 and ws@8 had already been overtaken by their parents (fastify 5, vitest 4, and direct bumps to ws and postcss). Removing all thirteen moves the audit from 4 high / 6 moderate / 2 low to 6 / 11 / 4; removing the ten changes nothing. Re-check the same way whenever a parent is upgraded.",
"overrides": {
"uuid@11": "^11.1.1",
"postcss@8": "^8.5.12",
"dompurify@3": "^3.4.14"
}
}
}