build(node): coordinate Node 22.22.2 floor with jsdom 30 - #896
build(node): coordinate Node 22.22.2 floor with jsdom 30#896seonghobae wants to merge 90 commits into
Conversation
|
Queued @opencode-agent for PR #896 at head |
|
Already queued @opencode-agent on this exact request for PR #896 at head |
4 similar comments
|
Already queued @opencode-agent on this exact request for PR #896 at head |
|
Already queued @opencode-agent on this exact request for PR #896 at head |
|
Already queued @opencode-agent on this exact request for PR #896 at head |
|
Already queued @opencode-agent on this exact request for PR #896 at head |
|
Already queued @opencode-agent on this exact request for PR #896 at head |
1 similar comment
|
Already queued @opencode-agent on this exact request for PR #896 at head |
|
Already queued @opencode-agent on this exact request for PR #896 at head |
2 similar comments
|
Already queued @opencode-agent on this exact request for PR #896 at head |
|
Already queued @opencode-agent on this exact request for PR #896 at head |
|
@opencode-agent Continue the canonical Fresh exact-head failure evidence: The older Then prove focused GREEN with the current Node/runtime contract tests and frozen |
|
Fresh downstream evidence for this canonical npm/lock provenance boundary: Dependabot PR #1134 (Vitest 4.1.10→4.1.11), exact head |
|
Fresh downstream evidence reinforces this Draft as the canonical repair owner rather than a documentation-only lane. Three current Dependabot heads generated unrelated npm development updates and reproduced the same lock-provenance failure:
All three runs independently verify the repository-pinned npm For the next complete npm 10.9.9 regeneration in this canonical owner, include the still-valid non-major development intents from those Dependabot PRs where compatible instead of creating a second hand-maintained lock path. Acceptance remains one complete generated root lock preserving |
|
Exact-head RED evidence after the non-force protected-base restack:
This is the intended realistic RED, not an infrastructure failure and not a reason to weaken frozen consumption. The causal fix remains one complete root |
Canonical #779 Node/jsdom compatibility slice
This Draft advances issue #779 on top of the integrated dependency-security baseline from #783. The branch targets protected
develop; predecessor, protected-base, prior-head, or model-only evidence never transfers to the current head.Exact current identity
fc3d1ec01a1124a4e11375259d720a976a53ec5e.develop@889d782e88b4df28dcbb4ae3cfd6d99ef85d9844.developas7ad56cf0065d068ec6463d92726de4855a6e201d.fc3d1ec01a1124a4e11375259d720a976a53ec5eis a non-force two-parent descendant of prior semantic head8e6a73879dac8aebd70f77aa80d55fc9c670a8f5and live protecteddevelop@889d782e88b4df28dcbb4ae3cfd6d99ef85d9844.apps/desktop/src-tauri/Cargo.lock; the restack adopts the exact protected blob rather than regenerating or hand-editing it.develop...HEADisbehind_by=0; the net PR delta remains exactly seven Node/jsdom/npm-policy files and does not carryCargo.lock.Compatibility and security contract
The branch requires:
>=22.22.2 <23, with an explicit rejection regression for Node 22.22.1;10.9.9;tar >=7.5.19before dependency extraction;^30.0.1;22.22.2execution innode-minimum-compatibilitywith setup-node package-manager cache disabled;corepack enable npmfollowed by exact npm/runtime verification before frozen dependency consumption;5108c9ad52056c1960d99d382bceb1bd72c6de98ports the protected npm 10.9.9/runtime-audit authority into this lane and updates the Node-floor regression contracts.8e6a73879dac8aebd70f77aa80d55fc9c670a8f5aligns the canonical npm provenance document with the raised Node floor and makes the non-mergeable lock-generation boundary explicit.fc3d1ec01a1124a4e11375259d720a976a53ec5eonly repairs ancestry against the current protected base; predecessor checks/reviews do not transfer.Current real RED boundary
The branch deliberately uses protected
develop's reviewed #783package-lock.jsonrather than retaining the old divergent/generated artifact. That lock still records the pre-migration Node floor and jsdom 29 graph, while this branch's manifests require>=22.22.2 <23and jsdom 30. Frozen validation and the regression tests therefore fail closed until one complete lock is regenerated with the approved npm10.9.9toolchain.Do not hand-edit the lock and do not transplant the closed Dependabot #760 lock as acceptance evidence. Its dependency graph is reference material only; generator provenance, exact-head checks, reviews, and approvals do not transfer.
The required next dependency action is a complete npm 10.9.9 lock generation on this current ancestry, followed by review of the full generated diff and frozen
npm ciconsumption. The resulting lock must preserve current #783 security state, SRI evidence, root@esbuild/*peer metadata, exact Undici/PDF.js security contracts, the raised root Node floor, and jsdom 30. The open Dependabot intents tracked separately must not be folded by hand; they may be consolidated only when one generated canonical lock proves their exact semantic deltas and evidence.Merge gate
Keep Draft and unmerged until the complete lock is generated by the approved toolchain and one unchanged exact head has every applicable repository/central CI, security, SAST, SBOM/supply-chain, coverage/docstring, build/package/release and review gate terminal-success; zero valid unresolved findings; a qualifying independent non-author last-push approval; and ordinary branch-protection acceptance.
Never weaken a gate, reuse predecessor evidence, self-approve, manufacture approval, or treat queued/pending/skipped/cancelled/failed/neutral/model-only evidence as success.