Files
tool-evaluator/docs/dependency-policy.md
T
opencode 2f66fff993
Build & Push Docker Image / build (push) Failing after 1m18s
chore(deps): upgrade all dependencies to latest and pin exact
Policy: every direct dependency is now an exact pin; lockfile + --frozen-lockfile keep builds reproducible; save-exact=true enforced.

Toolchain:
- pnpm 10.26 -> 11.18 (lockfile migrated; supportedArchitectures moved to pnpm-workspace.yaml)
- typescript 5.9 -> 7.0, vite 7 -> 8, @vitejs/plugin-react 5 -> 6
- esbuild override 0.27.3 -> 0.28.1 (closes GHSA-g7r4-m6w7-qqqr); added @esbuild/darwin-arm64 for local dev
- orval 8.9 -> 8.23, regenerated clients

Backend (prod image):
- openid-client 5.7 -> 6.8 (rewritten OIDC flow in routes/auth.ts: discovery + functional API, PKCE/state, fetchUserInfo, buildEndSessionUrl)
- pino 9 -> 10, pino-http 10 -> 11, thread-stream 3 -> 4
- zod 3.25 -> 4.4 (catalog; supported by drizzle-zod 0.8.3)
- pg 8.20 -> 8.22; removed deprecated @types/bcryptjs

Frontend:
- react/react-dom 19.1.0 -> 19.2.8 (catalog pin lifted; expo note removed)
- react-day-picker 9 -> 10 (table classname -> month_grid)
- recharts 2 -> 3 (TooltipContentProps + DefaultLegendContentProps typing; safe keys)
- react-resizable-panels 2 -> 4 (Group/Separator rename)
- date-fns 3 -> 4, @hookform/resolvers 3 -> 5, lucide-react 0.545 -> 1.28
- all @radix-ui/*, tailwind, types, and remaining patch/minor deps bumped to latest

Security/process:
- overrides for body-parser >=2.3.0 (GHSA-v422-hmwv-36x6) + markdown-it/linkify-it/brace-expansion/fast-uri (dev tooling)
- pnpm audit now reports 0 vulnerabilities (prod and full)
- CI audit gate added to build.yaml; docs/dependency-policy.md; renovate.json
- Dockerfile pins node:24.18.1-alpine and pnpm@11.18.0
2026-08-03 12:56:00 +02:00

55 lines
2.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Dependency Policy
How this workspace keeps npm dependencies current, safe and reproducible.
## Principles
1. **Exact pins** Every direct dependency in `package.json` is pinned to an
exact version (`1.2.3`, never `^1.2.3`). `save-exact=true` is set in
`.npmrc` so `pnpm add` follows this rule automatically.
2. **Committed lockfile** `pnpm-lock.yaml` is committed. CI and the Docker
build install with `--frozen-lockfile`, so builds are reproducible.
3. **Security gates** CI runs `pnpm audit --prod` (fails on any finding) and
`pnpm audit --audit-level high` (fails on high/critical). A non-zero exit
blocks the release pipeline.
4. **Supply-chain protection** `minimumReleaseAge: 1440` (1 day) in
`pnpm-workspace.yaml` blocks freshly published versions. Do not lower or
disable it; only allowlist trusted publishers via
`minimumReleaseAgeExclude` for urgent security fixes.
5. **Pinned critical packages** `react`, `react-dom` and `esbuild` are
intentionally excluded from automated updates (see `renovate.json`). Bump
them deliberately, one release at a time, with a test pass.
## Update cadence
| Frequency | Scope | Who |
|-----------|-------|-----|
| Weekly | Patch + minor (grouped by Renovate) | Renovate PR, human merge after green CI |
| Monthly | One major version at a time | Human, own commit + release tag |
| As needed | Security advisories | Immediate fix + patch release |
| Yearly | Infrastructure review (Node LTS, Postgres major, k3s) | Human |
## Rules
- **Patch/minor**: merge freely once CI (typecheck + build + audit) is green.
- **Major**: never bundle multiple majors into one release. One major per
commit so regressions can be bisected to the responsible change.
- **"Safe intermediate"**: if a package has a newer major that is not yet
absorbed, stay on the latest patch/minor of the *current* major line. The
exact-pin guarantees we never float into a new major by accident.
- **Node/Infra**: Node base image and pnpm version in the `Dockerfile` are
pinned exactly. Update them together with a build + live smoke test.
- **Postgres**: image tag is managed in the `admin/apps` repository
(`apps/system/toolrate`). Major upgrades run through a backup/restore flow.
## Process for applying updates
1. `pnpm install` to refresh the lockfile.
2. Regenerate clients if the API changed: `pnpm --filter @workspace/api-spec run codegen`.
3. Run `pnpm run typecheck`, `pnpm run build` (with `PORT=8080 BASE_PATH=/`),
and `pnpm audit`.
4. Fix any code that the new majors require (the common ones are
`openid-client`, `recharts`, `react-day-picker`, `date-fns`,
`@hookform/resolvers`, `react-resizable-panels`).
5. Commit, tag `vX.Y.Z`, push. CI builds, audits and deploys to k3s.