REPO_POLICIES.md says "Use yarn, not npm", and lists package.json and yarn.lock for JS. The web front end still uses npm: web/package-lock.json, RUN npm ci in the Dockerfile's web-builder stage, and npx in web/build.sh. #115 left this out of scope and said so.
Definition of done
web/ uses yarn: a web/yarn.lock made with the yarn version script/bootstrap pins replaces web/package-lock.json, with the same dependency versions and integrity hashes as today.
The web-builder stage installs with yarn install --frozen-lockfile, with yarn itself pinned to that exact version, and web/build.sh no longer calls npm or npx.
The built front end is unchanged: the files the web-builder stage puts in web/dist are the same as before, or any difference is explained in one line in the PR.
One reviewed PR against next.
Model: opus-5-5
`REPO_POLICIES.md` says "Use `yarn`, not `npm`", and lists `package.json` and `yarn.lock` for JS. The web front end still uses `npm`: `web/package-lock.json`, `RUN npm ci` in the `Dockerfile`'s `web-builder` stage, and `npx` in `web/build.sh`. https://git.eeqj.de/sneak/neoirc/pulls/115 left this out of scope and said so.
## Definition of done
1. `web/` uses `yarn`: a `web/yarn.lock` made with the `yarn` version `script/bootstrap` pins replaces `web/package-lock.json`, with the same dependency versions and integrity hashes as today.
2. The `web-builder` stage installs with `yarn install --frozen-lockfile`, with `yarn` itself pinned to that exact version, and `web/build.sh` no longer calls `npm` or `npx`.
3. The built front end is unchanged: the files the `web-builder` stage puts in `web/dist` are the same as before, or any difference is explained in one line in the PR.
4. One reviewed PR against `next`.
Model: opus-5-5
clawbot
self-assigned this 2026-10-07 00:14:13 +02:00
Built in #118: web/yarn.lock replaces web/package-lock.json with the same versions and integrity hashes, the web-builder stage installs with yarn 1.22.22 pinned by hash, and web/build.sh runs the locked esbuild. The built front end is unchanged.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/neoirc/pulls/118: `web/yarn.lock` replaces `web/package-lock.json` with the same versions and integrity hashes, the `web-builder` stage installs with `yarn` 1.22.22 pinned by hash, and `web/build.sh` runs the locked `esbuild`. The built front end is unchanged.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
REPO_POLICIES.mdsays "Useyarn, notnpm", and listspackage.jsonandyarn.lockfor JS. The web front end still usesnpm:web/package-lock.json,RUN npm ciin theDockerfile'sweb-builderstage, andnpxinweb/build.sh. #115 left this out of scope and said so.Definition of done
web/usesyarn: aweb/yarn.lockmade with theyarnversionscript/bootstrappins replacesweb/package-lock.json, with the same dependency versions and integrity hashes as today.web-builderstage installs withyarn install --frozen-lockfile, withyarnitself pinned to that exact version, andweb/build.shno longer callsnpmornpx.web-builderstage puts inweb/distare the same as before, or any difference is explained in one line in the PR.next.Model: opus-5-5
Built in #118:
web/yarn.lockreplacesweb/package-lock.jsonwith the same versions and integrity hashes, theweb-builderstage installs withyarn1.22.22 pinned by hash, andweb/build.shruns the lockedesbuild. The built front end is unchanged.Model: opus-5-5