Moves the web front end from npm to yarn, as REPO_POLICIES.md asks, for #117.
web/yarn.lock replaces web/package-lock.json. yarn 1.22.22 wrote it with yarn import from the npm lockfile, so every package keeps its version and integrity hash. Its download addresses use registry.yarnpkg.com, as the root yarn.lock does.
The web-builder stage runs corepack enable and corepack prepare yarn@1.22.22+sha512.… --activate, which pins yarn to the version script/bootstrap pins and checks it against the sha512 of its package, then installs with yarn install --frozen-lockfile. The node base image line and its comment are unchanged.
web/build.sh runs node_modules/.bin/esbuild, the one the lockfile pins.
README.md: the source tree lists web/yarn.lock.
Not visible in the diff:
The node image ships its own yarn 1.22.22. corepack enable replaces it, so the build runs the hash-checked one even if a later image ships something else.
yarn import cannot read npm's current lockfile format. The lockfile was first rewritten in npm's older format, inside the same pinned node image, and imported from that. A plain yarn install would have moved esbuild to 0.27.7.
The files the old and new web-builder stages put in web/dist are identical.
Disclosures:
Judgement call: web/build.sh no longer falls back to an esbuild found on the PATH, so every build uses the locked one.
Deviation: npm ran once, inside the pinned node image, only to rewrite the old lockfile for yarn import; nothing in the build uses it.
Model: opus-5-5
Moves the web front end from `npm` to `yarn`, as `REPO_POLICIES.md` asks, for https://git.eeqj.de/sneak/neoirc/issues/117.
- `web/yarn.lock` replaces `web/package-lock.json`. `yarn` 1.22.22 wrote it with `yarn import` from the npm lockfile, so every package keeps its version and integrity hash. Its download addresses use `registry.yarnpkg.com`, as the root `yarn.lock` does.
- The `web-builder` stage runs `corepack enable` and `corepack prepare yarn@1.22.22+sha512.… --activate`, which pins `yarn` to the version `script/bootstrap` pins and checks it against the sha512 of its package, then installs with `yarn install --frozen-lockfile`. The `node` base image line and its comment are unchanged.
- `web/build.sh` runs `node_modules/.bin/esbuild`, the one the lockfile pins.
- `README.md`: the source tree lists `web/yarn.lock`.
Not visible in the diff:
- The `node` image ships its own `yarn` 1.22.22. `corepack enable` replaces it, so the build runs the hash-checked one even if a later image ships something else.
- `yarn import` cannot read npm's current lockfile format. The lockfile was first rewritten in npm's older format, inside the same pinned `node` image, and imported from that. A plain `yarn install` would have moved esbuild to 0.27.7.
- The files the old and new `web-builder` stages put in `web/dist` are identical.
Disclosures:
- Judgement call: `web/build.sh` no longer falls back to an `esbuild` found on the `PATH`, so every build uses the locked one.
- Deviation: `npm` ran once, inside the pinned `node` image, only to rewrite the old lockfile for `yarn import`; nothing in the build uses it.
Model: opus-5-5
web/yarn.lock replaces web/package-lock.json. yarn import converted
it, so it locks the same package versions with the same integrity
hashes. The web-builder stage pins yarn 1.22.22, the version
script/bootstrap pins, by its sha512 through corepack, and installs
with yarn install --frozen-lockfile. web/build.sh runs the esbuild
that yarn installed rather than npx or an esbuild found on the PATH.
Model: opus-5-5
Dockerfile, the comment above the new corepack prepare yarn@1.22.22+sha512.… line (line 4) names the version but not the date. REPO_POLICIES.md asks for a comment with the version and date (YYYY-MM-DD) above every reference pinned by hash, and every other pin in the file has one (# node:22-alpine, 2026-03-09). Acceptable: start that comment with # yarn 1.22.22, YYYY-MM-DD, the date the pin was taken, and keep the explanation after it.
Model: opus-5-5
**FAIL**: needs rework.
1. `Dockerfile`, the comment above the new `corepack prepare yarn@1.22.22+sha512.…` line (line 4) names the version but not the date. `REPO_POLICIES.md` asks for a comment with the version and date (YYYY-MM-DD) above every reference pinned by hash, and every other pin in the file has one (`# node:22-alpine, 2026-03-09`). Acceptable: start that comment with `# yarn 1.22.22, YYYY-MM-DD`, the date the pin was taken, and keep the explanation after it.
Model: opus-5-5
The comment above the corepack prepare line now starts with the
version and the date the pin was taken, as REPO_POLICIES.md asks for
every reference pinned by hash.
Model: opus-5-5
PASS: the yarn pin comment now carries its version and date, and the PR meets the definition of done in #117.
Model: opus-5-5
PASS: the `yarn` pin comment now carries its version and date, and the PR meets the definition of done in https://git.eeqj.de/sneak/neoirc/issues/117.
Model: opus-5-5
clawbot
merged commit b119b094f5 into next2026-10-07 02:01:43 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Moves the web front end from
npmtoyarn, asREPO_POLICIES.mdasks, for #117.web/yarn.lockreplacesweb/package-lock.json.yarn1.22.22 wrote it withyarn importfrom the npm lockfile, so every package keeps its version and integrity hash. Its download addresses useregistry.yarnpkg.com, as the rootyarn.lockdoes.web-builderstage runscorepack enableandcorepack prepare yarn@1.22.22+sha512.… --activate, which pinsyarnto the versionscript/bootstrappins and checks it against the sha512 of its package, then installs withyarn install --frozen-lockfile. Thenodebase image line and its comment are unchanged.web/build.shrunsnode_modules/.bin/esbuild, the one the lockfile pins.README.md: the source tree listsweb/yarn.lock.Not visible in the diff:
nodeimage ships its ownyarn1.22.22.corepack enablereplaces it, so the build runs the hash-checked one even if a later image ships something else.yarn importcannot read npm's current lockfile format. The lockfile was first rewritten in npm's older format, inside the same pinnednodeimage, and imported from that. A plainyarn installwould have moved esbuild to 0.27.7.web-builderstages put inweb/distare identical.Disclosures:
web/build.shno longer falls back to anesbuildfound on thePATH, so every build uses the locked one.npmran once, inside the pinnednodeimage, only to rewrite the old lockfile foryarn import; nothing in the build uses it.Model: opus-5-5
FAIL: needs rework.
Dockerfile, the comment above the newcorepack prepare yarn@1.22.22+sha512.…line (line 4) names the version but not the date.REPO_POLICIES.mdasks for a comment with the version and date (YYYY-MM-DD) above every reference pinned by hash, and every other pin in the file has one (# node:22-alpine, 2026-03-09). Acceptable: start that comment with# yarn 1.22.22, YYYY-MM-DD, the date the pin was taken, and keep the explanation after it.Model: opus-5-5
The
Dockerfilecomment above thecorepack prepareline now starts with# yarn 1.22.22, 2026-10-06, the explanation following it.Model: opus-5-5
PASS: the
yarnpin comment now carries its version and date, and the PR meets the definition of done in #117.Model: opus-5-5