Build the web front end with yarn (closes #117) #118

Merged
clawbot merged 2 commits from issue-117-yarn into next 2026-10-07 02:01:43 +02:00
Collaborator

Moves the web front end from npm to yarn, as REPO_POLICIES.md asks, for #117.

  • web/yarn.lock replaces web/package-lock.json. yarn 1.22.22 wrote it with yarn import from the npm lockfile, so every package keeps its version and integrity hash. Its download addresses use registry.yarnpkg.com, as the root yarn.lock does.
  • The web-builder stage runs corepack enable and corepack prepare yarn@1.22.22+sha512.… --activate, which pins yarn to the version script/bootstrap pins and checks it against the sha512 of its package, then installs with yarn install --frozen-lockfile. The node base image line and its comment are unchanged.
  • web/build.sh runs node_modules/.bin/esbuild, the one the lockfile pins.
  • README.md: the source tree lists web/yarn.lock.

Not visible in the diff:

  • The node image ships its own yarn 1.22.22. corepack enable replaces it, so the build runs the hash-checked one even if a later image ships something else.
  • yarn import cannot read npm's current lockfile format. The lockfile was first rewritten in npm's older format, inside the same pinned node image, and imported from that. A plain yarn install would have moved esbuild to 0.27.7.
  • The files the old and new web-builder stages put in web/dist are identical.

Disclosures:

  • Judgement call: web/build.sh no longer falls back to an esbuild found on the PATH, so every build uses the locked one.
  • Deviation: npm ran once, inside the pinned node image, only to rewrite the old lockfile for yarn import; nothing in the build uses it.

Model: opus-5-5

Moves the web front end from `npm` to `yarn`, as `REPO_POLICIES.md` asks, for https://git.eeqj.de/sneak/neoirc/issues/117. - `web/yarn.lock` replaces `web/package-lock.json`. `yarn` 1.22.22 wrote it with `yarn import` from the npm lockfile, so every package keeps its version and integrity hash. Its download addresses use `registry.yarnpkg.com`, as the root `yarn.lock` does. - The `web-builder` stage runs `corepack enable` and `corepack prepare yarn@1.22.22+sha512.… --activate`, which pins `yarn` to the version `script/bootstrap` pins and checks it against the sha512 of its package, then installs with `yarn install --frozen-lockfile`. The `node` base image line and its comment are unchanged. - `web/build.sh` runs `node_modules/.bin/esbuild`, the one the lockfile pins. - `README.md`: the source tree lists `web/yarn.lock`. Not visible in the diff: - The `node` image ships its own `yarn` 1.22.22. `corepack enable` replaces it, so the build runs the hash-checked one even if a later image ships something else. - `yarn import` cannot read npm's current lockfile format. The lockfile was first rewritten in npm's older format, inside the same pinned `node` image, and imported from that. A plain `yarn install` would have moved esbuild to 0.27.7. - The files the old and new `web-builder` stages put in `web/dist` are identical. Disclosures: - Judgement call: `web/build.sh` no longer falls back to an `esbuild` found on the `PATH`, so every build uses the locked one. - Deviation: `npm` ran once, inside the pinned `node` image, only to rewrite the old lockfile for `yarn import`; nothing in the build uses it. Model: opus-5-5
clawbot added the needs-review label 2026-10-07 00:55:21 +02:00
clawbot self-assigned this 2026-10-07 00:55:21 +02:00
clawbot added 1 commit 2026-10-07 00:55:21 +02:00
web/yarn.lock replaces web/package-lock.json. yarn import converted
it, so it locks the same package versions with the same integrity
hashes. The web-builder stage pins yarn 1.22.22, the version
script/bootstrap pins, by its sha512 through corepack, and installs
with yarn install --frozen-lockfile. web/build.sh runs the esbuild
that yarn installed rather than npx or an esbuild found on the PATH.

Model: opus-5-5
Author
Collaborator

FAIL: needs rework.

  1. Dockerfile, the comment above the new corepack prepare yarn@1.22.22+sha512.… line (line 4) names the version but not the date. REPO_POLICIES.md asks for a comment with the version and date (YYYY-MM-DD) above every reference pinned by hash, and every other pin in the file has one (# node:22-alpine, 2026-03-09). Acceptable: start that comment with # yarn 1.22.22, YYYY-MM-DD, the date the pin was taken, and keep the explanation after it.

Model: opus-5-5

**FAIL**: needs rework. 1. `Dockerfile`, the comment above the new `corepack prepare yarn@1.22.22+sha512.…` line (line 4) names the version but not the date. `REPO_POLICIES.md` asks for a comment with the version and date (YYYY-MM-DD) above every reference pinned by hash, and every other pin in the file has one (`# node:22-alpine, 2026-03-09`). Acceptable: start that comment with `# yarn 1.22.22, YYYY-MM-DD`, the date the pin was taken, and keep the explanation after it. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-07 01:23:48 +02:00
clawbot added 1 commit 2026-10-07 01:31:35 +02:00
Date the yarn pin comment in the Dockerfile
check / check (push) Waiting to run
c257943f8e
The comment above the corepack prepare line now starts with the
version and the date the pin was taken, as REPO_POLICIES.md asks for
every reference pinned by hash.

Model: opus-5-5
Author
Collaborator

The Dockerfile comment above the corepack prepare line now starts with # yarn 1.22.22, 2026-10-06, the explanation following it.

Model: opus-5-5

The `Dockerfile` comment above the `corepack prepare` line now starts with `# yarn 1.22.22, 2026-10-06`, the explanation following it. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-07 01:42:11 +02:00
Author
Collaborator

PASS: the yarn pin comment now carries its version and date, and the PR meets the definition of done in #117.

Model: opus-5-5

PASS: the `yarn` pin comment now carries its version and date, and the PR meets the definition of done in https://git.eeqj.de/sneak/neoirc/issues/117. Model: opus-5-5
clawbot merged commit b119b094f5 into next 2026-10-07 02:01:43 +02:00
clawbot deleted branch issue-117-yarn 2026-10-07 02:01:44 +02:00
clawbot removed the needs-review label 2026-10-07 02:01:45 +02:00
Sign in to join this conversation.