yarn 1, which the node image ships and which is no longer developed,
printed node's url.parse() deprecation warning during the js-deps
install. package.json now pins yarn 4.18.1 by version and hash in its
packageManager field; the js-deps stage enables it with the node
image's own corepack and runs `yarn install --immutable`. yarn.lock is
regenerated in yarn 4's format from the old lockfile, so every package
keeps the version it had. The new .yarnrc.yml keeps the install in
node_modules/, where the lint and Markdown stages run the tools from.
Model: opus-5-5
`make fmt` formatted only Go, so the org's Markdown settings were unenforced and Markdown was wrapped by hand. prettier, pinned in `package.json` and `yarn.lock` beside ESLint, now formats the Markdown with `.prettierrc` (4-space tabs, `proseWrap: always`). It runs only in Docker: `make fmt` writes the formatted files back without a bind mount, and `make fmt-check`, `make check` and the image build fail on unformatted Markdown. The image build's lint stage now runs the Go format check directly and no longer installs `make`. `README.md` and `TODO.md` are reformatted with no word changed: the README reflows from 72 to 80 columns.
Model: opus-5-5
`REPO_POLICIES.md` binds the repo to a JavaScript styleguide, but nothing checked `static/js/`. ESLint, pinned by `package.json` and `yarn.lock`, now lints it with the styleguide's two checkable rules, `no-var` and `prefer-const`. It runs only in Docker on a digest-pinned node image: a `js-deps` stage installs ESLint and stays cached until the manifests change, and a `js-lint` stage runs it. `script/lint` builds `js-lint`, so `make lint` and `make check` fail on a violation, and the image build depends on it as on the repo's other checks. ESLint, node and yarn are not prerequisites, and `make lint` never uses a host copy.
Model: opus-5-5