Introduce AGENTS.md (root, primary agent instruction file) documenting six hard-won fixes with explicit DO NOT / WHY, plus executable enforcement so a future AI cannot delete or reintroduce them: 1. package-lock.json must be generated with npm 10 (Docker's npm 10.9.8). npm 11 drops the top-level @emnapi/core + @emnapi/runtime entries npm 10 needs, breaking the tag-triggered Docker build at `npm ci` (happened on v1.0.14). Add scripts/verify-lockfile-npm10.mjs + .npmrc + a Dockerfile fail-fast check + a CI step + tests/unit/lockfile-npm10-guard.test.js. Also re-fix the lockfile itself (regenerated with npm 10.9.8). 2. Tests must never write to the real ~/.9router DB (isolateDataDir). 3. Hidden providers must not leak into Usage (usageProviders !p.hidden). 4. codebuddy-intl connection test + OAuth identity. 5. Fork-only features that must survive upstream syncs. 6. Upstream sync procedure. Each marker cross-references AGENTS.md and the covering test. CLAUDE.md now points to AGENTS.md at the top. Verified: build ok, guard script passes, full suite leaves the real DB count unchanged (38), 0 new regressions.
18 lines
656 B
Plaintext
18 lines
656 B
Plaintext
# MIBP fork — npm behavior pin.
|
|
#
|
|
# DO NOT DELETE. See AGENTS.md §1.
|
|
#
|
|
# The Docker image (node:22-alpine, pinned by digest) ships npm 10.9.8 and runs
|
|
# `npm ci` against the committed package-lock.json. Regenerating the lockfile
|
|
# with npm 11+ drops the top-level @emnapi/core + @emnapi/runtime entries npm 10
|
|
# needs, which breaks the tag-triggered Docker build ("Build and Push Docker
|
|
# Image") at `npm ci`.
|
|
#
|
|
# Regenerate the lockfile with npm 10 only:
|
|
# npx -y npm@10.9.8 install --package-lock-only
|
|
# node scripts/verify-lockfile-npm10.mjs
|
|
#
|
|
# Keep install output quiet; never let audit/fund noise hide a lockfile error.
|
|
audit=false
|
|
fund=false
|