Files
ai-for-dummies/.agents/context/verification.md
Marcos Paulo 48c31dc1b3 build: migrate from npm to pnpm
Ten git worktrees each carried their own 225 MB node_modules (1.1 GB across
five) and paid 11s per `npm ci`. pnpm hardlinks from a shared store: the same
five worktrees cost ~250 MB total, and a fresh install is 4s.

What changed beyond the mechanical rename:

- `overrides` moved to `pnpm-workspace.yaml`. pnpm 11 does not read the `pnpm`
  field in package.json *or* npm's top-level `overrides`, and it fails silently
  — the vite/defu/language-server pins would have quietly stopped applying.
- Build scripts are blocked by default in pnpm; esbuild and sharp are allowed
  explicitly via `allowBuilds` (renamed from `onlyBuiltDependencies` in 11).
- `packageManager` + `engines` pin the toolchain.
- gate.sh rejects a package-lock.json/yarn.lock/bun.lock outright, so an agent
  running `npm install` out of habit fails loudly instead of building a second,
  divergent dependency tree.
- CI bootstraps pnpm with `npm install --global pnpm@11.25.0` rather than
  corepack (unbundled as of Node 25) or pnpm/action-setup (this self-hosted
  act-runner has never run a job; fetching a third-party action is not
  something to discover on the first one).

Two pre-existing CI bugs fixed while in the file:

- the gate installed with `npm install --package-lock=false`, which discarded
  the lockfile the previous session had just fixed.
- the visual-regression step imported `playwright`, which is not a dependency,
  and `visual-regression.mjs` has no compare mode anyway — in CI it overwrote
  its own baselines and passed unconditionally. Removed with a comment; it
  comes back when it can diff.

The `publish` job is now manual (`workflow_dispatch`). During the migration
dist/ holds three HTML files against the live pages branch's ten, so publishing
on every push to main would take the site down to a stub. Restore at task 20.

HANDOVER.md's incident log still says npm where it describes what happened at
the time; that is history, not a missed rename.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 04:29:42 +00:00

3.0 KiB

Context: the verification contract

scripts/verify.mjs is 13 KB, 42 throw new Error sites, 16 checkpoints. It reads 26 source files and asserts that specific string tokens appear in them — data-phase="plan", renderTree, .change-lens, styles.css?v=20260904-vote-widget, and so on.

Why this matters more than it looks

These assertions are the only thing standing between this site and silent content loss during a large refactor. They are also all going to break, because they assert against files that will stop existing.

The failure mode to guard against: an agent runs pnpm run verify, sees red, and "fixes" it by deleting the assertion. The suite goes green and the site loses a section. Deleting an assertion is a change that requires review, the same as deleting a feature.

How the contract must evolve

Three kinds of assertion, three different fates:

Kind Example Fate
Content presence 'data-phase="plan"' in full-guide/index.html Re-point at built output (dist/) — the token should survive rendering. If it does not, the component dropped content.
Implementation detail 'const phases', 'renderTree' in app.js Obsolete. Replace with an assertion about behaviour or output, never delete outright.
Cache-busting version 'app.js?v=20260904-vote-widget' Obsolete — Astro hashes assets. Replace with "the built HTML references a hashed asset".

Rule: the assertion count must not fall. Every removed token is replaced by one that pins the same user-visible fact against the new architecture. The verification engineer owns this and is the only role allowed to reduce coverage, with a written reason per removal.

The stronger check to add

Token-matching is brittle. During the migration, add a rendered-output diff: snapshot the current site's DOM text content per route, then assert the Astro build produces the same text. That catches dropped paragraphs the way token matching cannot.

# before migrating a page, from the vanilla site:
node .agents/scripts/snapshot-route.mjs /models/ > .agents/snapshots/models.txt
# after: same script against dist/, diff must be empty (or reviewed)

See ../skills/verify-contract/SKILL.md.

Also in the suite

scripts/audit-ui.mjs asserts every page has a viewport meta and no external <script>/<link>. Keep it and extend it: it currently misses external URLs inside CSS (@font-face src, @import, url()), which is exactly how the broken Google Fonts request in styles.css:1 got in.