update monorepo-tooling and audits specs to match verified repo state - #2255
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (6)
🚧 Files skipped from review as they are similar to previous changes (2)
📝 WalkthroughWalkthroughThe pull request updates pnpm migration documentation, monorepo tooling records, audit plans, and archive entries. It records completed work, remaining blockers, current ownership states, and planned audit tracking issues. ChangesTooling status and planning
Estimated code review effort: 2 (Simple) | ~15 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 5
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: fbf903cf-51ad-4e50-a380-d75a1099cd7b
📒 Files selected for processing (26)
docs/pnpm-migration-status.mdspecs/ARCHIVE.mdspecs/archive/monorepo-tooling/MT-12-isolated-linker.mdspecs/archive/monorepo-tooling/MT-13-pnpm-cache-audit.mdspecs/archive/monorepo-tooling/MT-21-circom-tester-pin.mdspecs/archive/monorepo-tooling/MT-29-ncu-version-sweep.mdspecs/archive/monorepo-tooling/MT-3-turbo-foundation.mdspecs/archive/monorepo-tooling/MT-4-root-script-migration.mdspecs/archive/monorepo-tooling/MT-6-pnpm-config-hardening.mdspecs/projects/sdk/INDEX.mdspecs/projects/sdk/workstreams/audits/SPEC.mdspecs/projects/sdk/workstreams/audits/plans/AUD-01-nfc-chip-reading-flow.mdspecs/projects/sdk/workstreams/audits/plans/AUD-02-key-material-keychain-lifecycle.mdspecs/projects/sdk/workstreams/audits/plans/AUD-03-startup-nav-routing.mdspecs/projects/sdk/workstreams/audits/plans/AUD-04-test-coverage-quality.mdspecs/projects/sdk/workstreams/audits/plans/AUD-05-bridge-protocol-surface.mdspecs/projects/sdk/workstreams/audits/plans/AUD-06-cruft-dead-code.mdspecs/projects/sdk/workstreams/audits/plans/AUD-07-config-ci-consolidation.mdspecs/projects/sdk/workstreams/audits/plans/AUD-08-analytics-observability.mdspecs/projects/sdk/workstreams/audits/plans/AUD-09-webview-app-surface.mdspecs/projects/sdk/workstreams/monorepo-tooling/SPEC.mdspecs/projects/sdk/workstreams/monorepo-tooling/plans/MT-1-blur-swap.mdspecs/projects/sdk/workstreams/monorepo-tooling/plans/MT-14-dedupe-audit.mdspecs/projects/sdk/workstreams/monorepo-tooling/plans/MT-22-circom-tester-migration.mdspecs/projects/sdk/workstreams/monorepo-tooling/plans/MT-8-yarn-residue-guardrail.mdspecs/projects/sdk/workstreams/monorepo-tooling/plans/MT-9-peer-strictness.md
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5f8994b1b5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Summary
docs/pnpm-migration-status.mdauthoritative for "is the yarn→pnpm migration done" (it is), and separates that from "is the hardening workstream closed" (it isn't).monorepo-tooling/SPEC.mdagainst the actual repo state — it misreported 6 tracks. Backlog collapses from 13 rows to 6 live ones; 7 settled plans are archived; two overdue decisions (MT-12, MT-24) are recorded instead of left open.auditsworkstream dormant and unowned, fills in the 9 Linear issue IDs its plans said wereTBD, and corrects 9 plan statuses that used a value the spec's own vocabulary doesn't allow.Why two workstreams in one PR: both are the same defect class (spec files that drift from the repo they describe) found in one verification pass, and the fix is identical in kind — no behavior, no shared files, reviewable as one read. Splitting would duplicate the rationale across two PRs of ~13 doc files each.
Changes
Docs — pnpm migration status
packageManagerwaspnpm@11.1.1; root ispnpm@11.12.0. It now points readers at rootpackage.jsonrather than naming a copy that drifts, and records the11.1.1 → 11.5.3 → 11.7.0 → 11.12.0history.pnpm formatbreaking on Yarnportal:(uselink:), prettierEACCESfrom/Volumesdropping the exec bit, stale yarn-era workspacenode_modulesshadowing root versions, and the.watchmanconfigguard (fix Reanimated native integration and Metro/watchman build config #2178) that must not ignorenode_modules/dist.pnpm-workspace.yamland silently ignores the rootpnpmfield.Specs — monorepo-tooling
Verified each track against the repo rather than trusting the table:
Draftin plan filesallowBuildsaudited per-entry, 6patchedDependencies, pin enforcedpnpm-workspace.yamlnodeLinker: hoistedis load-bearing; RN autolinking requires a flatnode_modulesreact-native-blur-effectdeclarations plus the Jest mock remain, and the nested-RN symptom is neutralized by the1.1.3override rather than by the removalpnpm-workspace.yamland.npmrc).github/CI_FORCE_RUNbecame general infra (documents four reuse cases, listed in 10+ workflows'paths:/check_changesallowlists, enforced bypnpm lint:ci-sentinel).kmp-ci.ymlruns:shared:jvmTest,:shared:iosSimulatorArm64Test, and:composeApp:testDebugUnitTestdirectly.Specs — audits
Owner: UNASSIGNED,Status: Dormant, plus a Current State block. The protocol and all nine plans landed in one PR (add codebase-audits workstream spec and nine audit plans #2167, 2026-06-11) and nothing has run since — no commits in ~2 months, noAUD-NNfindings doc indocs/reviews/.Linear: TBD — create the tracking issue, but the issues exist. Filled in SELF-3180…3188 (all unassigned; 8 Backlog, AUD-02Todo).Status: Draft, which is not in the spec's allowed vocabulary (Ready | Planned | In Progress | In Review | Blocked | Done). Corrected toPlanned — awaiting workstream owner, preserving each pre-draft caveat.path:linecitations date from June 2026 and the RN/Expo and pnpm work has moved code since.Archive
specs/archive/monorepo-tooling/(tracked as renames), each stamped with its outcome.specs/ARCHIVE.mdfollowing the existing convention, each carrying the durable decision rather than just "done".specs/projects/sdk/INDEX.mdfocus line updated for the narrowed scope.Note for the circuits owner
Documented, not fixed — circuits is separately owned. Written up at the top of the MT-22 plan:
circuits/package.json:67pinscircom_testertogithub:remicolin/circom_tester#main— a floating branch. The workspace override pins sha81e963ceand wins today, so installs are deterministic, but the floating ref contradicts the repo'sminimumReleaseAgeposture and goes live the moment that override is dropped — including by MT-22's own step that removes it.package.jsonfor the override; it actually lives inpnpm-workspace.yaml, which would have sent the implementer to the wrong file.Linear Issues
Test Plan
Docs-only change: no runtime, build, or dependency surface touched. Lockfile unchanged.
pnpm lint:headerspasses (duplicate + license header checks)pnpm lint:ci-sentinelpasses — sentinel coverage intact after the SPEC editsprettier --writeclean across all changed markdown.mdlinks in changed files resolvespecs/pnpm lint && pnpm typespass in CI🤖 Generated with Claude Code
Summary by CodeRabbit