docs: correct five stale claims found in the weekly source audit (iou-architectuur#105) - #236
Merged
Merged
Conversation
Items 4, 8, 10, 12 and the linked-data-explorer half of 17 in sgort/iou-architectuur#105. Comments and prose only; no behaviour changes. Each was re-checked against acc at 05b3168 rather than taken from the issue. **4. scripts/check-deps.sh named the wrong marker script.** The comment said the snapshot is taken by scripts/write-deps-marker.sh; the root postinstall runs scripts/write-deps-marker.mjs, which is the file that exists. **8. .npmrc described the caveat the Node 24 move had already closed.** It said Node 22.23.2 bundles npm 10.9.8 and so ignores min-release-age. .nvmrc is 24.21.0, which bundles npm 11.19.0 and honours the setting. The comment now says that, and that check-deps.sh's warning matters only on a workstation running something older than .nvmrc. **10. docs/ci-posture-across-repos.md contradicted itself.** Line 128 said "Node 24 on both tiers"; line 213 said all four App Services across both repositories run NODE|22-lts. Azure says this repository's two run NODE|24-lts and ronl-business-api's two run NODE|22-lts, read with `az webapp config show --query linuxFxVersion` on 27 September 2026. **12. Both backend workflows carried the same contradiction.** azure-backend-acc.yml:113 and azure-backend-production.yml:79 said the Node major "matches the App Service runtime, NODE|22-lts", while lines 416 and 369 of the same files said the App Service was switched to NODE|24-lts. **17. SECURITY-PIPELINE.md undercounted the workflows.** Line 25 said "all eight workflows" and line 39 "all nine workflows". There are eleven, since promote-to-production.yml, dependency-audit.yml and sbom.yml were added. Verified before changing the zizmor line: the pinned version there, 1.29.0, still matches zizmor.yml, and the Supply-chain audit job is green on acc. check-supply-chain green (31 pinned references, register agrees), all eleven workflow files still parse, check-deps.sh still passes bash -n. The five prettier warnings on root markdown are pre-existing on clean acc and outside check-format's --workspaces scope.
4 tasks done
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Items 4, 8, 10, 12 and the linked-data-explorer half of 17 in sgort/iou-architectuur#105. Comments and prose only; no behaviour changes. Each was re-checked against
accat05b3168rather than taken from the issue.scripts/check-deps.sh:16named the snapshot scriptwrite-deps-marker.shpostinstallrunswrite-deps-marker.mjs, which is the file that exists.npmrcsaid Node 22.23.2 bundles npm 10.9.8 and so ignoresmin-release-age.nvmrcis 24.21.0, which bundles npm 11.19.0 and honours it — the comment described the gap #80 had already closeddocs/ci-posture-across-repos.md:213said all four App Services runNODE|22-ltsNODE|24-lts, RBA's twoNODE|22-ltsazure-backend-acc.yml:113andazure-backend-production.yml:79said the major matchesNODE|22-ltsNODE|24-ltsSECURITY-PIPELINE.mdsaid "all eight workflows" and "all nine workflows"promote-to-production.yml,dependency-audit.ymlandsbom.ymlwere addedOn 10 and 12 the runtime was read from Azure with
az webapp config show --query linuxFxVersionon 27 September 2026, not inferred.On 17, before changing the zizmor sentence I checked the measurement it carries is still current:
zizmor.ymlpinsversion: '1.29.0', which matches the prose, and the Supply-chain audit job is green onacc.Checks
check-supply-chaingreen (31 pinned references, register agrees) · all eleven workflow files parse ·check-deps.shpassesbash -n.The five
prettierwarnings on root markdown are pre-existing on cleanacc— same count with these changes stashed — and outsidecheck-format's--workspacesscope.Not in this PR
Items 5 and 6 are source fixes and follow in a second PR. Item 18's LDE half is a repository-settings decision.