npm run db:migrate-upstream imports a BSK.db file into the bsk schema via
node:sqlite: re-keys all ids, maps shift 0/1 to morning/afternoon, converts
RTF template content to field labels, keeps pre-1970 birth dates, folds
suggestion/service-notes/ultrasound-doctor into visit notes, and warns on
every dropped or unmappable value. Pure transforms live in
scripts/upstream-transforms.mjs with a unit suite. Also grants service_role
the table privileges PostgREST needs for this and the existing seed scripts.
Replace pnpm-lock.yaml with package-lock.json. Four of the five overrides move
across unchanged, ranges intact.
postcss needed a different shape: npm rejects an override that disagrees with a
direct dependency (EOVERRIDE), and postcss was a devDependency at ^8.5.15 while
the override floored it at >=8.5.18. The devDependency now sits at the advisory
floor and the override references it as $postcss, so transitive copies follow
the same resolution the pnpm override produced.
brace-expansion is still deliberately not overridden. It resolves to 1.1.18 for
eslint's minimatch 3.x chain and 5.0.9 elsewhere; 1.1.18 is a patched 1.x, which
did not exist when the exception was written, so eslint runs clean and the
advisory is gone.
.npmrc held only pnpm-specific settings (verify-deps-before-run,
ignored-build-scripts-status-warn-only) and is removed. db:push, the Playwright
webServer command, and the secret-leak pathspec all referenced pnpm and would
have broken.
CI has been red on every push: the workflow runs `pnpm format:check`, which I
never included in local validation (I only gated typecheck/lint/build), so 54
files were committed unformatted.
- ran `pnpm format` — all changes are Prettier line-reflow, no logic touched
(verified: `git diff -w` flags exactly the same 54 files CI reported)
- added .gitattributes (`* text=auto eol=lf` + binary rules for fonts/images):
with core.autocrlf and no attributes file, `format:check` counted 141 files
locally vs 54 in CI, which is what let this slip through
All six CI gates now pass locally in workflow order: secret-leak, format:check,
test (97), lint, typecheck, build.
Defense-in-depth check that fails the build (and the local pre-push
workflow) if a server secret value is assigned to a NEXT_PUBLIC_*
variable — those get bundled into the browser by Next.js.
- scripts/check-no-secret-leak.mjs: git grep for the assignment shape,
excluding lockfiles and the script itself
- package.json: pnpm check:no-secret-leak
- .github/workflows/ci.yml: run the guard right after install, before
format/lint/typecheck/build
- docs/threat-model.md: close the last Unresolved item