From 24cce6a1a330e11ee017a04eb1d92753ae6a104c Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sun, 5 Jul 2026 15:00:21 +0200 Subject: [PATCH] =?UTF-8?q?feat(install):=20Node=20baseline=2022=20->=2024?= =?UTF-8?q?=20LTS=20=E2=80=94=20resolves=20impeccable's=20hard=20dependenc?= =?UTF-8?q?y?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fresh installs and too-old hosts now get Node 24 (NodeSource setup_24.x / brew node@24). GSD v2 (>=22) still satisfied. Next 'make plugin' on a Node-22 host upgrades in place and unlocks impeccable Step 8d. --- CHANGELOG.md | 2 +- install-plugins.sh | 16 ++++++++-------- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 1598990..26693e5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,7 +7,7 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). ## [Unreleased] ### Added -- **impeccable** (pbakaus, Apache-2.0) wired into the toolchain as the design counterpart of semgrep: the `/impeccable` skill (23 verbs under one command: audit, polish, bolder, quieter…) plus the 45-rule deterministic anti-pattern detector (`npx impeccable detect`, exit 0/2, `--json`). Complementary to `frontend-design` (kept — aesthetic direction at build time); impeccable adds the deterministic audit floor and per-project design context (`/impeccable init`). CLI pinned in `plugins.lock.json` (3.2.0 — a silent rules update would change audit output on unchanged code); dist is machine-owned under `skills-external/impeccable/` (gitignored, ctx7 pattern), staged-installed by `install-plugins.sh` Step 8d, refreshed pin-honored by `update-all.sh`, symlinked by `link.sh`, listed in the design/web/web-full/full profiles and the design-work routing. Requires Node ≥ 24 — the install/update steps skip gracefully below that (this host runs 22: bump Node to activate). Not in the design gate's GATE-BLOCK list yet — promotion deliberate, after first dogfood. +- **impeccable** (pbakaus, Apache-2.0) wired into the toolchain as the design counterpart of semgrep: the `/impeccable` skill (23 verbs under one command: audit, polish, bolder, quieter…) plus the 45-rule deterministic anti-pattern detector (`npx impeccable detect`, exit 0/2, `--json`). Complementary to `frontend-design` (kept — aesthetic direction at build time); impeccable adds the deterministic audit floor and per-project design context (`/impeccable init`). CLI pinned in `plugins.lock.json` (3.2.0 — a silent rules update would change audit output on unchanged code); dist is machine-owned under `skills-external/impeccable/` (gitignored, ctx7 pattern), staged-installed by `install-plugins.sh` Step 8d, refreshed pin-honored by `update-all.sh`, symlinked by `link.sh`, listed in the design/web/web-full/full profiles and the design-work routing. Requires Node ≥ 24: the install baseline is bumped from 22 to 24 LTS (NodeSource `setup_24.x` / brew `node@24`), so `make plugin` upgrades a too-old host in place; the impeccable steps still skip gracefully if Node stays below 24. Not in the design gate's GATE-BLOCK list yet — promotion deliberate, after first dogfood. - `/tour` skill — grouped all-axes sweep over one or several projects: security (pinned-semgrep `security-auditor` agent + `/cso` posture when gstack is ON) → cleanup → re-verify → reconcile (report-only, never edits the target TODO/registries) → doc sync, looping until a full pass applies zero fixes (bounded at 3 iterations). Fixes land on a `chore/tour-` branch the skill never merges; each project gets an append-only `.claude/audits/TOUR.md` report with BREAKING tags on contract-changing security fixes. Built TDD (superpowers:writing-skills): baseline run showed silent TODO rewrites, autonomous registry writes, grep-as-security-pass, no persistent report, scope creep and an unbounded loop — each countered and verified on a seeded fixture. ### Fixed diff --git a/install-plugins.sh b/install-plugins.sh index 44ca03a..7c259ba 100644 --- a/install-plugins.sh +++ b/install-plugins.sh @@ -125,29 +125,29 @@ else ok "git installed" fi -# --- Node.js (>=18) --- +# --- Node.js (>=24 — impeccable requires it; GSD v2 needs >=22) --- NODE_OK=false if command -v node &>/dev/null; then NODE_VER=$(node --version | sed 's/v//' | cut -d. -f1) - if [ "$NODE_VER" -ge 22 ]; then + if [ "$NODE_VER" -ge 24 ]; then ok "Node.js $(node --version)"; NODE_OK=true else - warn "Node.js $(node --version) is too old (need >=22 — GSD v2 requires it)" + warn "Node.js $(node --version) is too old (need >=24 — impeccable requires it)" fi fi if [ "$NODE_OK" = false ]; then - info "Installing Node.js 22 LTS..." + info "Installing Node.js 24 LTS..." case $OS in macos) - brew install node@22 - export PATH="/opt/homebrew/opt/node@22/bin:$PATH" + brew install node@24 + export PATH="/opt/homebrew/opt/node@24/bin:$PATH" ;; linux-apt) - curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash - + curl -fsSL https://deb.nodesource.com/setup_24.x | sudo -E bash - sudo apt-get install -y nodejs ;; linux-dnf) - curl -fsSL https://rpm.nodesource.com/setup_22.x | sudo bash - + curl -fsSL https://rpm.nodesource.com/setup_24.x | sudo bash - sudo dnf install -y nodejs ;; linux-pacman)