diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 4191b0e5b..1bf6c0b2f 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,11 @@ updates: directory: / schedule: interval: weekly + ignore: + # NestJS 12 es ESM-only y se migra en bloque (todo @nestjs/* + jest/ts config). + # Un major por paquete rompe los 5 workspaces (ver PRs #720 y #721, cerrados). + - dependency-name: "@nestjs/*" + update-types: ["version-update:semver-major"] - package-ecosystem: github-actions directory: / diff --git a/package-lock.json b/package-lock.json index fc9403fab..e57a84f7e 100644 --- a/package-lock.json +++ b/package-lock.json @@ -8164,11 +8164,6 @@ "@types/superagent": "^8.1.0" } }, - "node_modules/@types/uuid": { - "version": "10.0.0", - "dev": true, - "license": "MIT" - }, "node_modules/@types/validator": { "version": "13.15.10", "license": "MIT" @@ -15743,17 +15738,6 @@ "version": "1.0.2", "license": "MIT" }, - "node_modules/uuid": { - "version": "11.1.1", - "funding": [ - "https://github.com/sponsors/broofa", - "https://github.com/sponsors/ctavan" - ], - "license": "MIT", - "bin": { - "uuid": "dist/esm/bin/uuid" - } - }, "node_modules/v8-compile-cache-lib": { "version": "3.0.1", "dev": true, @@ -16920,7 +16904,7 @@ "@open-policy-agent/opa-wasm": "1.10.0", "@opentelemetry/api": "1.9.1", "@opentelemetry/auto-instrumentations-node": "0.80.0", - "@opentelemetry/exporter-trace-otlp-http": "^0.222.0", + "@opentelemetry/exporter-trace-otlp-http": "0.222.0", "@opentelemetry/sdk-node": "0.221.0", "cache-manager": "7.2.9", "class-transformer": "0.5.1", @@ -16933,7 +16917,6 @@ "prom-client": "15.1.3", "reflect-metadata": "0.2.2", "rxjs": "7.8.2", - "uuid": "11.1.1", "yaml": "2.9.0" }, "bin": { @@ -16947,7 +16930,6 @@ "@types/fs-extra": "11.0.4", "@types/jest": "30.0.0", "@types/node": "26.2.0", - "@types/uuid": "10.0.0", "@typescript-eslint/parser": "^8.64.0", "eslint": "*", "eslint-plugin-boundaries": "^7.2.0", @@ -17354,7 +17336,7 @@ "@nestjs/platform-express": "11.1.28", "@open-policy-agent/opa-wasm": "1.10.0", "@opentelemetry/api": "1.9.1", - "@opentelemetry/exporter-trace-otlp-http": "^0.222.0", + "@opentelemetry/exporter-trace-otlp-http": "0.222.0", "@opentelemetry/sdk-node": "0.221.0", "ajv": "8.20.0", "ajv-formats": "3.0.1", diff --git a/reference/core/control-center/maturity-reports/maturity-evidence.json b/reference/core/control-center/maturity-reports/maturity-evidence.json index 3b9e25b54..3ee14381c 100644 --- a/reference/core/control-center/maturity-reports/maturity-evidence.json +++ b/reference/core/control-center/maturity-reports/maturity-evidence.json @@ -5,34 +5,34 @@ { "id": "cli-baseline", "status": "PASS", - "observedAt": "2026-08-18", - "commit": "398def5b", - "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/32193798343", - "summary": "Re-observed 2026-08-18 on develop (398def5b) and GREEN. Run 32193798343 shows all THIRTEEN jobs of the CLI CI pipeline succeeding, CI Gate included: Lint and Type Check, Package Integrity, Unit Tests, E2E Tests, Architecture Validation, Evolith Core Validation, Security Audit, Secret Detection (gitleaks), Trivy Container Scan, CodeQL SAST, DAST OWASP ZAP, Winston Agentic Review and CI Gate. WHY THIS RE-OBSERVATION HAPPENED AT ALL, stated plainly: the previous entry was 30 days old and its sibling `documentation` had just crossed the 30-day window, failing `09-reconcile-maturity.mjs` on a promotion whose content had nothing to do with it. The window is the point -- evidence that ages out is supposed to be re-taken, not extended -- so this is a fresh observation of the same claim, not a date bump." + "observedAt": "2026-09-19", + "commit": "99b53259", + "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/35435224907", + "summary": "Re-observed 2026-09-19 on main (99b53259, the merge of #719) and GREEN. Run 35435224907 of the CLI CI pipeline shows all THIRTEEN jobs succeeding, CI Gate included: Lint and Type Check, Package Integrity, Unit Tests, E2E Tests, Architecture Validation, Evolith Core Validation, Security Audit, Secret Detection (gitleaks), Trivy Container Scan, CodeQL SAST, DAST OWASP ZAP, Winston Agentic Review and CI Gate. Why now: the four entries were taken together on 2026-08-18 and all four crossed the 0..30 day window on 2026-09-18, turning `Validate documentation` red on two Dependabot PRs whose content had nothing to do with it. Same rule as last time: aged-out evidence is re-taken against a fresh green run, not date-bumped." }, { "id": "coverage", "status": "PASS", - "observedAt": "2026-08-18", - "commit": "398def5b", - "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/32193798343", - "summary": "Re-observed 2026-08-18 on develop (398def5b) and GREEN. The Unit Tests job of run 32193798343 succeeds with 106 suites and 1486 tests, 0 failures, and the blocking coverage gate clears: Branches 75.69% (2376/3139) against the unchanged 75% global threshold. Both the suite count and the branch total have grown since the previous observation (85 suites / 1250 tests, 2023/2678 branches), so the margin over the threshold is being held while the corpus grows rather than by shrinking what is measured." + "observedAt": "2026-09-19", + "commit": "99b53259", + "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/35435224907", + "summary": "Re-observed 2026-09-19 on main (99b53259) and GREEN. The Unit Tests job of run 35435224907 succeeds with 107 suites and 1492 tests, 0 failures, and both coverage gates clear: the jest global thresholds (statements 80 / lines 80 / functions 75 / branches 75) with Statements 87.22% (5450/6248), Lines 87.54% (5116/5844), Functions 84.79% (853/1006) and Branches 75.73% (2382/3145), plus the workflow statement gate at 80%. Suite count, test count and branch total all grew since the previous observation (106 suites / 1486 tests, 2376/3139 branches), so the margin over the branch threshold is still being held while the corpus grows, not by shrinking what is measured." }, { "id": "documentation", "status": "PASS", - "observedAt": "2026-08-18", - "commit": "398def5b", - "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/32193798361", - "summary": "Re-observed 2026-08-18 on develop (398def5b) and GREEN. Run 32193798361 of Documentation Validation has both of its jobs succeeding -- 'Validate documentation' and 'Validate semantic tracking (guard)' -- so the reconciler, the bilingual parity suite and the gap-board tracking guard all pass on the same tree. THIS ENTRY IS THE ONE THAT AGED OUT: at 31 days it tripped the 0..30 day window and turned `Validate documentation` red on a promotion PR, which is the check working as designed. Its three siblings were at exactly 30 days and would have followed within a day, so all four are re-taken together against the same commit." + "observedAt": "2026-09-16", + "commit": "3d0662c7", + "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/35125943994", + "summary": "Observed 2026-09-16 on 3d0662c7 (the head of #719, whose tree became main as 99b53259 with no other change) and GREEN. Run 35125943994 of Documentation Validation has both jobs succeeding -- `Validate documentation` and `Validate semantic tracking (guard)` -- so the reconciler, bilingual parity, the bilingual sync guard, the gap-board tracking guard and the derived-artifact order guard all pass on the same tree. This entry cites a run three days older than its siblings ON PURPOSE: once the window closes, every later run of this workflow is red at the `Reconcile maturity evidence` step because of the window itself (see run 35435224859 on 99b53259: the evidence and ISO rules pass, then the reconciler rejects the four aged entries), so the last green run BEFORE the window closed is the only honest observation of this claim available until this very refresh lands." }, { "id": "release", "status": "PASS", - "observedAt": "2026-08-18", - "commit": "398def5b", - "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/32200256288", - "summary": "Re-observed 2026-08-18 on 398def5b and GREEN THROUGH THE BINARY JOBS FOR THE FIRST TIME. Run 32200256288 of the Evolith SDK CLI Release Pipeline succeeds across release-gate, build-and-test, Evolith Core Validation, package-binaries on all three platforms, smoke-test on all three platforms and smoke-test-functional. That last group is what makes this observation different from every previous one: until GT-707 landed, every packaged binary died on `--help` with ERR_REQUIRE_ESM, so smoke-test had never passed and `upload-assets` -- which needs it -- had never run. publish-npm, upload-assets and failure-notification are `skipped` because this run is not a tag." + "observedAt": "2026-09-19", + "commit": "99b53259", + "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/35435224976", + "summary": "Re-observed 2026-09-19 on main (99b53259) and GREEN through the binary jobs. Run 35435224976 of the Evolith SDK CLI Release Pipeline succeeds across release-gate, build-and-test, Evolith Core Validation, package-binaries on all three platforms (linux-x64, macos-x64, win-x64), smoke-test on all three platforms and smoke-test-functional. publish-npm, upload-assets and failure-notification are `skipped` because this run is a push to main, not a `cli-v*` tag. Second consecutive observation with the packaged binaries passing `--help` on every platform, which until GT-707 had never happened." } ] } diff --git a/reference/core/control-center/maturity-reports/maturity-reconciliation.json b/reference/core/control-center/maturity-reports/maturity-reconciliation.json index 1bdc8ede0..74b712b86 100644 --- a/reference/core/control-center/maturity-reports/maturity-reconciliation.json +++ b/reference/core/control-center/maturity-reports/maturity-reconciliation.json @@ -20,34 +20,34 @@ { "id": "cli-baseline", "status": "PASS", - "observedAt": "2026-08-18", - "commit": "398def5b", - "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/32193798343", - "summary": "Re-observed 2026-08-18 on develop (398def5b) and GREEN. Run 32193798343 shows all THIRTEEN jobs of the CLI CI pipeline succeeding, CI Gate included: Lint and Type Check, Package Integrity, Unit Tests, E2E Tests, Architecture Validation, Evolith Core Validation, Security Audit, Secret Detection (gitleaks), Trivy Container Scan, CodeQL SAST, DAST OWASP ZAP, Winston Agentic Review and CI Gate. WHY THIS RE-OBSERVATION HAPPENED AT ALL, stated plainly: the previous entry was 30 days old and its sibling `documentation` had just crossed the 30-day window, failing `09-reconcile-maturity.mjs` on a promotion whose content had nothing to do with it. The window is the point -- evidence that ages out is supposed to be re-taken, not extended -- so this is a fresh observation of the same claim, not a date bump." + "observedAt": "2026-09-19", + "commit": "99b53259", + "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/35435224907", + "summary": "Re-observed 2026-09-19 on main (99b53259, the merge of #719) and GREEN. Run 35435224907 of the CLI CI pipeline shows all THIRTEEN jobs succeeding, CI Gate included: Lint and Type Check, Package Integrity, Unit Tests, E2E Tests, Architecture Validation, Evolith Core Validation, Security Audit, Secret Detection (gitleaks), Trivy Container Scan, CodeQL SAST, DAST OWASP ZAP, Winston Agentic Review and CI Gate. Why now: the four entries were taken together on 2026-08-18 and all four crossed the 0..30 day window on 2026-09-18, turning `Validate documentation` red on two Dependabot PRs whose content had nothing to do with it. Same rule as last time: aged-out evidence is re-taken against a fresh green run, not date-bumped." }, { "id": "coverage", "status": "PASS", - "observedAt": "2026-08-18", - "commit": "398def5b", - "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/32193798343", - "summary": "Re-observed 2026-08-18 on develop (398def5b) and GREEN. The Unit Tests job of run 32193798343 succeeds with 106 suites and 1486 tests, 0 failures, and the blocking coverage gate clears: Branches 75.69% (2376/3139) against the unchanged 75% global threshold. Both the suite count and the branch total have grown since the previous observation (85 suites / 1250 tests, 2023/2678 branches), so the margin over the threshold is being held while the corpus grows rather than by shrinking what is measured." + "observedAt": "2026-09-19", + "commit": "99b53259", + "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/35435224907", + "summary": "Re-observed 2026-09-19 on main (99b53259) and GREEN. The Unit Tests job of run 35435224907 succeeds with 107 suites and 1492 tests, 0 failures, and both coverage gates clear: the jest global thresholds (statements 80 / lines 80 / functions 75 / branches 75) with Statements 87.22% (5450/6248), Lines 87.54% (5116/5844), Functions 84.79% (853/1006) and Branches 75.73% (2382/3145), plus the workflow statement gate at 80%. Suite count, test count and branch total all grew since the previous observation (106 suites / 1486 tests, 2376/3139 branches), so the margin over the branch threshold is still being held while the corpus grows, not by shrinking what is measured." }, { "id": "documentation", "status": "PASS", - "observedAt": "2026-08-18", - "commit": "398def5b", - "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/32193798361", - "summary": "Re-observed 2026-08-18 on develop (398def5b) and GREEN. Run 32193798361 of Documentation Validation has both of its jobs succeeding -- 'Validate documentation' and 'Validate semantic tracking (guard)' -- so the reconciler, the bilingual parity suite and the gap-board tracking guard all pass on the same tree. THIS ENTRY IS THE ONE THAT AGED OUT: at 31 days it tripped the 0..30 day window and turned `Validate documentation` red on a promotion PR, which is the check working as designed. Its three siblings were at exactly 30 days and would have followed within a day, so all four are re-taken together against the same commit." + "observedAt": "2026-09-16", + "commit": "3d0662c7", + "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/35125943994", + "summary": "Observed 2026-09-16 on 3d0662c7 (the head of #719, whose tree became main as 99b53259 with no other change) and GREEN. Run 35125943994 of Documentation Validation has both jobs succeeding -- `Validate documentation` and `Validate semantic tracking (guard)` -- so the reconciler, bilingual parity, the bilingual sync guard, the gap-board tracking guard and the derived-artifact order guard all pass on the same tree. This entry cites a run three days older than its siblings ON PURPOSE: once the window closes, every later run of this workflow is red at the `Reconcile maturity evidence` step because of the window itself (see run 35435224859 on 99b53259: the evidence and ISO rules pass, then the reconciler rejects the four aged entries), so the last green run BEFORE the window closed is the only honest observation of this claim available until this very refresh lands." }, { "id": "release", "status": "PASS", - "observedAt": "2026-08-18", - "commit": "398def5b", - "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/32200256288", - "summary": "Re-observed 2026-08-18 on 398def5b and GREEN THROUGH THE BINARY JOBS FOR THE FIRST TIME. Run 32200256288 of the Evolith SDK CLI Release Pipeline succeeds across release-gate, build-and-test, Evolith Core Validation, package-binaries on all three platforms, smoke-test on all three platforms and smoke-test-functional. That last group is what makes this observation different from every previous one: until GT-707 landed, every packaged binary died on `--help` with ERR_REQUIRE_ESM, so smoke-test had never passed and `upload-assets` -- which needs it -- had never run. publish-npm, upload-assets and failure-notification are `skipped` because this run is not a tag." + "observedAt": "2026-09-19", + "commit": "99b53259", + "source": "https://github.com/beyondnetcode/evolith_arch32/actions/runs/35435224976", + "summary": "Re-observed 2026-09-19 on main (99b53259) and GREEN through the binary jobs. Run 35435224976 of the Evolith SDK CLI Release Pipeline succeeds across release-gate, build-and-test, Evolith Core Validation, package-binaries on all three platforms (linux-x64, macos-x64, win-x64), smoke-test on all three platforms and smoke-test-functional. publish-npm, upload-assets and failure-notification are `skipped` because this run is a push to main, not a `cli-v*` tag. Second consecutive observation with the packaged binaries passing `--help` on every platform, which until GT-707 had never happened." } ], "externalProducts": [ diff --git a/src/packages/mcp-server/package.json b/src/packages/mcp-server/package.json index e5db977f1..3a504987a 100644 --- a/src/packages/mcp-server/package.json +++ b/src/packages/mcp-server/package.json @@ -68,7 +68,6 @@ "prom-client": "15.1.3", "reflect-metadata": "0.2.2", "rxjs": "7.8.2", - "uuid": "11.1.1", "yaml": "2.9.0" }, "devDependencies": { @@ -79,7 +78,6 @@ "@types/fs-extra": "11.0.4", "@types/jest": "30.0.0", "@types/node": "26.2.0", - "@types/uuid": "10.0.0", "@typescript-eslint/parser": "^8.64.0", "eslint": "*", "eslint-plugin-boundaries": "^7.2.0",