Skip to content

Align agent skills with Meteor 3.6 RC and fix dependency audit - #26

Closed
italojs wants to merge 1 commit into
mainfrom
codex/meteor-3.6-rc.0-agent-skills
Closed

italojs wants to merge 1 commit into
mainfrom
codex/meteor-3.6-rc.0-agent-skills

Conversation

@italojs

@italojs italojs commented Oct 7, 2026

Copy link
Copy Markdown
Member

Summary

Implement the eleven confirmed findings from the Meteor 3.6-rc.0 catalog audit across ten existing skills:

  • Correct deployment/runtime selection for Node 26 in Meteor 3.6 while retaining earlier release branches and the separate Node 24+ installer host prerequisite.
  • Add backup, MongoDB 7 FCV preparation, and platform checks before updating a preserved local database to bundled MongoDB 8.
  • Document independently versioned Accounts cookie, passwordless, and custom users collection behavior, including validation, rate limits, Strict navigation, instance isolation, and profile write protection.
  • Preserve the existing TypeScript provider by default and document explicit native meteor types generation on Meteor 3.6.
  • Add optional server lifecycle instrumentation and conditional SWC native carrier cache diagnosis.
  • Document architecture-specific Rspack main/test entries, legacy runtime limits, and the prepared RC dependency pairing.
  • Explain $where/$near observer-driver eligibility and polling fallback separately from query validity.

Keep names, descriptions, classification, bundle membership, and Meteor ranges unchanged. Add four focused references and the smallest affected acceptance cases. Preserve the original audit as maintenance evidence.

Approved dependency correction

Local execution of the existing CI audit found seven alerts already present on main. The user separately approved correcting this development dependency chain in this PR:

  • Pin fast-uri@3 to 3.1.8 and brace-expansion@5 to 5.0.12.
  • Replace the js-yaml@3 -> argparse@1 -> sprintf-js chain with js-yaml 4.3.2 and argparse 2.
  • Route both frontmatter consumers through a shared explicit YAML loader because gray-matter's default engine still calls the removed v3 safeLoad API.

Keep pnpm audit --audit-level moderate active. No ignored advisories or CI gate changes. The parser upgrade preserves parsed metadata and Markdown bodies for all 118 catalog/maintainer Markdown files. The public validator regression case was added before the adapter; it reproduced the safeLoad incompatibility after the dependency update and passed after the adapter.

Evidence and release context

  • Catalog base: 09d39dcd5a80a81957df84a7c837702ef95d1e80, synchronized with origin/main before implementation.
  • Meteor source: 581ffaec659ba73b8633b9876dbf1861b8657013 on release-3.6, plus the approved RC documentation/version preparation overlays recorded in the audit.
  • Key documentation: installation, Accounts tutorial, passwordless, native types, instrumentation, and Rspack integration.
  • Independent source review corrected the Accounts base RC version, conditional SWC carrier support, passwordless options.extra, host Node prerequisite, and optional arch callback value before the final case runs.

This is pre-publication source alignment, not certification of an installed Meteor RC. Refresh evidence against the exact clean Meteor release commit before a later catalog tag.

Verification

All local checks passed:

  • pnpm install --frozen-lockfile
  • pnpm audit --audit-level moderate: no known vulnerabilities
  • pnpm run validate
  • pnpm run check-links
  • pnpm run catalog:check
  • pnpm test: 34 tests across 5 files
  • pnpm run build:zips: 16 archives; all 112 file names and bytes match source, with no internal maintenance files
  • git diff --check

Twenty-three final affected prompts passed in fresh isolated agent conversations. Criteria were withheld during each run and graded afterward; the evaluated runtime skill snapshot matches the final guidance. Superseded runs were rerun after corrections and are not counted. No transcripts or raw model output are committed.

Skill Passing cases
meteor-accounts 15, 16, 17, 18, 19, 20
meteor-cli-installation 20, 21, 22
meteor-debugging 31, 32
meteor-deployment 5, 17
meteor-modern-build-stack 31, 32, 33, 34
meteor-mongo-minimongo 10
meteor-react 25
meteor-security 12
migrate-to-meteor-3 23, 29
migrate-to-rspack 36

Before merge / later publication

  • An outside contributor runs affected high-risk cases against Claude Code or Cursor, as required by AGENTS.md. The isolated agent evaluations above do not satisfy that separate contributor gate.

Proposed independent catalog version after review: v1.1.0-beta.1, subject to maintainer confirmation. This PR does not bump plugin versions, create a tag, publish packages/catalog artifacts, or announce the Meteor release.

@italojs italojs closed this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant