From 83be11d98081e40a720c1b53dc2f8ca0ac1f2ad1 Mon Sep 17 00:00:00 2001 From: Ned Twigg Date: Sun, 4 Oct 2026 16:03:38 -0700 Subject: [PATCH 1/2] Docs: describe npm releases instead of vendored tarballs SECURITY.md said pgstencil is unpublished and fixes reach consumers by re-vendoring; PACKAGES.md said npm publishing and release automation were deferred. Both shipped with 0.2.0/0.3.0. Co-Authored-By: Claude Opus 5.5 --- PACKAGES.md | 2 +- SECURITY.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/PACKAGES.md b/PACKAGES.md index 7ad4d9a..83c06ae 100644 --- a/PACKAGES.md +++ b/PACKAGES.md @@ -50,7 +50,7 @@ Auth reserves the existing `public.users`, `login_flows`, `login_challenges`, `s `Auth` accepts a `renderEmail` function for branding. `createAuthHttp` from `@pgstencil/auth/http` supplies JSON routes under `/api/auth/`, native OAuth callbacks under `/oauth/`, and a non-consuming email-link redirect under `/login/link`. The SPA confirms the link with an authenticated browser-flow POST. Session tokens stay in HttpOnly cookies; the JSON state contains the CSRF token, public session fields, and configured provider names. See the adopter's backend spec for a complete React integration. -The project is MIT licensed and hosted at [diffplug/pgstencil](https://github.com/diffplug/pgstencil). Public npm namespace, registry credentials, trusted publishing and release automation remain deferred. These local archives are ordinary npm package artifacts, so that later switch does not require submodules or a source-loader integration. +The project is MIT licensed and hosted at [diffplug/pgstencil](https://github.com/diffplug/pgstencil). Releases reach npm through trusted publishing, as described in [Releasing](#releasing). The local archives remain for trying unreleased changes; they are ordinary npm package artifacts, so moving between them and a released version needs no submodules or source-loader integration. ## Better Auth integration diff --git a/SECURITY.md b/SECURITY.md index 66bf722..ce0199d 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -88,7 +88,7 @@ Pinned by `pnpm test:scripts`, which runs the shipped reporting and redaction sh ## Reporting a vulnerability -Report privately through GitHub's [advisory form for diffplug/pgstencil](https://github.com/diffplug/pgstencil/security/advisories/new); never a public issue. pgstencil is pre-1.0 and unpublished to npm, so a fix lands on `main` and reaches a consumer through a re-vendored tarball; there is no backport branch. +Report privately through GitHub's [advisory form for diffplug/pgstencil](https://github.com/diffplug/pgstencil/security/advisories/new); never a public issue. pgstencil is pre-1.0 and releases to npm only from `main`, so a fix lands on `main` and reaches a consumer in the next release ([PACKAGES.md](PACKAGES.md#releasing)); there is no backport branch. ## What is not defended From 1889ec012c0b0441bbece40dcbfeaeedd01c429b Mon Sep 17 00:00:00 2001 From: Ned Twigg Date: Sun, 4 Oct 2026 16:04:04 -0700 Subject: [PATCH 2/2] Docs: a release, not re-vendoring, carries a raised dependency floor Co-Authored-By: Claude Opus 5.5 --- PACKAGES.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/PACKAGES.md b/PACKAGES.md index 83c06ae..30575e1 100644 --- a/PACKAGES.md +++ b/PACKAGES.md @@ -14,7 +14,7 @@ Every archive carries `package/dist/provenance.json`, holding the 40-character ` Applications declare pgstencil's peer dependencies themselves: `kysely` for every package, `hono` for `@pgstencil/auth`, and `stripe` for `@pgstencil/stripe`. Auth and billing also peer on the `pgstencil` released with them. A library is a peer when the application and pgstencil must share one copy. Either objects cross the boundary, or the library holds module-level state. Kysely and Hono classes have private fields, so two copies are incompatible types. `pgstencil/diagnostics` keeps its request scope in `AsyncLocalStorage`. The application's Renovate updates each shared library once, and pgstencil uses that copy. pnpm reports a release outside a peer range; pgstencil must widen the range first. -Every other dependency is private: pgstencil owns its version and applications do not import it. Better Auth is deliberately private. pgstencil imports its internal subpaths and tests login and linking rules against specific releases, so it is pinned to the exact release CI tested. Even a patch can change internals pgstencil reads (1.7.7 renamed its OAuth state rows), so each Better Auth upgrade reaches applications only through a pgstencil release. A new login provider or Better Auth plugin belongs in `@pgstencil/auth`, not in an application. Private ranges start at the version pgstencil's CI tested. [`.github/renovate.json`](.github/renovate.json) raises that floor, and re-vendoring carries it into each application. +Every other dependency is private: pgstencil owns its version and applications do not import it. Better Auth is deliberately private. pgstencil imports its internal subpaths and tests login and linking rules against specific releases, so it is pinned to the exact release CI tested. Even a patch can change internals pgstencil reads (1.7.7 renamed its OAuth state rows), so each Better Auth upgrade reaches applications only through a pgstencil release. A new login provider or Better Auth plugin belongs in `@pgstencil/auth`, not in an application. Private ranges start at the version pgstencil's CI tested. [`.github/renovate.json`](.github/renovate.json) raises that floor, and the next release carries it into each application. ## Releasing