Changes touching this path
- the site loads clerk-js at the exact version the installed clerk-react was built with, not the floating major: both ClerkProviders asked the CDN for @clerk/clerk-js@5, which it answers with an uncached 307 to its newest release, so whatever Clerk published ran unreviewed on the page that holds the seed. vite.config.ts now defines __CLERK_JS_VERSION__ from tools/clerk-js-version.ts, which asks the @clerk/shared under @clerk/clerk-react for the clerk-js it was released with (5.127.1 today), and each ClerkProvider passes it as clerkJSVersion; the CDN serves that URL with no redirect and as immutable. no subresource integrity: the clerk-react loader takes no option for one. pinned in vitest: the version is exact, is the one the installed shared names, lands in the script URL clerk-react builds, every ClerkProvider under src passes it, and the build carries it. red under named mutations, each restored: the private gate without the prop (1 failed and 4 passed), the account page without it (1 and 4), the helper returning the major (3 and 2, and 2 and 3 with its check off), a typed 5.128.0 (1 and 4), shared resolved from the site (3 and 2), and the build without the define (1 failed and 7 passed). local trace, signed out, warm: the script comes from cache at 30 ms against 51 to 60 over the redirect, and Clerk.load still starts at about 137 ms either way, on the 100 ms poll in clerk-react. cargo test green, 4886 passed over 144 test result lines with 15 ignored, and the site gate green at 945 passed. CONTEXT.md and ADR 0096 say so. owes a site deploy (lzxtqwxq)
f80b7345 · dbf3dbe6… - a Lock drops the identity, publishes the lock and tells the other tabs before it awaits the wipe, and tells them again once the wipe settles, where it told them only after the wipe, so a wipe waiting behind another tab upgrade left them unlocked for as long; a tab older than the device database has its open refused with StaleBuild, whose sentence the unlock card shows before and on an unlock: the page must be reloaded from a current build, where a stale tab after a rolled-back deploy read the account tier as unreachable. the Tickets measures take a MEASURE const, the span from the keys to the index is named tickets.keys-to-index for what it spans where it was tickets.fold, and the address width is named once as ADDRESS_BYTES. the ClerkProvider census reads aliased and namespace imports and refuses a use that is not a tag, the workbench frame says Unlocking again once the header is in, refusal.tsx names what defines the set of sealing calls rather than two of them, CONTEXT.md no longer calls every private surface client-rendered, and loot-codec and CONTEXT.md say its batch feature compiles merlin into every build of it. red under named mutations, each restored: the broadcast only once the wipe settles (3 failed and 6 passed), the lock published only once it settles (1 and 8), no broadcast once it settles (2 and 7), the VersionError passed through (4 and 5), the span measured from the fold (1 and 20), the engine measure not left (1 and 20), the frame ignoring unlocking (1 and 9), an aliased provider without the prop (1 and 9), and the census without aliases (2 and 8). cargo test green, 4897 passed over 144 test result lines with 15 ignored, and the site gate green at 981 passed. ADR 0096 says so. owes a site deploy (qrsypwtv)
8caf1999 · dbf3dbe6…diff
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.