Skip to content

Dependency upgrades

Modulecraft.15 · practice · docs · Pass 11 · 1 to 2 h
You builddocs/maintenance/dependency-upgrades.md
Testscourse/tests/craft.15 (named below, with why each exists)
Needsnone
Used byno code call site; this is an independent artifact
MilestoneMS-P11
  • Tie each claim to the exact platform evidence that Dependency upgrades produces.
  • State the owner, success condition, and recovery action before declaring the work complete.
  • Record unresolved assumptions so the next review can test them.
Terminal window
ol start craft.15
ol tests craft.15
ol check craft.15

Dependency changes can alter APIs, performance, and security properties at once. A deliberate upgrade isolates the cause and leaves a reversible path.

Read release notes and compatibility ranges before changing a major version. Upgrade one dependency family at a time, pin the resolved graph, and run behavior, race, security, and performance checks relevant to its use.

For a breaking Go or Rust library update, first make a minimal branch that builds against the new API, then run contract suites and compare benchmark distributions to the recorded baseline. Keep the prior lockfile available.

TestKINDChecksWhy it matters downstream
test_artifact_paths_are_declaredartifactConfirms the submitted paths and required evidence exist, so a plausible narrative cannot pass without the reviewable deliverable.
#PitfallSymptomCaught by
1The artifact names a decision without the evidence that supports itReviewers cannot verify the claim against the repository or system.test_artifact_paths_are_declared
2The failure or rollback case is omittedThe happy path passes while an operator has no safe response under failure.test_artifact_paths_are_declared
3The owner, threshold, or scope is implicitTwo reviewers can reach different release or risk decisions from the same evidence.test_artifact_paths_are_declared
DirectionModuleConnection
Backcraft.02Read this declared prerequisite before producing the artifact; use it to verify the relevant contract or evidence.
Backops.06Read this declared prerequisite before producing the artifact; use it to verify the relevant contract or evidence.
ResourceWhat to inspect
C4 model and architecture rules, section 2.3Compare the submitted views with the course system boundary and its process/file interfaces.