| |
|---|
| Module | craft.15 · practice · docs · Pass 11 · 1 to 2 h |
| You build | docs/maintenance/dependency-upgrades.md |
| Tests | course/tests/craft.15 (named below, with why each exists) |
| Needs | none |
| Used by | no code call site; this is an independent artifact |
| Milestone | MS-P11 |
- Tie each claim to the exact platform evidence that
Dependency upgrades produces.
- State the owner, success condition, and recovery action before declaring the work complete.
- Record unresolved assumptions so the next review can test them.
Dependency changes can alter APIs, performance, and security properties at once. A deliberate upgrade isolates the cause and leaves a reversible path.
Read release notes and compatibility ranges before changing a major version. Upgrade one dependency family at a time, pin the resolved graph, and run behavior, race, security, and performance checks relevant to its use.
For a breaking Go or Rust library update, first make a minimal branch that builds against the new API, then run contract suites and compare benchmark distributions to the recorded baseline. Keep the prior lockfile available.
| Test | KIND | Checks | Why it matters downstream |
|---|
test_artifact_paths_are_declared | artifact | Confirms the submitted paths and required evidence exist, so a plausible narrative cannot pass without the reviewable deliverable. | |
| # | Pitfall | Symptom | Caught by |
|---|
| 1 | The artifact names a decision without the evidence that supports it | Reviewers cannot verify the claim against the repository or system. | test_artifact_paths_are_declared |
| 2 | The failure or rollback case is omitted | The happy path passes while an operator has no safe response under failure. | test_artifact_paths_are_declared |
| 3 | The owner, threshold, or scope is implicit | Two reviewers can reach different release or risk decisions from the same evidence. | test_artifact_paths_are_declared |
| Direction | Module | Connection |
|---|
| Back | craft.02 | Read this declared prerequisite before producing the artifact; use it to verify the relevant contract or evidence. |
| Back | ops.06 | Read this declared prerequisite before producing the artifact; use it to verify the relevant contract or evidence. |
| Resource | What to inspect |
|---|
| C4 model and architecture rules, section 2.3 | Compare the submitted views with the course system boundary and its process/file interfaces. |