What Bones

Tooling

The tools that keep the monorepo consistent, formatted, and tested.

Workspaces

Yarn classic workspaces give one install and one lockfile. Dependencies used identically in several workspaces are declared once at the root. syncpack fails the lint if versions drift between workspaces.

Docker

Docker runs everything that isn't your code. yarn backend:dev starts docker-compose.dev.yml: Postgres, RustFS for S3, Mailpit for email, and the backend itself, built from backend/Dockerfile. The same Dockerfile has a production stage, for when the backend is deployed.

The backend tests start their own Postgres in Docker, and the Semgrep and ZAP scans run in Docker images, so none of them need a local install.

In development, tsx runs the backend's TypeScript directly and restarts it on change.

Lint and format

  • oxlint — a Rust linter, much faster than ESLint. One config at the root.
  • Prettier — formatting for code. Markdown is hand-formatted.

Tests

Dependencies

GitHub's Dependabot alerts flag vulnerable dependencies. The fix is always to bump the direct dependency. Bones never forces a version with Yarn resolutions. An alert that's blocked upstream is reported, not patched around.

Security scanning is on Semgrep and ZAP. CI is on GitHub Actions.

Used in