Tooling
The tools that keep the monorepo consistent, formatted, and tested.
Workspaces
Yarn classic workspaces give one install and one lockfile. Dependencies used identically in several workspaces are declared once at the root. syncpack fails the lint if versions drift between workspaces.
Docker
Docker runs everything that isn't your code. yarn backend:dev starts docker-compose.dev.yml: Postgres, RustFS for S3, Mailpit for email, and the backend itself, built from backend/Dockerfile. The same Dockerfile has a production stage, for when the backend is deployed.
The backend tests start their own Postgres in Docker, and the Semgrep and ZAP scans run in Docker images, so none of them need a local install.
In development, tsx runs the backend's TypeScript directly and restarts it on change.
Lint and format
- oxlint — a Rust linter, much faster than ESLint. One config at the root.
- Prettier — formatting for code. Markdown is hand-formatted.
Tests
- Vitest — the backend suite, against real Postgres from Testcontainers.
- Storybook — a story for every
shared-uicomponent and every web-app page, in every state. Data is mocked with MSW, through msw-trpc so each mock is typed against the real API. - Playwright — drives the Storybook play tests. See axe and Playwright.
Dependencies
GitHub's Dependabot alerts flag vulnerable dependencies. The fix is always to bump the direct dependency. Bones never forces a version with Yarn resolutions. An alert that's blocked upstream is reported, not patched around.
Security scanning is on Semgrep and ZAP. CI is on GitHub Actions.