geonosis
v3.1.0
Published
One manifest line pins the whole toolchain: the geonosis CLI and every gate it runs, on one version.
Maintainers
Readme
geonosis
One manifest line pins the toolchain.
pnpm add -D geonosis # or: bun add -d geonosis
npx geonosis --helpThat line installs @geonosis/cli and every gate it runs — the plugin, the doctor, the ratchet,
verify, verify-arch, lint-parity, the ledger, release, review, testbed, observability, walk and
visual-diff — all on the same version, because the whole group publishes as one fixed set. The
commands come from the packages it pins; this package ships no bin of its own.
geonosis update --to <version> bumps every pin in every workspace afterwards, in one command.
What it does not install
Everything that only some repos need stays out, so nobody's lockfile grows for a tool they do not run (#73: one pinned Postgres linter with platform binaries added 395 lines to a consumer's lockfile). Measured while this package was written: bun 1.4.0 installs a non-optional peer without being asked; pnpm 11.8.0 does not — so on a bun consumer a required peer is a dependency for everyone, whatever it is called.
| Optional peer | Needed by | Install when you need it |
|---|---|---|
| playwright | @geonosis/walk | pnpm add -D playwright · bun add -d playwright |
| posthog-node | @geonosis/observability | pnpm add -D posthog-node · bun add -d posthog-node |
| squawk-cli | @geonosis/release (postgres, mikro-orm-ts) | pnpm add -D [email protected] |
The peers everybody does pay for are oxlint, because every gate lints and oxlint is what loads the
plugin, and zod and better-result, because @geonosis/review and @geonosis/observability
put them in their public types. A consumer cannot call those packages without its own copy.
Libraries a repo imports from its own source are added by name, on the same version:
@geonosis/policy, @geonosis/integrations, @geonosis/themekit, @geonosis/rails,
@geonosis/evals, @geonosis/mcp, and create-geonosis for a new repo.
The floor packages under foundations/ and domains/ (@geonosis/events, @geonosis/db and the
rest) each version on a line of their own, so this number says nothing about which one to install.
Ask npm for its latest.
The lists above are exported as data (TOOLCHAIN, BY_NAME, OPTIONAL_BINARIES) and checked
against the workspace by this package's own test, so a package added to the group cannot go missing
from them quietly.
