From 7109994002e277074765662c8ff35d41ef6c10f9 Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 17:45:28 +1000 Subject: [PATCH 1/9] refactor: move npm packages and examples into languages/typescript Pure rename, no content changes, so git log --follow keeps each file's history. Every package under packages/ except EQL moves to languages/typescript/packages/, and examples/ moves to languages/typescript/examples/. packages/ is left for Rust crates and EQL, which stays whole at packages/eql. The tree does not build at this commit; the next commits update the references to the old paths. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- {examples => languages/typescript/examples}/basic/CHANGELOG.md | 0 {examples => languages/typescript/examples}/basic/README.md | 0 {examples => languages/typescript/examples}/basic/encrypt.ts | 0 {examples => languages/typescript/examples}/basic/index.ts | 0 {examples => languages/typescript/examples}/basic/package.json | 0 .../typescript/examples}/basic/src/encryption/index.ts | 0 {examples => languages/typescript/examples}/basic/stash.config.ts | 0 {examples => languages/typescript/examples}/basic/tsconfig.json | 0 {examples => languages/typescript/examples}/prisma/.env.example | 0 {examples => languages/typescript/examples}/prisma/CHANGELOG.md | 0 {examples => languages/typescript/examples}/prisma/README.md | 0 .../typescript/examples}/prisma/docker-compose.yml | 0 .../prisma/migrations/app/20260714T2142_initial/migration.json | 0 .../prisma/migrations/app/20260714T2142_initial/migration.ts | 0 .../prisma/migrations/app/20260714T2142_initial/ops.json | 0 .../20260601T0100_install_eql_v3_bundle/migration.json | 0 .../cipherstash/20260601T0100_install_eql_v3_bundle/ops.json | 0 .../cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/migration.json | 0 .../cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/ops.json | 0 .../cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/migration.json | 0 .../cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/ops.json | 0 .../cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/migration.json | 0 .../cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/ops.json | 0 .../cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/migration.json | 0 .../cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/ops.json | 0 .../examples}/prisma/migrations/cipherstash/refs/head.json | 0 .../contract.d.ts | 0 .../contract.json | 0 .../contract.d.ts | 0 .../contract.json | 0 {examples => languages/typescript/examples}/prisma/package.json | 0 .../typescript/examples}/prisma/prisma-next.config.ts | 0 .../typescript/examples}/prisma/prisma/schema.prisma | 0 {examples => languages/typescript/examples}/prisma/src/db.ts | 0 {examples => languages/typescript/examples}/prisma/src/index.ts | 0 .../typescript/examples}/prisma/src/prisma/contract.d.ts | 0 .../typescript/examples}/prisma/src/prisma/contract.json | 0 .../typescript/examples}/prisma/test/e2e/README.md | 0 .../typescript/examples}/prisma/test/e2e/bigint.e2e.test.ts | 0 .../typescript/examples}/prisma/test/e2e/bool.e2e.test.ts | 0 .../typescript/examples}/prisma/test/e2e/date.e2e.test.ts | 0 .../typescript/examples}/prisma/test/e2e/docker-compose.yml | 0 .../typescript/examples}/prisma/test/e2e/global-setup.ts | 0 .../typescript/examples}/prisma/test/e2e/harness.ts | 0 .../typescript/examples}/prisma/test/e2e/json.e2e.test.ts | 0 .../typescript/examples}/prisma/test/e2e/mixed.e2e.test.ts | 0 .../typescript/examples}/prisma/test/e2e/num.e2e.test.ts | 0 .../typescript/examples}/prisma/test/e2e/str-range.e2e.test.ts | 0 .../typescript/examples}/prisma/test/e2e/vitest.config.ts | 0 {examples => languages/typescript/examples}/prisma/tsconfig.json | 0 .../typescript/examples}/supabase-worker/.env.example | 0 .../typescript/examples}/supabase-worker/README.md | 0 .../typescript/examples}/supabase-worker/package.json | 0 .../supabase/functions/cipherstash-roundtrip/index.ts | 0 {packages => languages/typescript/packages}/bench/.gitignore | 0 {packages => languages/typescript/packages}/bench/CHANGELOG.md | 0 {packages => languages/typescript/packages}/bench/README.md | 0 .../packages}/bench/__benches__/drizzle/operators.bench.ts | 0 .../typescript/packages}/bench/__tests__/db-only.test.ts | 0 .../packages}/bench/__tests__/drizzle/operators.explain.test.ts | 0 .../typescript/packages}/bench/__tests__/harness.test.ts | 0 .../typescript/packages}/bench/__unit__/seed-keys.test.ts | 0 {packages => languages/typescript/packages}/bench/package.json | 0 {packages => languages/typescript/packages}/bench/sql/schema.sql | 0 .../typescript/packages}/bench/src/cli/reset.ts | 0 .../typescript/packages}/bench/src/cli/setup.ts | 0 .../typescript/packages}/bench/src/drizzle/setup.ts | 0 .../typescript/packages}/bench/src/harness/db.ts | 0 .../typescript/packages}/bench/src/harness/explain.ts | 0 .../typescript/packages}/bench/src/harness/global-setup.ts | 0 .../typescript/packages}/bench/src/harness/seed.ts | 0 {packages => languages/typescript/packages}/bench/tsconfig.json | 0 .../typescript/packages}/bench/vitest.config.ts | 0 .../typescript/packages}/bench/vitest.unit.config.ts | 0 {packages => languages/typescript/packages}/cli/AGENTS.md | 0 {packages => languages/typescript/packages}/cli/CHANGELOG.md | 0 {packages => languages/typescript/packages}/cli/README.md | 0 .../packages}/cli/__fixtures__/scaffold/drizzle.generated.ts | 0 .../packages}/cli/__fixtures__/scaffold/generic.generated.ts | 0 {packages => languages/typescript/packages}/cli/package.json | 0 .../typescript/packages}/cli/scripts/e2e-encrypt.sh | 0 .../typescript/packages}/cli/scripts/fixtures/seed-users.sql | 0 .../packages}/cli/src/__tests__/config-jiti-integration.test.ts | 0 .../typescript/packages}/cli/src/__tests__/config.test.ts | 0 .../typescript/packages}/cli/src/__tests__/database-url.test.ts | 0 .../typescript/packages}/cli/src/__tests__/detect.test.ts | 0 .../typescript/packages}/cli/src/__tests__/installer.test.ts | 0 .../cli/src/__tests__/module-error-classification.test.ts | 0 .../typescript/packages}/cli/src/__tests__/native.test.ts | 0 .../packages}/cli/src/__tests__/placeholder-guard-parity.test.ts | 0 .../typescript/packages}/cli/src/__tests__/release-train.test.ts | 0 .../packages}/cli/src/__tests__/rewrite-migrations.test.ts | 0 .../packages}/cli/src/__tests__/runtime-versions.test.ts | 0 .../packages}/cli/src/__tests__/skill-supabase-apply.test.ts | 0 .../typescript/packages}/cli/src/__tests__/v2-retirement.test.ts | 0 {packages => languages/typescript/packages}/cli/src/bin/main.ts | 0 {packages => languages/typescript/packages}/cli/src/bin/stash.ts | 0 .../typescript/packages}/cli/src/cli/__tests__/help.test.ts | 0 .../typescript/packages}/cli/src/cli/__tests__/manifest.test.ts | 0 {packages => languages/typescript/packages}/cli/src/cli/exit.ts | 0 {packages => languages/typescript/packages}/cli/src/cli/help.ts | 0 .../typescript/packages}/cli/src/cli/manifest.ts | 0 .../typescript/packages}/cli/src/cli/registry.ts | 0 .../packages}/cli/src/commands/auth/__tests__/failure.test.ts | 0 .../packages}/cli/src/commands/auth/__tests__/index.test.ts | 0 .../packages}/cli/src/commands/auth/__tests__/login.test.ts | 0 .../packages}/cli/src/commands/auth/__tests__/region.test.ts | 0 .../typescript/packages}/cli/src/commands/auth/events.ts | 0 .../typescript/packages}/cli/src/commands/auth/failure.ts | 0 .../typescript/packages}/cli/src/commands/auth/index.ts | 0 .../typescript/packages}/cli/src/commands/auth/login.ts | 0 .../typescript/packages}/cli/src/commands/auth/region.ts | 0 .../cli/src/commands/db/__tests__/config-scaffold.test.ts | 0 .../src/commands/db/__tests__/find-generated-migration.test.ts | 0 .../cli/src/commands/db/__tests__/install-verify-gate.test.ts | 0 .../packages}/cli/src/commands/db/__tests__/install.test.ts | 0 .../packages}/cli/src/commands/db/__tests__/preflight.test.ts | 0 .../src/commands/db/__tests__/prisma-next-install-guard.test.ts | 0 .../packages}/cli/src/commands/db/__tests__/status.test.ts | 0 .../packages}/cli/src/commands/db/__tests__/upgrade.test.ts | 0 .../typescript/packages}/cli/src/commands/db/client-scaffold.ts | 0 .../typescript/packages}/cli/src/commands/db/config-scaffold.ts | 0 .../typescript/packages}/cli/src/commands/db/detect.ts | 0 .../typescript/packages}/cli/src/commands/db/grants-report.ts | 0 .../typescript/packages}/cli/src/commands/db/install.ts | 0 .../typescript/packages}/cli/src/commands/db/preflight.ts | 0 .../packages}/cli/src/commands/db/resolve-diagnostic-url.ts | 0 .../packages}/cli/src/commands/db/rewrite-migrations.ts | 0 .../typescript/packages}/cli/src/commands/db/status.ts | 0 .../typescript/packages}/cli/src/commands/db/test-connection.ts | 0 .../typescript/packages}/cli/src/commands/db/upgrade.ts | 0 .../typescript/packages}/cli/src/commands/doctor/index.ts | 0 .../cli/src/commands/encrypt/__tests__/backfill-target.test.ts | 0 .../src/commands/encrypt/__tests__/context-placeholder.test.ts | 0 .../cli/src/commands/encrypt/__tests__/encrypt-v3.test.ts | 0 .../src/commands/encrypt/__tests__/prisma-next-context.test.ts | 0 .../typescript/packages}/cli/src/commands/encrypt/backfill.ts | 0 .../typescript/packages}/cli/src/commands/encrypt/context.ts | 0 .../packages}/cli/src/commands/encrypt/drizzle-helper.ts | 0 .../typescript/packages}/cli/src/commands/encrypt/drop.ts | 0 .../cli/src/commands/encrypt/lib/__tests__/resolve-eql.test.ts | 0 .../packages}/cli/src/commands/encrypt/lib/db-readers.ts | 0 .../packages}/cli/src/commands/encrypt/lib/resolve-eql.ts | 0 .../typescript/packages}/cli/src/commands/encrypt/plan.ts | 0 .../typescript/packages}/cli/src/commands/encrypt/status.ts | 0 .../packages}/cli/src/commands/env/__tests__/env.test.ts | 0 .../typescript/packages}/cli/src/commands/env/index.ts | 0 .../packages}/cli/src/commands/eql/__tests__/applied.live.test.ts | 0 .../packages}/cli/src/commands/eql/__tests__/migration.test.ts | 0 .../packages}/cli/src/commands/eql/__tests__/repair.test.ts | 0 .../cli/src/commands/eql/__tests__/supabase-migration.test.ts | 0 .../cli/src/commands/eql/__tests__/supabase-push.live.test.ts | 0 .../cli/src/commands/eql/__tests__/validate-command.test.ts | 0 .../packages}/cli/src/commands/eql/__tests__/validate.test.ts | 0 .../typescript/packages}/cli/src/commands/eql/applied.ts | 0 .../typescript/packages}/cli/src/commands/eql/journal.ts | 0 .../typescript/packages}/cli/src/commands/eql/migration.ts | 0 .../typescript/packages}/cli/src/commands/eql/repair.ts | 0 .../packages}/cli/src/commands/eql/supabase-migration.ts | 0 .../typescript/packages}/cli/src/commands/eql/sweep-report.ts | 0 .../typescript/packages}/cli/src/commands/eql/validate.ts | 0 .../typescript/packages}/cli/src/commands/eql/verify.ts | 0 .../cli/src/commands/impl/__tests__/how-to-proceed.test.ts | 0 .../packages}/cli/src/commands/impl/__tests__/impl.test.ts | 0 .../typescript/packages}/cli/src/commands/impl/index.ts | 0 .../src/commands/impl/steps/__tests__/handoff-agents-md.test.ts | 0 .../cli/src/commands/impl/steps/__tests__/handoff-claude.test.ts | 0 .../cli/src/commands/impl/steps/__tests__/handoff-codex.test.ts | 0 .../cli/src/commands/impl/steps/__tests__/handoff-lovable.test.ts | 0 .../commands/impl/steps/__tests__/how-to-proceed-dispatch.test.ts | 0 .../packages}/cli/src/commands/impl/steps/handoff-agents-md.ts | 0 .../packages}/cli/src/commands/impl/steps/handoff-claude.ts | 0 .../packages}/cli/src/commands/impl/steps/handoff-codex.ts | 0 .../packages}/cli/src/commands/impl/steps/handoff-lovable.ts | 0 .../packages}/cli/src/commands/impl/steps/handoff-wizard.ts | 0 .../packages}/cli/src/commands/impl/steps/how-to-proceed.ts | 0 .../typescript/packages}/cli/src/commands/index.ts | 0 .../cli/src/commands/init/__tests__/detect-agents.test.ts | 0 .../cli/src/commands/init/__tests__/init-command.test.ts | 0 .../commands/init/__tests__/placeholder-client-fixture.test.ts | 0 .../cli/src/commands/init/__tests__/sentinel-upsert.test.ts | 0 .../cli/src/commands/init/__tests__/steps-wiring.test.ts | 0 .../cli/src/commands/init/__tests__/utils-codegen-drizzle.test.ts | 0 .../cli/src/commands/init/__tests__/utils-codegen.test.ts | 0 .../packages}/cli/src/commands/init/__tests__/utils.test.ts | 0 .../typescript/packages}/cli/src/commands/init/detect-agents.ts | 0 .../packages}/cli/src/commands/init/doctrine/AGENTS-doctrine.md | 0 .../typescript/packages}/cli/src/commands/init/index.ts | 0 .../cli/src/commands/init/lib/__tests__/build-agents-md.test.ts | 0 .../commands/init/lib/__tests__/build-flow.integration.test.ts | 0 .../cli/src/commands/init/lib/__tests__/handoff-helpers.test.ts | 0 .../cli/src/commands/init/lib/__tests__/install-skills.test.ts | 0 .../cli/src/commands/init/lib/__tests__/introspect.test.ts | 0 .../cli/src/commands/init/lib/__tests__/parse-plan.test.ts | 0 .../cli/src/commands/init/lib/__tests__/read-context.test.ts | 0 .../cli/src/commands/init/lib/__tests__/rollout-state.test.ts | 0 .../cli/src/commands/init/lib/__tests__/setup-prompt.test.ts | 0 .../cli/src/commands/init/lib/__tests__/write-context.test.ts | 0 .../packages}/cli/src/commands/init/lib/build-agents-md.ts | 0 .../packages}/cli/src/commands/init/lib/bundled-paths.ts | 0 .../typescript/packages}/cli/src/commands/init/lib/env-keys.ts | 0 .../packages}/cli/src/commands/init/lib/handoff-helpers.ts | 0 .../packages}/cli/src/commands/init/lib/install-skills.ts | 0 .../typescript/packages}/cli/src/commands/init/lib/introspect.ts | 0 .../typescript/packages}/cli/src/commands/init/lib/parse-plan.ts | 0 .../packages}/cli/src/commands/init/lib/read-context.ts | 0 .../packages}/cli/src/commands/init/lib/rollout-state.ts | 0 .../packages}/cli/src/commands/init/lib/sentinel-upsert.ts | 0 .../packages}/cli/src/commands/init/lib/setup-prompt.ts | 0 .../packages}/cli/src/commands/init/lib/write-context.ts | 0 .../cli/src/commands/init/providers/__tests__/base.test.ts | 0 .../cli/src/commands/init/providers/__tests__/drizzle.test.ts | 0 .../cli/src/commands/init/providers/__tests__/prisma.test.ts | 0 .../cli/src/commands/init/providers/__tests__/supabase.test.ts | 0 .../typescript/packages}/cli/src/commands/init/providers/base.ts | 0 .../packages}/cli/src/commands/init/providers/drizzle.ts | 0 .../packages}/cli/src/commands/init/providers/prisma.ts | 0 .../packages}/cli/src/commands/init/providers/supabase.ts | 0 .../cli/src/commands/init/steps/__tests__/build-schema.test.ts | 0 .../cli/src/commands/init/steps/__tests__/install-deps.test.ts | 0 .../cli/src/commands/init/steps/__tests__/install-eql.test.ts | 0 .../cli/src/commands/init/steps/__tests__/install-skills.test.ts | 0 .../src/commands/init/steps/__tests__/resolve-database.test.ts | 0 .../packages}/cli/src/commands/init/steps/authenticate.ts | 0 .../packages}/cli/src/commands/init/steps/build-schema.ts | 0 .../packages}/cli/src/commands/init/steps/gather-context.ts | 0 .../packages}/cli/src/commands/init/steps/install-deps.ts | 0 .../packages}/cli/src/commands/init/steps/install-eql.ts | 0 .../packages}/cli/src/commands/init/steps/install-skills.ts | 0 .../packages}/cli/src/commands/init/steps/resolve-database.ts | 0 .../typescript/packages}/cli/src/commands/init/types.ts | 0 .../typescript/packages}/cli/src/commands/init/utils.ts | 0 .../typescript/packages}/cli/src/commands/manifest/index.ts | 0 .../typescript/packages}/cli/src/commands/plan/index.ts | 0 .../typescript/packages}/cli/src/commands/schema/build.ts | 0 .../packages}/cli/src/commands/status/__tests__/status.test.ts | 0 .../typescript/packages}/cli/src/commands/status/index.ts | 0 .../typescript/packages}/cli/src/commands/status/quest.ts | 0 .../typescript/packages}/cli/src/commands/status/render.ts | 0 .../typescript/packages}/cli/src/commands/telemetry/index.ts | 0 .../packages}/cli/src/commands/wizard/__tests__/index.test.ts | 0 .../typescript/packages}/cli/src/commands/wizard/index.ts | 0 .../cli/src/config/__tests__/load-encrypt-schemas.test.ts | 0 .../packages}/cli/src/config/__tests__/missing-package.test.ts | 0 .../typescript/packages}/cli/src/config/__tests__/tty.test.ts | 0 .../typescript/packages}/cli/src/config/database-url.ts | 0 .../typescript/packages}/cli/src/config/index.ts | 0 .../typescript/packages}/cli/src/config/missing-package.ts | 0 {packages => languages/typescript/packages}/cli/src/config/tty.ts | 0 .../typescript/packages}/cli/src/db/__tests__/client-wrap.test.ts | 0 .../typescript/packages}/cli/src/db/__tests__/config.test.ts | 0 .../packages}/cli/src/db/__tests__/no-sslmode-advisory.test.ts | 0 .../packages}/cli/src/db/__tests__/pg-construction-lint.test.ts | 0 {packages => languages/typescript/packages}/cli/src/db/client.ts | 0 {packages => languages/typescript/packages}/cli/src/db/config.ts | 0 .../typescript/packages}/cli/src/db/supabase-ca.ts | 0 {packages => languages/typescript/packages}/cli/src/index.ts | 0 .../packages}/cli/src/installer/__tests__/bundle-digest.test.ts | 0 .../cli/src/installer/__tests__/guarded-grants.live.test.ts | 0 .../cli/src/installer/__tests__/installation-state.test.ts | 0 .../typescript/packages}/cli/src/installer/__tests__/ore.test.ts | 0 .../packages}/cli/src/installer/__tests__/preflight.live.test.ts | 0 .../packages}/cli/src/installer/__tests__/reinstall.live.test.ts | 0 .../cli/src/installer/__tests__/restoration-scenarios.ts | 0 .../installer/__tests__/upgrade-encrypted-indexes.live.test.ts | 0 .../packages}/cli/src/installer/__tests__/verify.live.test.ts | 0 .../packages}/cli/src/installer/__tests__/verify.test.ts | 0 .../typescript/packages}/cli/src/installer/bundle-digest.ts | 0 .../cli/src/installer/derived-search-index-restoration.ts | 0 .../typescript/packages}/cli/src/installer/eql-bundle.ts | 0 .../typescript/packages}/cli/src/installer/grants.ts | 0 .../typescript/packages}/cli/src/installer/index.ts | 0 .../typescript/packages}/cli/src/installer/installation-state.ts | 0 .../typescript/packages}/cli/src/installer/ore.ts | 0 .../typescript/packages}/cli/src/installer/verify.ts | 0 {packages => languages/typescript/packages}/cli/src/messages.ts | 0 .../typescript/packages}/cli/src/module-error.ts | 0 {packages => languages/typescript/packages}/cli/src/native.ts | 0 .../typescript/packages}/cli/src/release-train.ts | 0 .../typescript/packages}/cli/src/runtime-versions.ts | 0 .../cli/src/telemetry/__tests__/classify-command.test.ts | 0 .../packages}/cli/src/telemetry/__tests__/state.test.ts | 0 .../cli/src/telemetry/__tests__/telemetry-lifecycle.test.ts | 0 .../packages}/cli/src/telemetry/__tests__/telemetry.test.ts | 0 .../typescript/packages}/cli/src/telemetry/classify-command.ts | 0 .../typescript/packages}/cli/src/telemetry/index.ts | 0 .../typescript/packages}/cli/src/telemetry/state.ts | 0 .../packages}/cli/tests/e2e/auth-login-cancel.e2e.test.ts | 0 .../packages}/cli/tests/e2e/auth-non-interactive.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/command-help.e2e.test.ts | 0 .../packages}/cli/tests/e2e/config-scaffold.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/database-url.e2e.test.ts | 0 .../packages}/cli/tests/e2e/doctor-missing-binary.e2e.test.ts | 0 .../cli/tests/e2e/doctor-probe-classification.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/doctor.e2e.test.ts | 0 .../packages}/cli/tests/e2e/env-non-interactive.e2e.test.ts | 0 .../packages}/cli/tests/e2e/eql-install-prisma-next.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/eql-repair.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/impl-non-tty.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/impl-pty-ci.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/manifest.e2e.test.ts | 0 .../packages}/cli/tests/e2e/plan-complete-rollout.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/plan-outcome.e2e.test.ts | 0 .../packages}/cli/tests/e2e/runner-aware-help.e2e.test.ts | 0 .../packages}/cli/tests/e2e/runtime-versions-embed.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/smoke.e2e.test.ts | 0 .../typescript/packages}/cli/tests/e2e/v2-retirement.e2e.test.ts | 0 .../typescript/packages}/cli/tests/helpers/pty.ts | 0 .../typescript/packages}/cli/tests/helpers/run.test.ts | 0 .../typescript/packages}/cli/tests/helpers/run.ts | 0 .../typescript/packages}/cli/tests/helpers/spawn-piped.ts | 0 {packages => languages/typescript/packages}/cli/tsconfig.json | 0 .../typescript/packages}/cli/tsconfig.scaffold.json | 0 {packages => languages/typescript/packages}/cli/tsup.config.ts | 0 {packages => languages/typescript/packages}/cli/vitest.config.ts | 0 .../typescript/packages}/cli/vitest.integration.config.ts | 0 {packages => languages/typescript/packages}/migrate/CHANGELOG.md | 0 {packages => languages/typescript/packages}/migrate/README.md | 0 {packages => languages/typescript/packages}/migrate/package.json | 0 .../migrate/src/__tests__/backfill-v3.integration.test.ts | 0 .../packages}/migrate/src/__tests__/backfill.integration.test.ts | 0 .../typescript/packages}/migrate/src/__tests__/manifest.test.ts | 0 .../typescript/packages}/migrate/src/__tests__/sql.test.ts | 0 .../typescript/packages}/migrate/src/__tests__/state.test.ts | 0 .../packages}/migrate/src/__tests__/v2-retirement.test.ts | 0 .../typescript/packages}/migrate/src/__tests__/version.test.ts | 0 .../typescript/packages}/migrate/src/backfill.ts | 0 {packages => languages/typescript/packages}/migrate/src/cursor.ts | 0 {packages => languages/typescript/packages}/migrate/src/index.ts | 0 .../typescript/packages}/migrate/src/install.ts | 0 .../typescript/packages}/migrate/src/manifest.ts | 0 {packages => languages/typescript/packages}/migrate/src/sql.ts | 0 {packages => languages/typescript/packages}/migrate/src/state.ts | 0 .../typescript/packages}/migrate/src/version.ts | 0 {packages => languages/typescript/packages}/migrate/tsconfig.json | 0 .../typescript/packages}/migrate/tsup.config.ts | 0 .../typescript/packages}/migrate/vitest.config.ts | 0 {packages => languages/typescript/packages}/nextjs/CHANGELOG.md | 0 {packages => languages/typescript/packages}/nextjs/README.md | 0 .../typescript/packages}/nextjs/__tests__/cts-refusal.test.ts | 0 .../typescript/packages}/nextjs/__tests__/nextjs.test.ts | 0 {packages => languages/typescript/packages}/nextjs/package.json | 0 .../typescript/packages}/nextjs/src/clerk/index.ts | 0 .../typescript/packages}/nextjs/src/cts/index.ts | 0 {packages => languages/typescript/packages}/nextjs/src/index.ts | 0 .../typescript/packages}/nextjs/tsconfig.jest.json | 0 {packages => languages/typescript/packages}/nextjs/tsconfig.json | 0 {packages => languages/typescript/packages}/nextjs/tsup.config.ts | 0 .../typescript/packages}/protect-ffi/.gitignore | 0 .../typescript/packages}/protect-ffi/CHANGELOG.md | 0 .../typescript/packages}/protect-ffi/Cargo.lock | 0 .../typescript/packages}/protect-ffi/Cargo.toml | 0 .../typescript/packages}/protect-ffi/LICENSE.md | 0 {packages => languages/typescript/packages}/protect-ffi/README.md | 0 .../packages}/protect-ffi/crates/protect-ffi/Cargo.toml | 0 .../protect-ffi/crates/protect-ffi/src/client_options.rs | 0 .../protect-ffi/crates/protect-ffi/src/encrypt_config.rs | 0 .../packages}/protect-ffi/crates/protect-ffi/src/eql_v3.rs | 0 .../packages}/protect-ffi/crates/protect-ffi/src/js_plaintext.rs | 0 .../packages}/protect-ffi/crates/protect-ffi/src/lib.rs | 0 .../packages}/protect-ffi/crates/protect-ffi/src/query_op.rs | 0 .../packages}/protect-ffi/crates/protect-ffi/src/wasm.rs | 0 .../typescript/packages}/protect-ffi/dist/wasm/errors.d.ts | 0 .../typescript/packages}/protect-ffi/dist/wasm/protect_ffi.d.ts | 0 .../packages}/protect-ffi/dist/wasm/protect_ffi_bg.wasm.d.ts | 0 .../protect-ffi/docs/canonical-encryption-config-migration.md | 0 .../typescript/packages}/protect-ffi/docs/jsonb-api-reference.md | 0 .../typescript/packages}/protect-ffi/docs/jsonb-integration.md | 0 .../packages}/protect-ffi/docs/jsonb-troubleshooting.md | 0 .../packages}/protect-ffi/integration-tests/CHANGELOG.md | 0 .../packages}/protect-ffi/integration-tests/docker-compose.yml | 0 .../packages}/protect-ffi/integration-tests/package.json | 0 .../packages}/protect-ffi/integration-tests/sql/.gitkeep | 0 .../typescript/packages}/protect-ffi/integration-tests/tasks.toml | 0 .../packages}/protect-ffi/integration-tests/tests/common.ts | 0 .../packages}/protect-ffi/integration-tests/tests/dates.test.ts | 0 .../protect-ffi/integration-tests/tests/encrypt-config.test.ts | 0 .../packages}/protect-ffi/integration-tests/tests/eql-v3.test.ts | 0 .../protect-ffi/integration-tests/tests/error-stack.test.ts | 0 .../protect-ffi/integration-tests/tests/event-loop-exit.test.ts | 0 .../integration-tests/tests/fixtures/event-loop-exit-auto.cjs | 0 .../integration-tests/tests/fixtures/event-loop-exit-jsbacked.cjs | 0 .../protect-ffi/integration-tests/tests/js-strategy.test.ts | 0 .../protect-ffi/integration-tests/tests/json-bulk.test.ts | 0 .../protect-ffi/integration-tests/tests/json-containment.test.ts | 0 .../packages}/protect-ffi/integration-tests/tests/json.test.ts | 0 .../packages}/protect-ffi/integration-tests/tests/keyset.test.ts | 0 .../protect-ffi/integration-tests/tests/lock-context.test.ts | 0 .../protect-ffi/integration-tests/tests/oidc-federation.test.ts | 0 .../protect-ffi/integration-tests/tests/postgres-v3.test.ts | 0 .../protect-ffi/integration-tests/tests/postgres.test.ts | 0 .../packages}/protect-ffi/integration-tests/tests/query.test.ts | 0 .../protect-ffi/integration-tests/tests/scalar-bulk.test.ts | 0 .../packages}/protect-ffi/integration-tests/tests/scalar.test.ts | 0 .../protect-ffi/integration-tests/tests/strict-options.test.ts | 0 .../protect-ffi/integration-tests/tests/wasm-error-codes.test.ts | 0 .../protect-ffi/integration-tests/tests/wasm-round-trip.test.ts | 0 .../packages}/protect-ffi/integration-tests/tsconfig.json | 0 .../packages}/protect-ffi/integration-tests/vitest.config.ts | 0 {packages => languages/typescript/packages}/protect-ffi/mise.toml | 0 .../typescript/packages}/protect-ffi/package.json | 0 .../packages}/protect-ffi/platforms/darwin-arm64/CHANGELOG.md | 0 .../packages}/protect-ffi/platforms/darwin-arm64/README.md | 0 .../packages}/protect-ffi/platforms/darwin-arm64/package.json | 0 .../packages}/protect-ffi/platforms/darwin-x64/CHANGELOG.md | 0 .../packages}/protect-ffi/platforms/darwin-x64/README.md | 0 .../packages}/protect-ffi/platforms/darwin-x64/package.json | 0 .../packages}/protect-ffi/platforms/linux-arm64-gnu/CHANGELOG.md | 0 .../packages}/protect-ffi/platforms/linux-arm64-gnu/README.md | 0 .../packages}/protect-ffi/platforms/linux-arm64-gnu/package.json | 0 .../packages}/protect-ffi/platforms/linux-x64-gnu/CHANGELOG.md | 0 .../packages}/protect-ffi/platforms/linux-x64-gnu/README.md | 0 .../packages}/protect-ffi/platforms/linux-x64-gnu/package.json | 0 .../packages}/protect-ffi/platforms/linux-x64-musl/CHANGELOG.md | 0 .../packages}/protect-ffi/platforms/linux-x64-musl/README.md | 0 .../packages}/protect-ffi/platforms/linux-x64-musl/package.json | 0 .../packages}/protect-ffi/platforms/win32-x64-msvc/CHANGELOG.md | 0 .../packages}/protect-ffi/platforms/win32-x64-msvc/README.md | 0 .../packages}/protect-ffi/platforms/win32-x64-msvc/package.json | 0 .../packages}/protect-ffi/scripts/changelog-extract.mjs | 0 .../typescript/packages}/protect-ffi/scripts/inline-wasm.mjs | 0 .../typescript/packages}/protect-ffi/scripts/sync-eql-v3-types.sh | 0 .../typescript/packages}/protect-ffi/src/bigintWire.test.ts | 0 .../typescript/packages}/protect-ffi/src/bigintWire.ts | 0 .../typescript/packages}/protect-ffi/src/credentials.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Bigint.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/BigintEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/BigintEqQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/BigintOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/BigintOrdOpe.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/BigintOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/BigintOrdOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/BigintOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/BigintOrdQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/BloomFilter.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Boolean.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/Ciphertext.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Date.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/DateEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DateEqQuery.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/DateOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DateOrdOpe.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DateOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DateOrdOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DateOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DateOrdQuery.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Double.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/DoubleEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DoubleEqQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DoubleOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DoubleOrdOpe.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DoubleOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DoubleOrdOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DoubleOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/DoubleOrdQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/EntryCiphertext.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Hmac256.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/Identifier.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Integer.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/IntegerEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/IntegerEqQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/IntegerOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/IntegerOrdOpe.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/IntegerOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/IntegerOrdOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/IntegerOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/IntegerOrdQuery.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Json.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/KeyHeader.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Numeric.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/NumericEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/NumericEqQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/NumericOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/NumericOrdOpe.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/NumericOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/NumericOrdOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/NumericOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/NumericOrdQuery.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/OpeCllw.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/OreBlock256.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Real.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/RealEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/RealEqQuery.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/RealOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/RealOrdOpe.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/RealOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/RealOrdOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/RealOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/RealOrdQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SchemaVersion.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Selector.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Smallint.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SmallintEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SmallintEqQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SmallintOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SmallintOrdOpe.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SmallintOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SmallintOrdOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SmallintOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SmallintOrdQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SteVecDocument.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SteVecEntry.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SteVecForm.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SteVecQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/SteVecQueryEntry.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/Text.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/TextEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextEqQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextMatch.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextMatchQuery.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3-types/TextOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextOrdOpe.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextOrdOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextOrdQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextSearch.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextSearchOre.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextSearchOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TextSearchQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/Timestamp.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TimestampEq.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TimestampEqQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TimestampOrd.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TimestampOrdOpe.ts | 0 .../protect-ffi/src/eql-v3-types/TimestampOrdOpeQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TimestampOrdOre.ts | 0 .../protect-ffi/src/eql-v3-types/TimestampOrdOreQuery.ts | 0 .../packages}/protect-ffi/src/eql-v3-types/TimestampOrdQuery.ts | 0 .../typescript/packages}/protect-ffi/src/eql-v3.ts | 0 .../typescript/packages}/protect-ffi/src/errorCodes.test.ts | 0 .../typescript/packages}/protect-ffi/src/errors.test.ts | 0 .../typescript/packages}/protect-ffi/src/errors.ts | 0 .../typescript/packages}/protect-ffi/src/index.cts | 0 .../typescript/packages}/protect-ffi/src/index.mts | 0 .../typescript/packages}/protect-ffi/src/index.types.test.ts | 0 .../packages}/protect-ffi/src/integrationSuiteCi.test.ts | 0 .../typescript/packages}/protect-ffi/src/lintWiring.test.ts | 0 .../typescript/packages}/protect-ffi/src/load.cts | 0 .../typescript/packages}/protect-ffi/src/nativeLoading.test.ts | 0 .../typescript/packages}/protect-ffi/src/newClientArgs.test.ts | 0 .../typescript/packages}/protect-ffi/src/newClientArgs.ts | 0 .../typescript/packages}/protect-ffi/src/types.ts | 0 .../packages}/protect-ffi/src/withEnvCredentials.test.ts | 0 .../typescript/packages}/protect-ffi/tsconfig.json | 0 .../typescript/packages}/protect-ffi/tsconfig.test.json | 0 .../typescript/packages}/protect-ffi/tsconfig.wasm-errors.json | 0 .../typescript/packages}/protect-ffi/type-tests/tsconfig.json | 0 .../typescript/packages}/protect-ffi/type-tests/wasm.test-d.mts | 0 .../typescript/packages}/protect-ffi/vitest.config.ts | 0 .../typescript/packages}/stack-drizzle/CHANGELOG.md | 0 .../typescript/packages}/stack-drizzle/README.md | 0 .../typescript/packages}/stack-drizzle/__tests__/bigint.test.ts | 0 .../typescript/packages}/stack-drizzle/__tests__/codec.test.ts | 0 .../typescript/packages}/stack-drizzle/__tests__/column.test.ts | 0 .../typescript/packages}/stack-drizzle/__tests__/exports.test.ts | 0 .../typescript/packages}/stack-drizzle/__tests__/indexes.test.ts | 0 .../packages}/stack-drizzle/__tests__/operators.test-d.ts | 0 .../packages}/stack-drizzle/__tests__/operators.test.ts | 0 .../packages}/stack-drizzle/__tests__/schema-extraction.test-d.ts | 0 .../packages}/stack-drizzle/__tests__/schema-extraction.test.ts | 0 .../typescript/packages}/stack-drizzle/__tests__/selector.test.ts | 0 .../packages}/stack-drizzle/__tests__/sql-dialect.test.ts | 0 .../typescript/packages}/stack-drizzle/__tests__/types.test-d.ts | 0 .../typescript/packages}/stack-drizzle/__tests__/types.test.ts | 0 .../typescript/packages}/stack-drizzle/integration/adapter.ts | 0 .../stack-drizzle/integration/families.integration.test.ts | 0 .../packages}/stack-drizzle/integration/json-adapter.ts | 0 .../packages}/stack-drizzle/integration/json.integration.test.ts | 0 .../stack-drizzle/integration/lock-context.integration.test.ts | 0 .../integration/null-persistence.integration.test.ts | 0 .../stack-drizzle/integration/relational.integration.test.ts | 0 .../packages}/stack-drizzle/integration/vitest.config.ts | 0 .../typescript/packages}/stack-drizzle/package.json | 0 .../typescript/packages}/stack-drizzle/src/codec.ts | 0 .../typescript/packages}/stack-drizzle/src/column.ts | 0 .../typescript/packages}/stack-drizzle/src/index.ts | 0 .../typescript/packages}/stack-drizzle/src/indexes.ts | 0 .../typescript/packages}/stack-drizzle/src/operators.ts | 0 .../typescript/packages}/stack-drizzle/src/schema-extraction.ts | 0 .../typescript/packages}/stack-drizzle/src/sql-dialect.ts | 0 .../typescript/packages}/stack-drizzle/src/types.ts | 0 .../typescript/packages}/stack-drizzle/tsconfig.json | 0 .../typescript/packages}/stack-drizzle/tsconfig.typecheck.json | 0 .../typescript/packages}/stack-drizzle/tsup.config.ts | 0 .../typescript/packages}/stack-drizzle/vitest.config.ts | 0 .../typescript/packages}/stack-prisma/CHANGELOG.md | 0 .../typescript/packages}/stack-prisma/DEVELOPING.md | 0 .../typescript/packages}/stack-prisma/README.md | 0 .../typescript/packages}/stack-prisma/integration/adapter.ts | 0 .../stack-prisma/integration/families.integration.test.ts | 0 .../typescript/packages}/stack-prisma/integration/json-adapter.ts | 0 .../packages}/stack-prisma/integration/json.integration.test.ts | 0 .../packages}/stack-prisma/integration/vitest.config.ts | 0 .../migrations/20260601T0100_install_eql_v3_bundle/migration.json | 0 .../migrations/20260601T0100_install_eql_v3_bundle/migration.ts | 0 .../migrations/20260601T0100_install_eql_v3_bundle/ops.json | 0 .../migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.json | 0 .../migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.ts | 0 .../migrations/20260720T0000_upgrade_eql_v3_3_0_2/ops.json | 0 .../migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.json | 0 .../migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.ts | 0 .../migrations/20260728T0000_upgrade_eql_v3_3_0_4/ops.json | 0 .../migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.json | 0 .../migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.ts | 0 .../migrations/20260814T0000_upgrade_eql_v3_3_0_5/ops.json | 0 .../migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.json | 0 .../migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.ts | 0 .../migrations/20261002T0000_upgrade_eql_v3_3_0_6/ops.json | 0 .../typescript/packages}/stack-prisma/migrations/refs/head.json | 0 .../contract.d.ts | 0 .../contract.json | 0 .../typescript/packages}/stack-prisma/package.json | 0 .../typescript/packages}/stack-prisma/prisma-next.config.ts | 0 .../typescript/packages}/stack-prisma/src/contract-authoring.ts | 0 .../typescript/packages}/stack-prisma/src/contract.d.ts | 0 .../typescript/packages}/stack-prisma/src/contract.json | 0 .../typescript/packages}/stack-prisma/src/contract.prisma | 0 .../typescript/packages}/stack-prisma/src/execution/abort.ts | 0 .../packages}/stack-prisma/src/execution/decrypt-all.ts | 0 .../packages}/stack-prisma/src/execution/envelope-base.ts | 0 .../packages}/stack-prisma/src/execution/envelope-bigint.ts | 0 .../packages}/stack-prisma/src/execution/envelope-boolean.ts | 0 .../packages}/stack-prisma/src/execution/envelope-date.ts | 0 .../packages}/stack-prisma/src/execution/envelope-json.ts | 0 .../packages}/stack-prisma/src/execution/envelope-string.ts | 0 .../packages}/stack-prisma/src/execution/middleware-registry.ts | 0 .../typescript/packages}/stack-prisma/src/execution/routing.ts | 0 .../typescript/packages}/stack-prisma/src/execution/sdk.ts | 0 .../typescript/packages}/stack-prisma/src/exports/codec-types.ts | 0 .../typescript/packages}/stack-prisma/src/exports/column-types.ts | 0 .../packages}/stack-prisma/src/exports/contract-space-typing.ts | 0 .../typescript/packages}/stack-prisma/src/exports/control.ts | 0 .../packages}/stack-prisma/src/exports/operation-types.ts | 0 .../typescript/packages}/stack-prisma/src/exports/pack.ts | 0 .../typescript/packages}/stack-prisma/src/exports/runtime.ts | 0 .../typescript/packages}/stack-prisma/src/exports/stack.ts | 0 .../typescript/packages}/stack-prisma/src/exports/v3.ts | 0 .../stack-prisma/src/extension-metadata/codec-metadata.ts | 0 .../packages}/stack-prisma/src/extension-metadata/constants-v3.ts | 0 .../packages}/stack-prisma/src/extension-metadata/constants.ts | 0 .../stack-prisma/src/extension-metadata/descriptor-meta.ts | 0 .../packages}/stack-prisma/src/migration/cipherstash-codec-v3.ts | 0 .../packages}/stack-prisma/src/migration/eql-bundle-v3.ts | 0 .../typescript/packages}/stack-prisma/src/stack/from-stack-v3.ts | 0 .../typescript/packages}/stack-prisma/src/types/codec-types.ts | 0 .../packages}/stack-prisma/src/types/operation-types.ts | 0 .../typescript/packages}/stack-prisma/src/v3/barrel.ts | 0 .../typescript/packages}/stack-prisma/src/v3/bulk-encrypt-v3.ts | 0 .../typescript/packages}/stack-prisma/src/v3/catalog.ts | 0 .../typescript/packages}/stack-prisma/src/v3/codec-runtime-v3.ts | 0 .../typescript/packages}/stack-prisma/src/v3/derive-schemas-v3.ts | 0 .../typescript/packages}/stack-prisma/src/v3/envelope-number.ts | 0 .../packages}/stack-prisma/src/v3/from-stack-v3-validate.ts | 0 .../typescript/packages}/stack-prisma/src/v3/operators-v3.ts | 0 .../typescript/packages}/stack-prisma/src/v3/query-term.ts | 0 .../typescript/packages}/stack-prisma/src/v3/runtime-v3.ts | 0 .../typescript/packages}/stack-prisma/src/v3/sdk-adapter-v3.ts | 0 .../typescript/packages}/stack-prisma/src/v3/wire-v3.ts | 0 .../typescript/packages}/stack-prisma/test/abort.test.ts | 0 .../typescript/packages}/stack-prisma/test/authoring.test.ts | 0 .../stack-prisma/test/bulk-encrypt-middleware.helpers.ts | 0 .../packages}/stack-prisma/test/bundling-isolation.test.ts | 0 .../typescript/packages}/stack-prisma/test/column-types.test.ts | 0 .../typescript/packages}/stack-prisma/test/decrypt-all.test.ts | 0 .../typescript/packages}/stack-prisma/test/descriptor.test.ts | 0 .../packages}/stack-prisma/test/envelope-bigint.test.ts | 0 .../packages}/stack-prisma/test/envelope-boolean.test.ts | 0 .../typescript/packages}/stack-prisma/test/envelope-date.test.ts | 0 .../typescript/packages}/stack-prisma/test/envelope-json.test.ts | 0 .../packages}/stack-prisma/test/envelope-string.test.ts | 0 .../packages}/stack-prisma/test/envelope.types.test-d.ts | 0 .../packages}/stack-prisma/test/equality-trait-removal.test.ts | 0 .../packages}/stack-prisma/test/live/bigint-live-pg.test.ts | 0 .../stack-prisma/test/live/boolean-storage-live-pg.test.ts | 0 .../packages}/stack-prisma/test/live/bulk-encrypt-live-pg.test.ts | 0 .../typescript/packages}/stack-prisma/test/live/helpers/eql-v3.ts | 0 .../packages}/stack-prisma/test/live/helpers/harness.ts | 0 .../packages}/stack-prisma/test/live/helpers/live-gate.ts | 0 .../stack-prisma/test/live/migration-apply-live-pg.test.ts | 0 .../packages}/stack-prisma/test/live/operators-live-pg.test.ts | 0 .../stack-prisma/test/live/operators-null-live-pg.test.ts | 0 .../packages}/stack-prisma/test/operation-types.types.test-d.ts | 0 .../packages}/stack-prisma/test/psl-interpretation.test.ts | 0 .../typescript/packages}/stack-prisma/test/routing.test.ts | 0 .../typescript/packages}/stack-prisma/test/sdk.types.test-d.ts | 0 .../packages}/stack-prisma/test/v3/bulk-encrypt-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/catalog-invariants.test.ts | 0 .../typescript/packages}/stack-prisma/test/v3/catalog.test.ts | 0 .../packages}/stack-prisma/test/v3/codec-runtime-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/codec-types-v3.test-d.ts | 0 .../packages}/stack-prisma/test/v3/column-types.test-d.ts | 0 .../packages}/stack-prisma/test/v3/constants-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/derive-schemas-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/envelope-number.test.ts | 0 .../stack-prisma/test/v3/from-stack-divergence-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/from-stack-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/migration-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/operator-gating-v3.test.ts | 0 .../stack-prisma/test/v3/operator-lowering-v3-equality.test.ts | 0 .../stack-prisma/test/v3/operator-lowering-v3-json.test.ts | 0 .../stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts | 0 .../stack-prisma/test/v3/operator-lowering-v3-text-search.test.ts | 0 .../stack-prisma/test/v3/operator-lowering-v3.helpers.ts | 0 .../typescript/packages}/stack-prisma/test/v3/properties.test.ts | 0 .../typescript/packages}/stack-prisma/test/v3/runtime-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/sdk-adapter-v3.test.ts | 0 .../packages}/stack-prisma/test/v3/stale-vendored-space.test.ts | 0 .../packages}/stack-prisma/test/v3/vendored-space-parity.test.ts | 0 .../typescript/packages}/stack-prisma/test/v3/wire-v3.test.ts | 0 .../typescript/packages}/stack-prisma/tsconfig.json | 0 .../typescript/packages}/stack-prisma/tsup.config.ts | 0 .../typescript/packages}/stack-prisma/turbo.json | 0 .../typescript/packages}/stack-prisma/vitest.config.ts | 0 .../typescript/packages}/stack-supabase/CHANGELOG.md | 0 .../typescript/packages}/stack-supabase/README.md | 0 .../stack-supabase/__tests__/browser-export-condition.test.ts | 0 .../stack-supabase/__tests__/column-map-predicate.test.ts | 0 .../packages}/stack-supabase/__tests__/helpers/postgrest-wire.ts | 0 .../packages}/stack-supabase/__tests__/helpers/supabase-mock.ts | 0 .../packages}/stack-supabase/__tests__/like-pattern.test.ts | 0 .../stack-supabase/__tests__/supabase-declared-mode.test.ts | 0 .../stack-supabase/__tests__/supabase-encryption-error.test.ts | 0 .../packages}/stack-supabase/__tests__/supabase-helpers.test.ts | 0 .../stack-supabase/__tests__/supabase-introspect.test.ts | 0 .../stack-supabase/__tests__/supabase-schema-builder.test.ts | 0 .../stack-supabase/__tests__/supabase-v3-builder.test.ts | 0 .../stack-supabase/__tests__/supabase-v3-factory.test.ts | 0 .../packages}/stack-supabase/__tests__/supabase-v3-json.test.ts | 0 .../packages}/stack-supabase/__tests__/supabase-v3-matrix.test.ts | 0 .../stack-supabase/__tests__/supabase-v3-select-star.test.ts | 0 .../packages}/stack-supabase/__tests__/supabase-v3-wire.test.ts | 0 .../packages}/stack-supabase/__tests__/supabase-v3.test-d.ts | 0 .../packages}/stack-supabase/__tests__/supabase-verify.test.ts | 0 .../stack-supabase/__tests__/supabase-wasm-config.test-d.ts | 0 .../stack-supabase/__tests__/wasm-client-adapter.test.ts | 0 .../stack-supabase/__tests__/wasm-entry-edge-safety.test.ts | 0 .../typescript/packages}/stack-supabase/integration/adapter.ts | 0 .../stack-supabase/integration/families.integration.test.ts | 0 .../stack-supabase/integration/grants.integration.test.ts | 0 .../packages}/stack-supabase/integration/helpers/pgrest.ts | 0 .../packages}/stack-supabase/integration/helpers/v3-envelope.ts | 0 .../stack-supabase/integration/introspect.integration.test.ts | 0 .../packages}/stack-supabase/integration/json.integration.test.ts | 0 .../stack-supabase/integration/select-alias.integration.test.ts | 0 .../packages}/stack-supabase/integration/vitest.config.ts | 0 .../packages}/stack-supabase/integration/wire.integration.test.ts | 0 .../typescript/packages}/stack-supabase/package.json | 0 .../typescript/packages}/stack-supabase/src/column-map.ts | 0 .../typescript/packages}/stack-supabase/src/create.ts | 0 .../typescript/packages}/stack-supabase/src/helpers.ts | 0 .../typescript/packages}/stack-supabase/src/index.ts | 0 .../typescript/packages}/stack-supabase/src/introspect.ts | 0 .../typescript/packages}/stack-supabase/src/like-pattern.ts | 0 .../typescript/packages}/stack-supabase/src/query-builder.ts | 0 .../typescript/packages}/stack-supabase/src/query-dbspace.ts | 0 .../typescript/packages}/stack-supabase/src/query-encrypt.ts | 0 .../typescript/packages}/stack-supabase/src/query-filters.ts | 0 .../typescript/packages}/stack-supabase/src/query-mutation.ts | 0 .../typescript/packages}/stack-supabase/src/query-results.ts | 0 .../typescript/packages}/stack-supabase/src/query-terms.ts | 0 .../typescript/packages}/stack-supabase/src/schema-builder.ts | 0 .../typescript/packages}/stack-supabase/src/types.ts | 0 .../typescript/packages}/stack-supabase/src/verify.ts | 0 .../packages}/stack-supabase/src/wasm-client-adapter.ts | 0 .../typescript/packages}/stack-supabase/src/wasm-inline.ts | 0 .../typescript/packages}/stack-supabase/tsconfig.json | 0 .../typescript/packages}/stack-supabase/tsconfig.typecheck.json | 0 .../typescript/packages}/stack-supabase/tsup.config.ts | 0 .../typescript/packages}/stack-supabase/turbo.json | 0 .../typescript/packages}/stack-supabase/vitest.config.ts | 0 {packages => languages/typescript/packages}/stack/CHANGELOG.md | 0 {packages => languages/typescript/packages}/stack/README.md | 0 .../typescript/packages}/stack/__tests__/audit.test.ts | 0 .../packages}/stack/__tests__/auth-failure-propagation.test.ts | 0 .../typescript/packages}/stack/__tests__/auth-reexports.test.ts | 0 .../typescript/packages}/stack/__tests__/basic-protect.test.ts | 0 .../packages}/stack/__tests__/browser-export-condition.test.ts | 0 .../packages}/stack/__tests__/bulk-decrypt-item-failure.test.ts | 0 .../packages}/stack/__tests__/bulk-encrypt-validation.test.ts | 0 .../packages}/stack/__tests__/bulk-model-hyphen-fields.test.ts | 0 .../typescript/packages}/stack/__tests__/bulk-protect.test.ts | 0 .../typescript/packages}/stack/__tests__/cjs-require.test.ts | 0 .../typescript/packages}/stack/__tests__/clerk-provider.test.ts | 0 .../packages}/stack/__tests__/client-get-schemas.test.ts | 0 .../typescript/packages}/stack/__tests__/config.test.ts | 0 .../packages}/stack/__tests__/decrypt-audit-forwarding.test.ts | 0 .../packages}/stack/__tests__/diagnostics-entry.test.ts | 0 .../packages}/stack/__tests__/dynamodb/client-compat.test-d.ts | 0 .../packages}/stack/__tests__/dynamodb/construct-guard.test.ts | 0 .../stack/__tests__/dynamodb/encrypted-dynamodb-v3.test.ts | 0 .../packages}/stack/__tests__/dynamodb/helpers-v3.test.ts | 0 .../packages}/stack/__tests__/dynamodb/hmac-domains.test.ts | 0 .../packages}/stack/__tests__/dynamodb/properties.test.ts | 0 .../packages}/stack/__tests__/dynamodb/resolve-decrypt.test.ts | 0 .../packages}/stack/__tests__/dynamodb/v2-grouped-date.test.ts | 0 .../stack/__tests__/dynamodb/v2-table-forwarding.test.ts | 0 .../packages}/stack/__tests__/dynamodb/v2-type-coverage.test.ts | 0 .../packages}/stack/__tests__/empty-schemas-boundary.test.ts | 0 .../packages}/stack/__tests__/encrypt-lock-context-guards.test.ts | 0 .../stack/__tests__/encrypt-query-match-preflight.test.ts | 0 .../stack/__tests__/encrypt-query-searchable-json.test.ts | 0 .../packages}/stack/__tests__/encrypt-query-stevec.test.ts | 0 .../typescript/packages}/stack/__tests__/encrypt-query.test.ts | 0 .../packages}/stack/__tests__/encryption-helpers.test.ts | 0 .../packages}/stack/__tests__/encryption-v3-only.test-d.ts | 0 .../stack/__tests__/eql-v3-capability-matrix-skill.test.ts | 0 .../packages}/stack/__tests__/eql-v3-domain-registry.test.ts | 0 .../typescript/packages}/stack/__tests__/error-codes.test.ts | 0 .../packages}/stack/__tests__/error-discriminated-union.test-d.ts | 0 .../typescript/packages}/stack/__tests__/error-helpers.test.ts | 0 .../packages}/stack/__tests__/fixtures-query-contract.test.ts | 0 .../typescript/packages}/stack/__tests__/fixtures/index.ts | 0 .../typescript/packages}/stack/__tests__/helpers.test.ts | 0 .../typescript/packages}/stack/__tests__/helpers/expect-result.ts | 0 .../packages}/stack/__tests__/helpers/process-free-realm.mjs | 0 .../packages}/stack/__tests__/helpers/stub-auth-wasm-inline.ts | 0 .../stack/__tests__/helpers/stub-protect-ffi-wasm-inline.ts | 0 .../packages}/stack/__tests__/identify-cts-refusal.test.ts | 0 .../typescript/packages}/stack/__tests__/infer-index-type.test.ts | 0 .../typescript/packages}/stack/__tests__/init-strategy.test.ts | 0 .../typescript/packages}/stack/__tests__/jsonb-helpers.test.ts | 0 .../typescript/packages}/stack/__tests__/keysets.test.ts | 0 .../packages}/stack/__tests__/lock-context-wiring.test.ts | 0 .../typescript/packages}/stack/__tests__/lock-context.test.ts | 0 .../packages}/stack/__tests__/logger-edge-safety.test.ts | 0 .../typescript/packages}/stack/__tests__/match-bloom-live.test.ts | 0 .../packages}/stack/__tests__/match-needle-guard.test.ts | 0 .../packages}/stack/__tests__/model-column-mapping.test.ts | 0 .../typescript/packages}/stack/__tests__/null-guards.test.ts | 0 .../stack/__tests__/operation-failure-diagnostics.test.ts | 0 .../typescript/packages}/stack/__tests__/protect-ops.test.ts | 0 .../typescript/packages}/stack/__tests__/readme-sync.test.ts | 0 .../packages}/stack/__tests__/resolve-lock-context.test.ts | 0 .../typescript/packages}/stack/__tests__/schema-v3.test.ts | 0 .../typescript/packages}/stack/__tests__/selector-path.test.ts | 0 .../packages}/stack/__tests__/subpath-types-parity.test.ts | 0 .../typescript/packages}/stack/__tests__/test-kit-env.test.ts | 0 .../packages}/stack/__tests__/test-kit-families.test.ts | 0 .../packages}/stack/__tests__/test-kit-v2-fixtures.test.ts | 0 .../packages}/stack/__tests__/typed-client-v3.test-d.ts | 0 .../typescript/packages}/stack/__tests__/typed-client-v3.test.ts | 0 .../packages}/stack/__tests__/types-public-surface.test-d.ts | 0 .../typescript/packages}/stack/__tests__/v3-matrix/catalog.ts | 0 .../packages}/stack/__tests__/v3-matrix/matrix-audit.test-d.ts | 0 .../stack/__tests__/v3-matrix/matrix-lock-context.test.ts | 0 .../packages}/stack/__tests__/v3-matrix/matrix.test-d.ts | 0 .../typescript/packages}/stack/__tests__/v3-matrix/matrix.test.ts | 0 .../packages}/stack/__tests__/v3-matrix/needle-for.test.ts | 0 .../packages}/stack/__tests__/v3-only-public-surface.test.ts | 0 .../packages}/stack/__tests__/wasm-inline-auth-failure.test.ts | 0 .../typescript/packages}/stack/__tests__/wasm-inline-bulk.test.ts | 0 .../stack/__tests__/wasm-inline-bundle-isolation.test.ts | 0 .../packages}/stack/__tests__/wasm-inline-column-name.test.ts | 0 .../stack/__tests__/wasm-inline-core-credential-contract.test.ts | 0 .../packages}/stack/__tests__/wasm-inline-models.test.ts | 0 .../packages}/stack/__tests__/wasm-inline-new-client.test.ts | 0 .../packages}/stack/__tests__/wasm-inline-normalize.test.ts | 0 .../packages}/stack/__tests__/wasm-inline-query.test.ts | 0 .../packages}/stack/__tests__/wasm-inline-result-contract.test.ts | 0 .../packages}/stack/__tests__/wasm-inline-schemas.test-d.ts | 0 .../packages}/stack/__tests__/wasm-inline-strategy.test.ts | 0 .../typescript/packages}/stack/__tests__/wasm-inline-v3.test.ts | 0 .../typescript/packages}/stack/__tests__/wasm-plaintext.test-d.ts | 0 .../typescript/packages}/stack/dist-types/README.md | 0 .../typescript/packages}/stack/dist-types/encrypt-query.ts | 0 .../packages}/stack/dist-types/node16/encrypt-query.cts | 0 .../packages}/stack/dist-types/node16/encrypt-query.mts | 0 .../typescript/packages}/stack/dist-types/node16/tsconfig.json | 0 .../typescript/packages}/stack/dist-types/node16/wasm-inline.mts | 0 .../typescript/packages}/stack/dist-types/schemas-and-config.ts | 0 .../typescript/packages}/stack/dist-types/tsconfig.json | 0 .../packages}/stack/dist-types/wasm-inline-type-identity.ts | 0 .../integration/identity/matrix-identity.integration.test.ts | 0 .../stack/integration/shared/harness.integration.test.ts | 0 .../stack/integration/shared/json-crypto.integration.test.ts | 0 .../stack/integration/shared/match-bloom.integration.test.ts | 0 .../stack/integration/shared/matrix-bulk.integration.test.ts | 0 .../stack/integration/shared/matrix-crypto.integration.test.ts | 0 .../stack/integration/shared/matrix-keyset.integration.test.ts | 0 .../stack/integration/shared/matrix-sql.integration.test.ts | 0 .../stack/integration/shared/ope-term.integration.test.ts | 0 .../stack/integration/shared/schema-pg.integration.test.ts | 0 .../stack/integration/shared/schema-v3-client.integration.test.ts | 0 .../integration/shared/v2-decrypt-compat.integration.test.ts | 0 .../typescript/packages}/stack/integration/vitest.config.ts | 0 .../typescript/packages}/stack/integration/wasm/adapter.ts | 0 .../packages}/stack/integration/wasm/families.integration.test.ts | 0 .../stack/integration/wasm/v2-decrypt-compat.integration.test.ts | 0 {packages => languages/typescript/packages}/stack/package.json | 0 .../typescript/packages}/stack/scripts/install-eql-v3.ts | 0 .../typescript/packages}/stack/src/adapter-kit.ts | 0 .../typescript/packages}/stack/src/diagnostics.ts | 0 .../typescript/packages}/stack/src/dynamodb/helpers.ts | 0 .../typescript/packages}/stack/src/dynamodb/index.ts | 0 .../packages}/stack/src/dynamodb/operations/base-operation.ts | 0 .../stack/src/dynamodb/operations/bulk-decrypt-models.ts | 0 .../stack/src/dynamodb/operations/bulk-encrypt-models.ts | 0 .../packages}/stack/src/dynamodb/operations/decrypt-model.ts | 0 .../packages}/stack/src/dynamodb/operations/encrypt-model.ts | 0 .../typescript/packages}/stack/src/dynamodb/types.ts | 0 .../typescript/packages}/stack/src/encryption/client-v3.ts | 0 .../packages}/stack/src/encryption/helpers/auth-failure.ts | 0 .../packages}/stack/src/encryption/helpers/error-code.ts | 0 .../typescript/packages}/stack/src/encryption/helpers/index.ts | 0 .../packages}/stack/src/encryption/helpers/infer-index-type.ts | 0 .../typescript/packages}/stack/src/encryption/helpers/jsonb.ts | 0 .../packages}/stack/src/encryption/helpers/model-helpers.ts | 0 .../packages}/stack/src/encryption/helpers/model-traversal.ts | 0 .../packages}/stack/src/encryption/helpers/type-guards.ts | 0 .../packages}/stack/src/encryption/helpers/validation.ts | 0 .../typescript/packages}/stack/src/encryption/index.ts | 0 .../packages}/stack/src/encryption/operations/base-operation.ts | 0 .../stack/src/encryption/operations/batch-encrypt-query.ts | 0 .../stack/src/encryption/operations/bulk-decrypt-models.ts | 0 .../packages}/stack/src/encryption/operations/bulk-decrypt.ts | 0 .../stack/src/encryption/operations/bulk-encrypt-models.ts | 0 .../packages}/stack/src/encryption/operations/bulk-encrypt.ts | 0 .../packages}/stack/src/encryption/operations/decrypt-model.ts | 0 .../packages}/stack/src/encryption/operations/decrypt.ts | 0 .../packages}/stack/src/encryption/operations/encrypt-model.ts | 0 .../packages}/stack/src/encryption/operations/encrypt-query.ts | 0 .../packages}/stack/src/encryption/operations/encrypt.ts | 0 .../packages}/stack/src/encryption/operations/mapped-decrypt.ts | 0 .../typescript/packages}/stack/src/encryption/v3.ts | 0 .../typescript/packages}/stack/src/eql/v3/columns.ts | 0 .../typescript/packages}/stack/src/eql/v3/date-reconstruction.ts | 0 .../typescript/packages}/stack/src/eql/v3/domain-registry.ts | 0 .../typescript/packages}/stack/src/eql/v3/index.ts | 0 .../typescript/packages}/stack/src/eql/v3/selector-path.ts | 0 .../typescript/packages}/stack/src/eql/v3/table.ts | 0 .../typescript/packages}/stack/src/eql/v3/types.ts | 0 .../typescript/packages}/stack/src/errors/index.ts | 0 .../typescript/packages}/stack/src/identity/index.ts | 0 {packages => languages/typescript/packages}/stack/src/index.ts | 0 .../typescript/packages}/stack/src/schema/index.ts | 0 .../typescript/packages}/stack/src/schema/internal.ts | 0 .../typescript/packages}/stack/src/schema/match-defaults.ts | 0 .../typescript/packages}/stack/src/types-public.ts | 0 {packages => languages/typescript/packages}/stack/src/types.ts | 0 .../typescript/packages}/stack/src/utils/config/index.ts | 0 .../typescript/packages}/stack/src/utils/logger/index.ts | 0 .../typescript/packages}/stack/src/wasm-inline.ts | 0 {packages => languages/typescript/packages}/stack/tsconfig.json | 0 .../typescript/packages}/stack/tsconfig.typecheck.json | 0 {packages => languages/typescript/packages}/stack/tsup.config.ts | 0 {packages => languages/typescript/packages}/stack/turbo.json | 0 .../typescript/packages}/stack/vitest.config.ts | 0 .../typescript/packages}/stack/vitest.wasm-core.config.ts | 0 {packages => languages/typescript/packages}/test-kit/CHANGELOG.md | 0 {packages => languages/typescript/packages}/test-kit/package.json | 0 .../typescript/packages}/test-kit/src/__tests__/install.test.ts | 0 .../typescript/packages}/test-kit/src/adapter.ts | 0 .../typescript/packages}/test-kit/src/catalog.ts | 0 {packages => languages/typescript/packages}/test-kit/src/env.ts | 0 .../typescript/packages}/test-kit/src/families.ts | 0 {packages => languages/typescript/packages}/test-kit/src/index.ts | 0 .../typescript/packages}/test-kit/src/install.ts | 0 .../typescript/packages}/test-kit/src/integration/clerk.ts | 0 .../typescript/packages}/test-kit/src/integration/config.ts | 0 .../typescript/packages}/test-kit/src/integration/global-setup.ts | 0 .../packages}/test-kit/src/integration/no-skips-reporter.ts | 0 .../typescript/packages}/test-kit/src/json-adapter.ts | 0 .../typescript/packages}/test-kit/src/needle-for.ts | 0 {packages => languages/typescript/packages}/test-kit/src/ops.ts | 0 .../typescript/packages}/test-kit/src/oracle.ts | 0 .../typescript/packages}/test-kit/src/results.ts | 0 {packages => languages/typescript/packages}/test-kit/src/rows.ts | 0 .../typescript/packages}/test-kit/src/run-family-suite.ts | 0 .../typescript/packages}/test-kit/src/run-json-suite.ts | 0 .../typescript/packages}/test-kit/src/v2-fixtures.ts | 0 .../typescript/packages}/test-kit/tsconfig.json | 0 {packages => languages/typescript/packages}/utils/config/index.ts | 0 {packages => languages/typescript/packages}/utils/logger/index.ts | 0 {packages => languages/typescript/packages}/wizard/CHANGELOG.md | 0 {packages => languages/typescript/packages}/wizard/README.md | 0 {packages => languages/typescript/packages}/wizard/package.json | 0 .../typescript/packages}/wizard/src/__tests__/agent-sdk.test.ts | 0 .../packages}/wizard/src/__tests__/commandments.test.ts | 0 .../typescript/packages}/wizard/src/__tests__/detect.test.ts | 0 .../packages}/wizard/src/__tests__/errors-runner.test.ts | 0 .../typescript/packages}/wizard/src/__tests__/format.test.ts | 0 .../packages}/wizard/src/__tests__/gateway-messages.test.ts | 0 .../packages}/wizard/src/__tests__/health-checks.test.ts | 0 .../typescript/packages}/wizard/src/__tests__/hooks.test.ts | 0 .../packages}/wizard/src/__tests__/install-skills.test.ts | 0 .../typescript/packages}/wizard/src/__tests__/interface.test.ts | 0 .../typescript/packages}/wizard/src/__tests__/parse-args.test.ts | 0 .../typescript/packages}/wizard/src/__tests__/post-agent.test.ts | 0 .../packages}/wizard/src/__tests__/prerequisites.test.ts | 0 .../packages}/wizard/src/__tests__/rewrite-migrations.test.ts | 0 .../packages}/wizard/src/__tests__/wizard-tools.test.ts | 0 .../packages}/wizard/src/agent/__tests__/interface.test.ts | 0 .../typescript/packages}/wizard/src/agent/commandments.ts | 0 .../typescript/packages}/wizard/src/agent/errors.ts | 0 .../typescript/packages}/wizard/src/agent/fetch-prompt.ts | 0 .../typescript/packages}/wizard/src/agent/hooks.ts | 0 .../typescript/packages}/wizard/src/agent/interface.ts | 0 .../typescript/packages}/wizard/src/bin/parse-args.ts | 0 .../typescript/packages}/wizard/src/bin/wizard.ts | 0 .../typescript/packages}/wizard/src/health-checks/index.ts | 0 .../typescript/packages}/wizard/src/lib/analytics.ts | 0 .../typescript/packages}/wizard/src/lib/changelog.ts | 0 .../typescript/packages}/wizard/src/lib/constants.ts | 0 .../typescript/packages}/wizard/src/lib/detect.ts | 0 .../typescript/packages}/wizard/src/lib/format.ts | 0 .../typescript/packages}/wizard/src/lib/gather.ts | 0 .../typescript/packages}/wizard/src/lib/install-skills.ts | 0 .../typescript/packages}/wizard/src/lib/post-agent.ts | 0 .../typescript/packages}/wizard/src/lib/prerequisites.ts | 0 .../typescript/packages}/wizard/src/lib/rewrite-migrations.ts | 0 .../typescript/packages}/wizard/src/lib/types.ts | 0 .../typescript/packages}/wizard/src/lib/wire-call-sites.ts | 0 {packages => languages/typescript/packages}/wizard/src/run.ts | 0 .../typescript/packages}/wizard/src/tools/wizard-tools.ts | 0 {packages => languages/typescript/packages}/wizard/tsconfig.json | 0 {packages => languages/typescript/packages}/wizard/tsup.config.ts | 0 1017 files changed, 0 insertions(+), 0 deletions(-) rename {examples => languages/typescript/examples}/basic/CHANGELOG.md (100%) rename {examples => languages/typescript/examples}/basic/README.md (100%) rename {examples => languages/typescript/examples}/basic/encrypt.ts (100%) rename {examples => languages/typescript/examples}/basic/index.ts (100%) rename {examples => languages/typescript/examples}/basic/package.json (100%) rename {examples => languages/typescript/examples}/basic/src/encryption/index.ts (100%) rename {examples => languages/typescript/examples}/basic/stash.config.ts (100%) rename {examples => languages/typescript/examples}/basic/tsconfig.json (100%) rename {examples => languages/typescript/examples}/prisma/.env.example (100%) rename {examples => languages/typescript/examples}/prisma/CHANGELOG.md (100%) rename {examples => languages/typescript/examples}/prisma/README.md (100%) rename {examples => languages/typescript/examples}/prisma/docker-compose.yml (100%) rename {examples => languages/typescript/examples}/prisma/migrations/app/20260714T2142_initial/migration.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/app/20260714T2142_initial/migration.ts (100%) rename {examples => languages/typescript/examples}/prisma/migrations/app/20260714T2142_initial/ops.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/migration.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/ops.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/migration.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/ops.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/migration.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/ops.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/migration.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/ops.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/migration.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/ops.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/cipherstash/refs/head.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts (100%) rename {examples => languages/typescript/examples}/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json (100%) rename {examples => languages/typescript/examples}/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.d.ts (100%) rename {examples => languages/typescript/examples}/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.json (100%) rename {examples => languages/typescript/examples}/prisma/package.json (100%) rename {examples => languages/typescript/examples}/prisma/prisma-next.config.ts (100%) rename {examples => languages/typescript/examples}/prisma/prisma/schema.prisma (100%) rename {examples => languages/typescript/examples}/prisma/src/db.ts (100%) rename {examples => languages/typescript/examples}/prisma/src/index.ts (100%) rename {examples => languages/typescript/examples}/prisma/src/prisma/contract.d.ts (100%) rename {examples => languages/typescript/examples}/prisma/src/prisma/contract.json (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/README.md (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/bigint.e2e.test.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/bool.e2e.test.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/date.e2e.test.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/docker-compose.yml (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/global-setup.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/harness.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/json.e2e.test.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/mixed.e2e.test.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/num.e2e.test.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/str-range.e2e.test.ts (100%) rename {examples => languages/typescript/examples}/prisma/test/e2e/vitest.config.ts (100%) rename {examples => languages/typescript/examples}/prisma/tsconfig.json (100%) rename {examples => languages/typescript/examples}/supabase-worker/.env.example (100%) rename {examples => languages/typescript/examples}/supabase-worker/README.md (100%) rename {examples => languages/typescript/examples}/supabase-worker/package.json (100%) rename {examples => languages/typescript/examples}/supabase-worker/supabase/functions/cipherstash-roundtrip/index.ts (100%) rename {packages => languages/typescript/packages}/bench/.gitignore (100%) rename {packages => languages/typescript/packages}/bench/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/bench/README.md (100%) rename {packages => languages/typescript/packages}/bench/__benches__/drizzle/operators.bench.ts (100%) rename {packages => languages/typescript/packages}/bench/__tests__/db-only.test.ts (100%) rename {packages => languages/typescript/packages}/bench/__tests__/drizzle/operators.explain.test.ts (100%) rename {packages => languages/typescript/packages}/bench/__tests__/harness.test.ts (100%) rename {packages => languages/typescript/packages}/bench/__unit__/seed-keys.test.ts (100%) rename {packages => languages/typescript/packages}/bench/package.json (100%) rename {packages => languages/typescript/packages}/bench/sql/schema.sql (100%) rename {packages => languages/typescript/packages}/bench/src/cli/reset.ts (100%) rename {packages => languages/typescript/packages}/bench/src/cli/setup.ts (100%) rename {packages => languages/typescript/packages}/bench/src/drizzle/setup.ts (100%) rename {packages => languages/typescript/packages}/bench/src/harness/db.ts (100%) rename {packages => languages/typescript/packages}/bench/src/harness/explain.ts (100%) rename {packages => languages/typescript/packages}/bench/src/harness/global-setup.ts (100%) rename {packages => languages/typescript/packages}/bench/src/harness/seed.ts (100%) rename {packages => languages/typescript/packages}/bench/tsconfig.json (100%) rename {packages => languages/typescript/packages}/bench/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/bench/vitest.unit.config.ts (100%) rename {packages => languages/typescript/packages}/cli/AGENTS.md (100%) rename {packages => languages/typescript/packages}/cli/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/cli/README.md (100%) rename {packages => languages/typescript/packages}/cli/__fixtures__/scaffold/drizzle.generated.ts (100%) rename {packages => languages/typescript/packages}/cli/__fixtures__/scaffold/generic.generated.ts (100%) rename {packages => languages/typescript/packages}/cli/package.json (100%) rename {packages => languages/typescript/packages}/cli/scripts/e2e-encrypt.sh (100%) rename {packages => languages/typescript/packages}/cli/scripts/fixtures/seed-users.sql (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/config-jiti-integration.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/config.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/database-url.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/detect.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/installer.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/module-error-classification.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/native.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/placeholder-guard-parity.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/release-train.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/rewrite-migrations.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/runtime-versions.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/skill-supabase-apply.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/__tests__/v2-retirement.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/bin/main.ts (100%) rename {packages => languages/typescript/packages}/cli/src/bin/stash.ts (100%) rename {packages => languages/typescript/packages}/cli/src/cli/__tests__/help.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/cli/__tests__/manifest.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/cli/exit.ts (100%) rename {packages => languages/typescript/packages}/cli/src/cli/help.ts (100%) rename {packages => languages/typescript/packages}/cli/src/cli/manifest.ts (100%) rename {packages => languages/typescript/packages}/cli/src/cli/registry.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/__tests__/failure.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/__tests__/index.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/__tests__/login.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/__tests__/region.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/events.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/failure.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/login.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/auth/region.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/__tests__/config-scaffold.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/__tests__/find-generated-migration.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/__tests__/install-verify-gate.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/__tests__/install.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/__tests__/preflight.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/__tests__/prisma-next-install-guard.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/__tests__/status.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/__tests__/upgrade.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/client-scaffold.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/config-scaffold.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/detect.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/grants-report.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/install.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/preflight.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/resolve-diagnostic-url.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/rewrite-migrations.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/status.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/test-connection.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/db/upgrade.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/doctor/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/__tests__/backfill-target.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/__tests__/context-placeholder.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/__tests__/encrypt-v3.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/__tests__/prisma-next-context.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/backfill.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/context.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/drizzle-helper.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/drop.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/lib/__tests__/resolve-eql.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/lib/db-readers.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/lib/resolve-eql.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/plan.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/encrypt/status.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/env/__tests__/env.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/env/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/__tests__/applied.live.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/__tests__/migration.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/__tests__/repair.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/__tests__/supabase-migration.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/__tests__/supabase-push.live.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/__tests__/validate-command.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/__tests__/validate.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/applied.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/journal.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/migration.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/repair.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/supabase-migration.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/sweep-report.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/validate.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/eql/verify.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/__tests__/how-to-proceed.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/__tests__/impl.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/__tests__/handoff-agents-md.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/__tests__/handoff-claude.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/__tests__/handoff-codex.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/__tests__/handoff-lovable.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/__tests__/how-to-proceed-dispatch.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/handoff-agents-md.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/handoff-claude.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/handoff-codex.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/handoff-lovable.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/handoff-wizard.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/impl/steps/how-to-proceed.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/__tests__/detect-agents.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/__tests__/init-command.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/__tests__/placeholder-client-fixture.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/__tests__/sentinel-upsert.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/__tests__/steps-wiring.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/__tests__/utils-codegen-drizzle.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/__tests__/utils-codegen.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/__tests__/utils.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/detect-agents.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/doctrine/AGENTS-doctrine.md (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/build-agents-md.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/build-flow.integration.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/handoff-helpers.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/install-skills.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/introspect.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/parse-plan.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/read-context.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/rollout-state.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/__tests__/write-context.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/build-agents-md.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/bundled-paths.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/env-keys.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/handoff-helpers.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/install-skills.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/introspect.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/parse-plan.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/read-context.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/rollout-state.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/sentinel-upsert.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/setup-prompt.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/lib/write-context.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/providers/__tests__/base.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/providers/__tests__/drizzle.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/providers/__tests__/prisma.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/providers/__tests__/supabase.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/providers/base.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/providers/drizzle.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/providers/prisma.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/providers/supabase.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/__tests__/build-schema.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/__tests__/install-deps.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/__tests__/install-eql.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/__tests__/install-skills.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/__tests__/resolve-database.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/authenticate.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/build-schema.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/gather-context.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/install-deps.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/install-eql.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/install-skills.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/steps/resolve-database.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/types.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/init/utils.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/manifest/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/plan/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/schema/build.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/status/__tests__/status.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/status/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/status/quest.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/status/render.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/telemetry/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/wizard/__tests__/index.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/commands/wizard/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/config/__tests__/load-encrypt-schemas.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/config/__tests__/missing-package.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/config/__tests__/tty.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/config/database-url.ts (100%) rename {packages => languages/typescript/packages}/cli/src/config/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/config/missing-package.ts (100%) rename {packages => languages/typescript/packages}/cli/src/config/tty.ts (100%) rename {packages => languages/typescript/packages}/cli/src/db/__tests__/client-wrap.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/db/__tests__/config.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/db/__tests__/no-sslmode-advisory.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/db/__tests__/pg-construction-lint.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/db/client.ts (100%) rename {packages => languages/typescript/packages}/cli/src/db/config.ts (100%) rename {packages => languages/typescript/packages}/cli/src/db/supabase-ca.ts (100%) rename {packages => languages/typescript/packages}/cli/src/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/bundle-digest.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/guarded-grants.live.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/installation-state.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/ore.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/preflight.live.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/reinstall.live.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/restoration-scenarios.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/upgrade-encrypted-indexes.live.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/verify.live.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/__tests__/verify.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/bundle-digest.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/derived-search-index-restoration.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/eql-bundle.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/grants.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/installation-state.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/ore.ts (100%) rename {packages => languages/typescript/packages}/cli/src/installer/verify.ts (100%) rename {packages => languages/typescript/packages}/cli/src/messages.ts (100%) rename {packages => languages/typescript/packages}/cli/src/module-error.ts (100%) rename {packages => languages/typescript/packages}/cli/src/native.ts (100%) rename {packages => languages/typescript/packages}/cli/src/release-train.ts (100%) rename {packages => languages/typescript/packages}/cli/src/runtime-versions.ts (100%) rename {packages => languages/typescript/packages}/cli/src/telemetry/__tests__/classify-command.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/telemetry/__tests__/state.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/telemetry/__tests__/telemetry-lifecycle.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/telemetry/__tests__/telemetry.test.ts (100%) rename {packages => languages/typescript/packages}/cli/src/telemetry/classify-command.ts (100%) rename {packages => languages/typescript/packages}/cli/src/telemetry/index.ts (100%) rename {packages => languages/typescript/packages}/cli/src/telemetry/state.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/auth-login-cancel.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/auth-non-interactive.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/command-help.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/config-scaffold.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/database-url.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/doctor-missing-binary.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/doctor-probe-classification.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/doctor.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/env-non-interactive.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/eql-install-prisma-next.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/eql-repair.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/impl-non-tty.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/impl-pty-ci.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/manifest.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/plan-complete-rollout.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/plan-outcome.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/runner-aware-help.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/runtime-versions-embed.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/smoke.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/e2e/v2-retirement.e2e.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/helpers/pty.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/helpers/run.test.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/helpers/run.ts (100%) rename {packages => languages/typescript/packages}/cli/tests/helpers/spawn-piped.ts (100%) rename {packages => languages/typescript/packages}/cli/tsconfig.json (100%) rename {packages => languages/typescript/packages}/cli/tsconfig.scaffold.json (100%) rename {packages => languages/typescript/packages}/cli/tsup.config.ts (100%) rename {packages => languages/typescript/packages}/cli/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/cli/vitest.integration.config.ts (100%) rename {packages => languages/typescript/packages}/migrate/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/migrate/README.md (100%) rename {packages => languages/typescript/packages}/migrate/package.json (100%) rename {packages => languages/typescript/packages}/migrate/src/__tests__/backfill-v3.integration.test.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/__tests__/backfill.integration.test.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/__tests__/manifest.test.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/__tests__/sql.test.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/__tests__/state.test.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/__tests__/v2-retirement.test.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/__tests__/version.test.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/backfill.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/cursor.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/index.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/install.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/manifest.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/sql.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/state.ts (100%) rename {packages => languages/typescript/packages}/migrate/src/version.ts (100%) rename {packages => languages/typescript/packages}/migrate/tsconfig.json (100%) rename {packages => languages/typescript/packages}/migrate/tsup.config.ts (100%) rename {packages => languages/typescript/packages}/migrate/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/nextjs/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/nextjs/README.md (100%) rename {packages => languages/typescript/packages}/nextjs/__tests__/cts-refusal.test.ts (100%) rename {packages => languages/typescript/packages}/nextjs/__tests__/nextjs.test.ts (100%) rename {packages => languages/typescript/packages}/nextjs/package.json (100%) rename {packages => languages/typescript/packages}/nextjs/src/clerk/index.ts (100%) rename {packages => languages/typescript/packages}/nextjs/src/cts/index.ts (100%) rename {packages => languages/typescript/packages}/nextjs/src/index.ts (100%) rename {packages => languages/typescript/packages}/nextjs/tsconfig.jest.json (100%) rename {packages => languages/typescript/packages}/nextjs/tsconfig.json (100%) rename {packages => languages/typescript/packages}/nextjs/tsup.config.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/.gitignore (100%) rename {packages => languages/typescript/packages}/protect-ffi/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/Cargo.lock (100%) rename {packages => languages/typescript/packages}/protect-ffi/Cargo.toml (100%) rename {packages => languages/typescript/packages}/protect-ffi/LICENSE.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/README.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/crates/protect-ffi/Cargo.toml (100%) rename {packages => languages/typescript/packages}/protect-ffi/crates/protect-ffi/src/client_options.rs (100%) rename {packages => languages/typescript/packages}/protect-ffi/crates/protect-ffi/src/encrypt_config.rs (100%) rename {packages => languages/typescript/packages}/protect-ffi/crates/protect-ffi/src/eql_v3.rs (100%) rename {packages => languages/typescript/packages}/protect-ffi/crates/protect-ffi/src/js_plaintext.rs (100%) rename {packages => languages/typescript/packages}/protect-ffi/crates/protect-ffi/src/lib.rs (100%) rename {packages => languages/typescript/packages}/protect-ffi/crates/protect-ffi/src/query_op.rs (100%) rename {packages => languages/typescript/packages}/protect-ffi/crates/protect-ffi/src/wasm.rs (100%) rename {packages => languages/typescript/packages}/protect-ffi/dist/wasm/errors.d.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/dist/wasm/protect_ffi.d.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/dist/wasm/protect_ffi_bg.wasm.d.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/docs/canonical-encryption-config-migration.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/docs/jsonb-api-reference.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/docs/jsonb-integration.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/docs/jsonb-troubleshooting.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/docker-compose.yml (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/package.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/sql/.gitkeep (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tasks.toml (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/common.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/dates.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/encrypt-config.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/eql-v3.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/error-stack.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/event-loop-exit.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-auto.cjs (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-jsbacked.cjs (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/js-strategy.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/json-bulk.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/json-containment.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/json.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/keyset.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/lock-context.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/oidc-federation.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/postgres-v3.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/postgres.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/query.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/scalar-bulk.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/scalar.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/strict-options.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/wasm-error-codes.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tests/wasm-round-trip.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/tsconfig.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/integration-tests/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/mise.toml (100%) rename {packages => languages/typescript/packages}/protect-ffi/package.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/darwin-arm64/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/darwin-arm64/README.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/darwin-arm64/package.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/darwin-x64/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/darwin-x64/README.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/darwin-x64/package.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-arm64-gnu/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-arm64-gnu/README.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-arm64-gnu/package.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-x64-gnu/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-x64-gnu/README.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-x64-gnu/package.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-x64-musl/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-x64-musl/README.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/linux-x64-musl/package.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/win32-x64-msvc/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/win32-x64-msvc/README.md (100%) rename {packages => languages/typescript/packages}/protect-ffi/platforms/win32-x64-msvc/package.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/scripts/changelog-extract.mjs (100%) rename {packages => languages/typescript/packages}/protect-ffi/scripts/inline-wasm.mjs (100%) rename {packages => languages/typescript/packages}/protect-ffi/scripts/sync-eql-v3-types.sh (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/bigintWire.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/bigintWire.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/credentials.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Bigint.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BigintEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BigintEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BigintOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BigintOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BigintOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BigintOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BigintOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BigintOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/BloomFilter.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Boolean.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Ciphertext.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Date.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DateEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DateEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DateOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DateOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DateOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DateOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DateOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DateOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Double.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DoubleEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DoubleEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DoubleOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DoubleOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DoubleOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DoubleOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DoubleOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/DoubleOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/EntryCiphertext.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Hmac256.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Identifier.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Integer.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/IntegerEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/IntegerEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/IntegerOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/IntegerOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/IntegerOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/IntegerOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/IntegerOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/IntegerOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Json.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/KeyHeader.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Numeric.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/NumericEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/NumericEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/NumericOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/NumericOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/NumericOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/NumericOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/NumericOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/NumericOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/OpeCllw.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/OreBlock256.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Real.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/RealEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/RealEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/RealOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/RealOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/RealOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/RealOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/RealOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/RealOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SchemaVersion.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Selector.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Smallint.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SmallintEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SmallintEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SmallintOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SmallintOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SmallintOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SmallintOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SmallintOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SmallintOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SteVecDocument.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SteVecEntry.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SteVecForm.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SteVecQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/SteVecQueryEntry.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Text.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextMatch.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextMatchQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextSearch.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextSearchOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextSearchOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TextSearchQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/Timestamp.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TimestampEq.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TimestampEqQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TimestampOrd.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TimestampOrdOpe.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TimestampOrdOpeQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TimestampOrdOre.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TimestampOrdOreQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3-types/TimestampOrdQuery.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/eql-v3.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/errorCodes.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/errors.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/errors.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/index.cts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/index.mts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/index.types.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/integrationSuiteCi.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/lintWiring.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/load.cts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/nativeLoading.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/newClientArgs.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/newClientArgs.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/types.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/src/withEnvCredentials.test.ts (100%) rename {packages => languages/typescript/packages}/protect-ffi/tsconfig.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/tsconfig.test.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/tsconfig.wasm-errors.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/type-tests/tsconfig.json (100%) rename {packages => languages/typescript/packages}/protect-ffi/type-tests/wasm.test-d.mts (100%) rename {packages => languages/typescript/packages}/protect-ffi/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/stack-drizzle/README.md (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/bigint.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/codec.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/column.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/exports.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/indexes.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/operators.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/operators.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/schema-extraction.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/schema-extraction.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/selector.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/sql-dialect.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/types.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/__tests__/types.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/integration/adapter.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/integration/families.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/integration/json-adapter.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/integration/json.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/integration/lock-context.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/integration/null-persistence.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/integration/relational.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/integration/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/package.json (100%) rename {packages => languages/typescript/packages}/stack-drizzle/src/codec.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/src/column.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/src/index.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/src/indexes.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/src/operators.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/src/schema-extraction.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/src/sql-dialect.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/src/types.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/tsconfig.json (100%) rename {packages => languages/typescript/packages}/stack-drizzle/tsconfig.typecheck.json (100%) rename {packages => languages/typescript/packages}/stack-drizzle/tsup.config.ts (100%) rename {packages => languages/typescript/packages}/stack-drizzle/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/stack-prisma/DEVELOPING.md (100%) rename {packages => languages/typescript/packages}/stack-prisma/README.md (100%) rename {packages => languages/typescript/packages}/stack-prisma/integration/adapter.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/integration/families.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/integration/json-adapter.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/integration/json.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/integration/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/ops.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/ops.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/ops.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/ops.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/ops.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/refs/head.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/package.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/prisma-next.config.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/contract-authoring.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/contract.d.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/contract.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/contract.prisma (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/abort.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/decrypt-all.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/envelope-base.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/envelope-bigint.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/envelope-boolean.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/envelope-date.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/envelope-json.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/envelope-string.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/middleware-registry.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/routing.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/execution/sdk.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/codec-types.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/column-types.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/contract-space-typing.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/control.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/operation-types.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/pack.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/runtime.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/stack.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/exports/v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/extension-metadata/codec-metadata.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/extension-metadata/constants-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/extension-metadata/constants.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/extension-metadata/descriptor-meta.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/migration/cipherstash-codec-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/migration/eql-bundle-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/stack/from-stack-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/types/codec-types.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/types/operation-types.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/barrel.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/bulk-encrypt-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/catalog.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/codec-runtime-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/derive-schemas-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/envelope-number.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/from-stack-v3-validate.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/operators-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/query-term.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/runtime-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/sdk-adapter-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/src/v3/wire-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/abort.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/authoring.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/bulk-encrypt-middleware.helpers.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/bundling-isolation.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/column-types.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/decrypt-all.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/descriptor.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/envelope-bigint.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/envelope-boolean.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/envelope-date.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/envelope-json.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/envelope-string.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/envelope.types.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/equality-trait-removal.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/bigint-live-pg.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/boolean-storage-live-pg.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/bulk-encrypt-live-pg.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/helpers/eql-v3.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/helpers/harness.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/helpers/live-gate.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/migration-apply-live-pg.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/operators-live-pg.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/live/operators-null-live-pg.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/operation-types.types.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/psl-interpretation.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/routing.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/sdk.types.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/bulk-encrypt-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/catalog-invariants.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/catalog.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/codec-runtime-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/codec-types-v3.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/column-types.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/constants-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/derive-schemas-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/envelope-number.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/from-stack-divergence-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/from-stack-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/migration-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/operator-gating-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/operator-lowering-v3-json.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/operator-lowering-v3-text-search.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/operator-lowering-v3.helpers.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/properties.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/runtime-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/sdk-adapter-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/stale-vendored-space.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/vendored-space-parity.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/test/v3/wire-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/tsconfig.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/tsup.config.ts (100%) rename {packages => languages/typescript/packages}/stack-prisma/turbo.json (100%) rename {packages => languages/typescript/packages}/stack-prisma/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/stack-supabase/README.md (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/browser-export-condition.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/column-map-predicate.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/helpers/postgrest-wire.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/helpers/supabase-mock.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/like-pattern.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-declared-mode.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-encryption-error.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-helpers.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-introspect.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-schema-builder.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-v3-builder.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-v3-factory.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-v3-json.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-v3-matrix.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-v3-select-star.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-v3-wire.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-v3.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-verify.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/supabase-wasm-config.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/wasm-client-adapter.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/adapter.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/families.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/grants.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/helpers/pgrest.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/helpers/v3-envelope.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/introspect.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/json.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/select-alias.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/integration/wire.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/package.json (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/column-map.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/create.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/helpers.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/index.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/introspect.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/like-pattern.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/query-builder.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/query-dbspace.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/query-encrypt.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/query-filters.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/query-mutation.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/query-results.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/query-terms.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/schema-builder.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/types.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/verify.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/wasm-client-adapter.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/src/wasm-inline.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/tsconfig.json (100%) rename {packages => languages/typescript/packages}/stack-supabase/tsconfig.typecheck.json (100%) rename {packages => languages/typescript/packages}/stack-supabase/tsup.config.ts (100%) rename {packages => languages/typescript/packages}/stack-supabase/turbo.json (100%) rename {packages => languages/typescript/packages}/stack-supabase/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/stack/README.md (100%) rename {packages => languages/typescript/packages}/stack/__tests__/audit.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/auth-failure-propagation.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/auth-reexports.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/basic-protect.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/browser-export-condition.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/bulk-decrypt-item-failure.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/bulk-encrypt-validation.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/bulk-model-hyphen-fields.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/bulk-protect.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/cjs-require.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/clerk-provider.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/client-get-schemas.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/config.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/decrypt-audit-forwarding.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/diagnostics-entry.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/client-compat.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/construct-guard.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/encrypted-dynamodb-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/helpers-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/hmac-domains.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/properties.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/resolve-decrypt.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/v2-grouped-date.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/v2-table-forwarding.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/dynamodb/v2-type-coverage.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/empty-schemas-boundary.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/encrypt-lock-context-guards.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/encrypt-query-match-preflight.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/encrypt-query-searchable-json.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/encrypt-query-stevec.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/encrypt-query.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/encryption-helpers.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/encryption-v3-only.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/eql-v3-capability-matrix-skill.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/eql-v3-domain-registry.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/error-codes.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/error-discriminated-union.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/error-helpers.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/fixtures-query-contract.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/fixtures/index.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/helpers.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/helpers/expect-result.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/helpers/process-free-realm.mjs (100%) rename {packages => languages/typescript/packages}/stack/__tests__/helpers/stub-auth-wasm-inline.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/helpers/stub-protect-ffi-wasm-inline.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/identify-cts-refusal.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/infer-index-type.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/init-strategy.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/jsonb-helpers.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/keysets.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/lock-context-wiring.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/lock-context.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/logger-edge-safety.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/match-bloom-live.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/match-needle-guard.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/model-column-mapping.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/null-guards.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/operation-failure-diagnostics.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/protect-ops.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/readme-sync.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/resolve-lock-context.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/schema-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/selector-path.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/subpath-types-parity.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/test-kit-env.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/test-kit-families.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/test-kit-v2-fixtures.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/typed-client-v3.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/typed-client-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/types-public-surface.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/v3-matrix/catalog.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/v3-matrix/matrix-audit.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/v3-matrix/matrix-lock-context.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/v3-matrix/matrix.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/v3-matrix/matrix.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/v3-matrix/needle-for.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/v3-only-public-surface.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-auth-failure.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-bulk.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-bundle-isolation.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-column-name.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-core-credential-contract.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-models.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-new-client.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-normalize.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-query.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-result-contract.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-schemas.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-strategy.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-inline-v3.test.ts (100%) rename {packages => languages/typescript/packages}/stack/__tests__/wasm-plaintext.test-d.ts (100%) rename {packages => languages/typescript/packages}/stack/dist-types/README.md (100%) rename {packages => languages/typescript/packages}/stack/dist-types/encrypt-query.ts (100%) rename {packages => languages/typescript/packages}/stack/dist-types/node16/encrypt-query.cts (100%) rename {packages => languages/typescript/packages}/stack/dist-types/node16/encrypt-query.mts (100%) rename {packages => languages/typescript/packages}/stack/dist-types/node16/tsconfig.json (100%) rename {packages => languages/typescript/packages}/stack/dist-types/node16/wasm-inline.mts (100%) rename {packages => languages/typescript/packages}/stack/dist-types/schemas-and-config.ts (100%) rename {packages => languages/typescript/packages}/stack/dist-types/tsconfig.json (100%) rename {packages => languages/typescript/packages}/stack/dist-types/wasm-inline-type-identity.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/identity/matrix-identity.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/harness.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/json-crypto.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/match-bloom.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/matrix-bulk.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/matrix-crypto.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/matrix-keyset.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/matrix-sql.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/ope-term.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/schema-pg.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/schema-v3-client.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/shared/v2-decrypt-compat.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/wasm/adapter.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/wasm/families.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/integration/wasm/v2-decrypt-compat.integration.test.ts (100%) rename {packages => languages/typescript/packages}/stack/package.json (100%) rename {packages => languages/typescript/packages}/stack/scripts/install-eql-v3.ts (100%) rename {packages => languages/typescript/packages}/stack/src/adapter-kit.ts (100%) rename {packages => languages/typescript/packages}/stack/src/diagnostics.ts (100%) rename {packages => languages/typescript/packages}/stack/src/dynamodb/helpers.ts (100%) rename {packages => languages/typescript/packages}/stack/src/dynamodb/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/dynamodb/operations/base-operation.ts (100%) rename {packages => languages/typescript/packages}/stack/src/dynamodb/operations/bulk-decrypt-models.ts (100%) rename {packages => languages/typescript/packages}/stack/src/dynamodb/operations/bulk-encrypt-models.ts (100%) rename {packages => languages/typescript/packages}/stack/src/dynamodb/operations/decrypt-model.ts (100%) rename {packages => languages/typescript/packages}/stack/src/dynamodb/operations/encrypt-model.ts (100%) rename {packages => languages/typescript/packages}/stack/src/dynamodb/types.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/client-v3.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/auth-failure.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/error-code.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/infer-index-type.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/jsonb.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/model-helpers.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/model-traversal.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/type-guards.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/helpers/validation.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/base-operation.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/batch-encrypt-query.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/bulk-decrypt-models.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/bulk-decrypt.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/bulk-encrypt-models.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/bulk-encrypt.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/decrypt-model.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/decrypt.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/encrypt-model.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/encrypt-query.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/encrypt.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/operations/mapped-decrypt.ts (100%) rename {packages => languages/typescript/packages}/stack/src/encryption/v3.ts (100%) rename {packages => languages/typescript/packages}/stack/src/eql/v3/columns.ts (100%) rename {packages => languages/typescript/packages}/stack/src/eql/v3/date-reconstruction.ts (100%) rename {packages => languages/typescript/packages}/stack/src/eql/v3/domain-registry.ts (100%) rename {packages => languages/typescript/packages}/stack/src/eql/v3/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/eql/v3/selector-path.ts (100%) rename {packages => languages/typescript/packages}/stack/src/eql/v3/table.ts (100%) rename {packages => languages/typescript/packages}/stack/src/eql/v3/types.ts (100%) rename {packages => languages/typescript/packages}/stack/src/errors/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/identity/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/schema/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/schema/internal.ts (100%) rename {packages => languages/typescript/packages}/stack/src/schema/match-defaults.ts (100%) rename {packages => languages/typescript/packages}/stack/src/types-public.ts (100%) rename {packages => languages/typescript/packages}/stack/src/types.ts (100%) rename {packages => languages/typescript/packages}/stack/src/utils/config/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/utils/logger/index.ts (100%) rename {packages => languages/typescript/packages}/stack/src/wasm-inline.ts (100%) rename {packages => languages/typescript/packages}/stack/tsconfig.json (100%) rename {packages => languages/typescript/packages}/stack/tsconfig.typecheck.json (100%) rename {packages => languages/typescript/packages}/stack/tsup.config.ts (100%) rename {packages => languages/typescript/packages}/stack/turbo.json (100%) rename {packages => languages/typescript/packages}/stack/vitest.config.ts (100%) rename {packages => languages/typescript/packages}/stack/vitest.wasm-core.config.ts (100%) rename {packages => languages/typescript/packages}/test-kit/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/test-kit/package.json (100%) rename {packages => languages/typescript/packages}/test-kit/src/__tests__/install.test.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/adapter.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/catalog.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/env.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/families.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/index.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/install.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/integration/clerk.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/integration/config.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/integration/global-setup.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/integration/no-skips-reporter.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/json-adapter.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/needle-for.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/ops.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/oracle.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/results.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/rows.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/run-family-suite.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/run-json-suite.ts (100%) rename {packages => languages/typescript/packages}/test-kit/src/v2-fixtures.ts (100%) rename {packages => languages/typescript/packages}/test-kit/tsconfig.json (100%) rename {packages => languages/typescript/packages}/utils/config/index.ts (100%) rename {packages => languages/typescript/packages}/utils/logger/index.ts (100%) rename {packages => languages/typescript/packages}/wizard/CHANGELOG.md (100%) rename {packages => languages/typescript/packages}/wizard/README.md (100%) rename {packages => languages/typescript/packages}/wizard/package.json (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/agent-sdk.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/commandments.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/detect.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/errors-runner.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/format.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/gateway-messages.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/health-checks.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/hooks.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/install-skills.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/interface.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/parse-args.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/post-agent.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/prerequisites.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/rewrite-migrations.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/__tests__/wizard-tools.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/agent/__tests__/interface.test.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/agent/commandments.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/agent/errors.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/agent/fetch-prompt.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/agent/hooks.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/agent/interface.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/bin/parse-args.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/bin/wizard.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/health-checks/index.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/analytics.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/changelog.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/constants.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/detect.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/format.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/gather.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/install-skills.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/post-agent.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/prerequisites.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/rewrite-migrations.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/types.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/lib/wire-call-sites.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/run.ts (100%) rename {packages => languages/typescript/packages}/wizard/src/tools/wizard-tools.ts (100%) rename {packages => languages/typescript/packages}/wizard/tsconfig.json (100%) rename {packages => languages/typescript/packages}/wizard/tsup.config.ts (100%) diff --git a/examples/basic/CHANGELOG.md b/languages/typescript/examples/basic/CHANGELOG.md similarity index 100% rename from examples/basic/CHANGELOG.md rename to languages/typescript/examples/basic/CHANGELOG.md diff --git a/examples/basic/README.md b/languages/typescript/examples/basic/README.md similarity index 100% rename from examples/basic/README.md rename to languages/typescript/examples/basic/README.md diff --git a/examples/basic/encrypt.ts b/languages/typescript/examples/basic/encrypt.ts similarity index 100% rename from examples/basic/encrypt.ts rename to languages/typescript/examples/basic/encrypt.ts diff --git a/examples/basic/index.ts b/languages/typescript/examples/basic/index.ts similarity index 100% rename from examples/basic/index.ts rename to languages/typescript/examples/basic/index.ts diff --git a/examples/basic/package.json b/languages/typescript/examples/basic/package.json similarity index 100% rename from examples/basic/package.json rename to languages/typescript/examples/basic/package.json diff --git a/examples/basic/src/encryption/index.ts b/languages/typescript/examples/basic/src/encryption/index.ts similarity index 100% rename from examples/basic/src/encryption/index.ts rename to languages/typescript/examples/basic/src/encryption/index.ts diff --git a/examples/basic/stash.config.ts b/languages/typescript/examples/basic/stash.config.ts similarity index 100% rename from examples/basic/stash.config.ts rename to languages/typescript/examples/basic/stash.config.ts diff --git a/examples/basic/tsconfig.json b/languages/typescript/examples/basic/tsconfig.json similarity index 100% rename from examples/basic/tsconfig.json rename to languages/typescript/examples/basic/tsconfig.json diff --git a/examples/prisma/.env.example b/languages/typescript/examples/prisma/.env.example similarity index 100% rename from examples/prisma/.env.example rename to languages/typescript/examples/prisma/.env.example diff --git a/examples/prisma/CHANGELOG.md b/languages/typescript/examples/prisma/CHANGELOG.md similarity index 100% rename from examples/prisma/CHANGELOG.md rename to languages/typescript/examples/prisma/CHANGELOG.md diff --git a/examples/prisma/README.md b/languages/typescript/examples/prisma/README.md similarity index 100% rename from examples/prisma/README.md rename to languages/typescript/examples/prisma/README.md diff --git a/examples/prisma/docker-compose.yml b/languages/typescript/examples/prisma/docker-compose.yml similarity index 100% rename from examples/prisma/docker-compose.yml rename to languages/typescript/examples/prisma/docker-compose.yml diff --git a/examples/prisma/migrations/app/20260714T2142_initial/migration.json b/languages/typescript/examples/prisma/migrations/app/20260714T2142_initial/migration.json similarity index 100% rename from examples/prisma/migrations/app/20260714T2142_initial/migration.json rename to languages/typescript/examples/prisma/migrations/app/20260714T2142_initial/migration.json diff --git a/examples/prisma/migrations/app/20260714T2142_initial/migration.ts b/languages/typescript/examples/prisma/migrations/app/20260714T2142_initial/migration.ts similarity index 100% rename from examples/prisma/migrations/app/20260714T2142_initial/migration.ts rename to languages/typescript/examples/prisma/migrations/app/20260714T2142_initial/migration.ts diff --git a/examples/prisma/migrations/app/20260714T2142_initial/ops.json b/languages/typescript/examples/prisma/migrations/app/20260714T2142_initial/ops.json similarity index 100% rename from examples/prisma/migrations/app/20260714T2142_initial/ops.json rename to languages/typescript/examples/prisma/migrations/app/20260714T2142_initial/ops.json diff --git a/examples/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/migration.json b/languages/typescript/examples/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/migration.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/migration.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/migration.json diff --git a/examples/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/ops.json b/languages/typescript/examples/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/ops.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/ops.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20260601T0100_install_eql_v3_bundle/ops.json diff --git a/examples/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/migration.json b/languages/typescript/examples/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/migration.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/migration.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/migration.json diff --git a/examples/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/ops.json b/languages/typescript/examples/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/ops.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/ops.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20260720T0000_upgrade_eql_v3_3_0_2/ops.json diff --git a/examples/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/migration.json b/languages/typescript/examples/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/migration.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/migration.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/migration.json diff --git a/examples/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/ops.json b/languages/typescript/examples/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/ops.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/ops.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20260728T0000_upgrade_eql_v3_3_0_4/ops.json diff --git a/examples/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/migration.json b/languages/typescript/examples/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/migration.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/migration.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/migration.json diff --git a/examples/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/ops.json b/languages/typescript/examples/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/ops.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/ops.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20260814T0000_upgrade_eql_v3_3_0_5/ops.json diff --git a/examples/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/migration.json b/languages/typescript/examples/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/migration.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/migration.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/migration.json diff --git a/examples/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/ops.json b/languages/typescript/examples/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/ops.json similarity index 100% rename from examples/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/ops.json rename to languages/typescript/examples/prisma/migrations/cipherstash/20261002T0000_upgrade_eql_v3_3_0_6/ops.json diff --git a/examples/prisma/migrations/cipherstash/refs/head.json b/languages/typescript/examples/prisma/migrations/cipherstash/refs/head.json similarity index 100% rename from examples/prisma/migrations/cipherstash/refs/head.json rename to languages/typescript/examples/prisma/migrations/cipherstash/refs/head.json diff --git a/examples/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts b/languages/typescript/examples/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts similarity index 100% rename from examples/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts rename to languages/typescript/examples/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts diff --git a/examples/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json b/languages/typescript/examples/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json similarity index 100% rename from examples/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json rename to languages/typescript/examples/prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json diff --git a/examples/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.d.ts b/languages/typescript/examples/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.d.ts similarity index 100% rename from examples/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.d.ts rename to languages/typescript/examples/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.d.ts diff --git a/examples/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.json b/languages/typescript/examples/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.json similarity index 100% rename from examples/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.json rename to languages/typescript/examples/prisma/migrations/snapshots/f1cd58a4c67d07d7c45d05b6d11a5629e063848d9597a17af2311542622cd8d7/contract.json diff --git a/examples/prisma/package.json b/languages/typescript/examples/prisma/package.json similarity index 100% rename from examples/prisma/package.json rename to languages/typescript/examples/prisma/package.json diff --git a/examples/prisma/prisma-next.config.ts b/languages/typescript/examples/prisma/prisma-next.config.ts similarity index 100% rename from examples/prisma/prisma-next.config.ts rename to languages/typescript/examples/prisma/prisma-next.config.ts diff --git a/examples/prisma/prisma/schema.prisma b/languages/typescript/examples/prisma/prisma/schema.prisma similarity index 100% rename from examples/prisma/prisma/schema.prisma rename to languages/typescript/examples/prisma/prisma/schema.prisma diff --git a/examples/prisma/src/db.ts b/languages/typescript/examples/prisma/src/db.ts similarity index 100% rename from examples/prisma/src/db.ts rename to languages/typescript/examples/prisma/src/db.ts diff --git a/examples/prisma/src/index.ts b/languages/typescript/examples/prisma/src/index.ts similarity index 100% rename from examples/prisma/src/index.ts rename to languages/typescript/examples/prisma/src/index.ts diff --git a/examples/prisma/src/prisma/contract.d.ts b/languages/typescript/examples/prisma/src/prisma/contract.d.ts similarity index 100% rename from examples/prisma/src/prisma/contract.d.ts rename to languages/typescript/examples/prisma/src/prisma/contract.d.ts diff --git a/examples/prisma/src/prisma/contract.json b/languages/typescript/examples/prisma/src/prisma/contract.json similarity index 100% rename from examples/prisma/src/prisma/contract.json rename to languages/typescript/examples/prisma/src/prisma/contract.json diff --git a/examples/prisma/test/e2e/README.md b/languages/typescript/examples/prisma/test/e2e/README.md similarity index 100% rename from examples/prisma/test/e2e/README.md rename to languages/typescript/examples/prisma/test/e2e/README.md diff --git a/examples/prisma/test/e2e/bigint.e2e.test.ts b/languages/typescript/examples/prisma/test/e2e/bigint.e2e.test.ts similarity index 100% rename from examples/prisma/test/e2e/bigint.e2e.test.ts rename to languages/typescript/examples/prisma/test/e2e/bigint.e2e.test.ts diff --git a/examples/prisma/test/e2e/bool.e2e.test.ts b/languages/typescript/examples/prisma/test/e2e/bool.e2e.test.ts similarity index 100% rename from examples/prisma/test/e2e/bool.e2e.test.ts rename to languages/typescript/examples/prisma/test/e2e/bool.e2e.test.ts diff --git a/examples/prisma/test/e2e/date.e2e.test.ts b/languages/typescript/examples/prisma/test/e2e/date.e2e.test.ts similarity index 100% rename from examples/prisma/test/e2e/date.e2e.test.ts rename to languages/typescript/examples/prisma/test/e2e/date.e2e.test.ts diff --git a/examples/prisma/test/e2e/docker-compose.yml b/languages/typescript/examples/prisma/test/e2e/docker-compose.yml similarity index 100% rename from examples/prisma/test/e2e/docker-compose.yml rename to languages/typescript/examples/prisma/test/e2e/docker-compose.yml diff --git a/examples/prisma/test/e2e/global-setup.ts b/languages/typescript/examples/prisma/test/e2e/global-setup.ts similarity index 100% rename from examples/prisma/test/e2e/global-setup.ts rename to languages/typescript/examples/prisma/test/e2e/global-setup.ts diff --git a/examples/prisma/test/e2e/harness.ts b/languages/typescript/examples/prisma/test/e2e/harness.ts similarity index 100% rename from examples/prisma/test/e2e/harness.ts rename to languages/typescript/examples/prisma/test/e2e/harness.ts diff --git a/examples/prisma/test/e2e/json.e2e.test.ts b/languages/typescript/examples/prisma/test/e2e/json.e2e.test.ts similarity index 100% rename from examples/prisma/test/e2e/json.e2e.test.ts rename to languages/typescript/examples/prisma/test/e2e/json.e2e.test.ts diff --git a/examples/prisma/test/e2e/mixed.e2e.test.ts b/languages/typescript/examples/prisma/test/e2e/mixed.e2e.test.ts similarity index 100% rename from examples/prisma/test/e2e/mixed.e2e.test.ts rename to languages/typescript/examples/prisma/test/e2e/mixed.e2e.test.ts diff --git a/examples/prisma/test/e2e/num.e2e.test.ts b/languages/typescript/examples/prisma/test/e2e/num.e2e.test.ts similarity index 100% rename from examples/prisma/test/e2e/num.e2e.test.ts rename to languages/typescript/examples/prisma/test/e2e/num.e2e.test.ts diff --git a/examples/prisma/test/e2e/str-range.e2e.test.ts b/languages/typescript/examples/prisma/test/e2e/str-range.e2e.test.ts similarity index 100% rename from examples/prisma/test/e2e/str-range.e2e.test.ts rename to languages/typescript/examples/prisma/test/e2e/str-range.e2e.test.ts diff --git a/examples/prisma/test/e2e/vitest.config.ts b/languages/typescript/examples/prisma/test/e2e/vitest.config.ts similarity index 100% rename from examples/prisma/test/e2e/vitest.config.ts rename to languages/typescript/examples/prisma/test/e2e/vitest.config.ts diff --git a/examples/prisma/tsconfig.json b/languages/typescript/examples/prisma/tsconfig.json similarity index 100% rename from examples/prisma/tsconfig.json rename to languages/typescript/examples/prisma/tsconfig.json diff --git a/examples/supabase-worker/.env.example b/languages/typescript/examples/supabase-worker/.env.example similarity index 100% rename from examples/supabase-worker/.env.example rename to languages/typescript/examples/supabase-worker/.env.example diff --git a/examples/supabase-worker/README.md b/languages/typescript/examples/supabase-worker/README.md similarity index 100% rename from examples/supabase-worker/README.md rename to languages/typescript/examples/supabase-worker/README.md diff --git a/examples/supabase-worker/package.json b/languages/typescript/examples/supabase-worker/package.json similarity index 100% rename from examples/supabase-worker/package.json rename to languages/typescript/examples/supabase-worker/package.json diff --git a/examples/supabase-worker/supabase/functions/cipherstash-roundtrip/index.ts b/languages/typescript/examples/supabase-worker/supabase/functions/cipherstash-roundtrip/index.ts similarity index 100% rename from examples/supabase-worker/supabase/functions/cipherstash-roundtrip/index.ts rename to languages/typescript/examples/supabase-worker/supabase/functions/cipherstash-roundtrip/index.ts diff --git a/packages/bench/.gitignore b/languages/typescript/packages/bench/.gitignore similarity index 100% rename from packages/bench/.gitignore rename to languages/typescript/packages/bench/.gitignore diff --git a/packages/bench/CHANGELOG.md b/languages/typescript/packages/bench/CHANGELOG.md similarity index 100% rename from packages/bench/CHANGELOG.md rename to languages/typescript/packages/bench/CHANGELOG.md diff --git a/packages/bench/README.md b/languages/typescript/packages/bench/README.md similarity index 100% rename from packages/bench/README.md rename to languages/typescript/packages/bench/README.md diff --git a/packages/bench/__benches__/drizzle/operators.bench.ts b/languages/typescript/packages/bench/__benches__/drizzle/operators.bench.ts similarity index 100% rename from packages/bench/__benches__/drizzle/operators.bench.ts rename to languages/typescript/packages/bench/__benches__/drizzle/operators.bench.ts diff --git a/packages/bench/__tests__/db-only.test.ts b/languages/typescript/packages/bench/__tests__/db-only.test.ts similarity index 100% rename from packages/bench/__tests__/db-only.test.ts rename to languages/typescript/packages/bench/__tests__/db-only.test.ts diff --git a/packages/bench/__tests__/drizzle/operators.explain.test.ts b/languages/typescript/packages/bench/__tests__/drizzle/operators.explain.test.ts similarity index 100% rename from packages/bench/__tests__/drizzle/operators.explain.test.ts rename to languages/typescript/packages/bench/__tests__/drizzle/operators.explain.test.ts diff --git a/packages/bench/__tests__/harness.test.ts b/languages/typescript/packages/bench/__tests__/harness.test.ts similarity index 100% rename from packages/bench/__tests__/harness.test.ts rename to languages/typescript/packages/bench/__tests__/harness.test.ts diff --git a/packages/bench/__unit__/seed-keys.test.ts b/languages/typescript/packages/bench/__unit__/seed-keys.test.ts similarity index 100% rename from packages/bench/__unit__/seed-keys.test.ts rename to languages/typescript/packages/bench/__unit__/seed-keys.test.ts diff --git a/packages/bench/package.json b/languages/typescript/packages/bench/package.json similarity index 100% rename from packages/bench/package.json rename to languages/typescript/packages/bench/package.json diff --git a/packages/bench/sql/schema.sql b/languages/typescript/packages/bench/sql/schema.sql similarity index 100% rename from packages/bench/sql/schema.sql rename to languages/typescript/packages/bench/sql/schema.sql diff --git a/packages/bench/src/cli/reset.ts b/languages/typescript/packages/bench/src/cli/reset.ts similarity index 100% rename from packages/bench/src/cli/reset.ts rename to languages/typescript/packages/bench/src/cli/reset.ts diff --git a/packages/bench/src/cli/setup.ts b/languages/typescript/packages/bench/src/cli/setup.ts similarity index 100% rename from packages/bench/src/cli/setup.ts rename to languages/typescript/packages/bench/src/cli/setup.ts diff --git a/packages/bench/src/drizzle/setup.ts b/languages/typescript/packages/bench/src/drizzle/setup.ts similarity index 100% rename from packages/bench/src/drizzle/setup.ts rename to languages/typescript/packages/bench/src/drizzle/setup.ts diff --git a/packages/bench/src/harness/db.ts b/languages/typescript/packages/bench/src/harness/db.ts similarity index 100% rename from packages/bench/src/harness/db.ts rename to languages/typescript/packages/bench/src/harness/db.ts diff --git a/packages/bench/src/harness/explain.ts b/languages/typescript/packages/bench/src/harness/explain.ts similarity index 100% rename from packages/bench/src/harness/explain.ts rename to languages/typescript/packages/bench/src/harness/explain.ts diff --git a/packages/bench/src/harness/global-setup.ts b/languages/typescript/packages/bench/src/harness/global-setup.ts similarity index 100% rename from packages/bench/src/harness/global-setup.ts rename to languages/typescript/packages/bench/src/harness/global-setup.ts diff --git a/packages/bench/src/harness/seed.ts b/languages/typescript/packages/bench/src/harness/seed.ts similarity index 100% rename from packages/bench/src/harness/seed.ts rename to languages/typescript/packages/bench/src/harness/seed.ts diff --git a/packages/bench/tsconfig.json b/languages/typescript/packages/bench/tsconfig.json similarity index 100% rename from packages/bench/tsconfig.json rename to languages/typescript/packages/bench/tsconfig.json diff --git a/packages/bench/vitest.config.ts b/languages/typescript/packages/bench/vitest.config.ts similarity index 100% rename from packages/bench/vitest.config.ts rename to languages/typescript/packages/bench/vitest.config.ts diff --git a/packages/bench/vitest.unit.config.ts b/languages/typescript/packages/bench/vitest.unit.config.ts similarity index 100% rename from packages/bench/vitest.unit.config.ts rename to languages/typescript/packages/bench/vitest.unit.config.ts diff --git a/packages/cli/AGENTS.md b/languages/typescript/packages/cli/AGENTS.md similarity index 100% rename from packages/cli/AGENTS.md rename to languages/typescript/packages/cli/AGENTS.md diff --git a/packages/cli/CHANGELOG.md b/languages/typescript/packages/cli/CHANGELOG.md similarity index 100% rename from packages/cli/CHANGELOG.md rename to languages/typescript/packages/cli/CHANGELOG.md diff --git a/packages/cli/README.md b/languages/typescript/packages/cli/README.md similarity index 100% rename from packages/cli/README.md rename to languages/typescript/packages/cli/README.md diff --git a/packages/cli/__fixtures__/scaffold/drizzle.generated.ts b/languages/typescript/packages/cli/__fixtures__/scaffold/drizzle.generated.ts similarity index 100% rename from packages/cli/__fixtures__/scaffold/drizzle.generated.ts rename to languages/typescript/packages/cli/__fixtures__/scaffold/drizzle.generated.ts diff --git a/packages/cli/__fixtures__/scaffold/generic.generated.ts b/languages/typescript/packages/cli/__fixtures__/scaffold/generic.generated.ts similarity index 100% rename from packages/cli/__fixtures__/scaffold/generic.generated.ts rename to languages/typescript/packages/cli/__fixtures__/scaffold/generic.generated.ts diff --git a/packages/cli/package.json b/languages/typescript/packages/cli/package.json similarity index 100% rename from packages/cli/package.json rename to languages/typescript/packages/cli/package.json diff --git a/packages/cli/scripts/e2e-encrypt.sh b/languages/typescript/packages/cli/scripts/e2e-encrypt.sh similarity index 100% rename from packages/cli/scripts/e2e-encrypt.sh rename to languages/typescript/packages/cli/scripts/e2e-encrypt.sh diff --git a/packages/cli/scripts/fixtures/seed-users.sql b/languages/typescript/packages/cli/scripts/fixtures/seed-users.sql similarity index 100% rename from packages/cli/scripts/fixtures/seed-users.sql rename to languages/typescript/packages/cli/scripts/fixtures/seed-users.sql diff --git a/packages/cli/src/__tests__/config-jiti-integration.test.ts b/languages/typescript/packages/cli/src/__tests__/config-jiti-integration.test.ts similarity index 100% rename from packages/cli/src/__tests__/config-jiti-integration.test.ts rename to languages/typescript/packages/cli/src/__tests__/config-jiti-integration.test.ts diff --git a/packages/cli/src/__tests__/config.test.ts b/languages/typescript/packages/cli/src/__tests__/config.test.ts similarity index 100% rename from packages/cli/src/__tests__/config.test.ts rename to languages/typescript/packages/cli/src/__tests__/config.test.ts diff --git a/packages/cli/src/__tests__/database-url.test.ts b/languages/typescript/packages/cli/src/__tests__/database-url.test.ts similarity index 100% rename from packages/cli/src/__tests__/database-url.test.ts rename to languages/typescript/packages/cli/src/__tests__/database-url.test.ts diff --git a/packages/cli/src/__tests__/detect.test.ts b/languages/typescript/packages/cli/src/__tests__/detect.test.ts similarity index 100% rename from packages/cli/src/__tests__/detect.test.ts rename to languages/typescript/packages/cli/src/__tests__/detect.test.ts diff --git a/packages/cli/src/__tests__/installer.test.ts b/languages/typescript/packages/cli/src/__tests__/installer.test.ts similarity index 100% rename from packages/cli/src/__tests__/installer.test.ts rename to languages/typescript/packages/cli/src/__tests__/installer.test.ts diff --git a/packages/cli/src/__tests__/module-error-classification.test.ts b/languages/typescript/packages/cli/src/__tests__/module-error-classification.test.ts similarity index 100% rename from packages/cli/src/__tests__/module-error-classification.test.ts rename to languages/typescript/packages/cli/src/__tests__/module-error-classification.test.ts diff --git a/packages/cli/src/__tests__/native.test.ts b/languages/typescript/packages/cli/src/__tests__/native.test.ts similarity index 100% rename from packages/cli/src/__tests__/native.test.ts rename to languages/typescript/packages/cli/src/__tests__/native.test.ts diff --git a/packages/cli/src/__tests__/placeholder-guard-parity.test.ts b/languages/typescript/packages/cli/src/__tests__/placeholder-guard-parity.test.ts similarity index 100% rename from packages/cli/src/__tests__/placeholder-guard-parity.test.ts rename to languages/typescript/packages/cli/src/__tests__/placeholder-guard-parity.test.ts diff --git a/packages/cli/src/__tests__/release-train.test.ts b/languages/typescript/packages/cli/src/__tests__/release-train.test.ts similarity index 100% rename from packages/cli/src/__tests__/release-train.test.ts rename to languages/typescript/packages/cli/src/__tests__/release-train.test.ts diff --git a/packages/cli/src/__tests__/rewrite-migrations.test.ts b/languages/typescript/packages/cli/src/__tests__/rewrite-migrations.test.ts similarity index 100% rename from packages/cli/src/__tests__/rewrite-migrations.test.ts rename to languages/typescript/packages/cli/src/__tests__/rewrite-migrations.test.ts diff --git a/packages/cli/src/__tests__/runtime-versions.test.ts b/languages/typescript/packages/cli/src/__tests__/runtime-versions.test.ts similarity index 100% rename from packages/cli/src/__tests__/runtime-versions.test.ts rename to languages/typescript/packages/cli/src/__tests__/runtime-versions.test.ts diff --git a/packages/cli/src/__tests__/skill-supabase-apply.test.ts b/languages/typescript/packages/cli/src/__tests__/skill-supabase-apply.test.ts similarity index 100% rename from packages/cli/src/__tests__/skill-supabase-apply.test.ts rename to languages/typescript/packages/cli/src/__tests__/skill-supabase-apply.test.ts diff --git a/packages/cli/src/__tests__/v2-retirement.test.ts b/languages/typescript/packages/cli/src/__tests__/v2-retirement.test.ts similarity index 100% rename from packages/cli/src/__tests__/v2-retirement.test.ts rename to languages/typescript/packages/cli/src/__tests__/v2-retirement.test.ts diff --git a/packages/cli/src/bin/main.ts b/languages/typescript/packages/cli/src/bin/main.ts similarity index 100% rename from packages/cli/src/bin/main.ts rename to languages/typescript/packages/cli/src/bin/main.ts diff --git a/packages/cli/src/bin/stash.ts b/languages/typescript/packages/cli/src/bin/stash.ts similarity index 100% rename from packages/cli/src/bin/stash.ts rename to languages/typescript/packages/cli/src/bin/stash.ts diff --git a/packages/cli/src/cli/__tests__/help.test.ts b/languages/typescript/packages/cli/src/cli/__tests__/help.test.ts similarity index 100% rename from packages/cli/src/cli/__tests__/help.test.ts rename to languages/typescript/packages/cli/src/cli/__tests__/help.test.ts diff --git a/packages/cli/src/cli/__tests__/manifest.test.ts b/languages/typescript/packages/cli/src/cli/__tests__/manifest.test.ts similarity index 100% rename from packages/cli/src/cli/__tests__/manifest.test.ts rename to languages/typescript/packages/cli/src/cli/__tests__/manifest.test.ts diff --git a/packages/cli/src/cli/exit.ts b/languages/typescript/packages/cli/src/cli/exit.ts similarity index 100% rename from packages/cli/src/cli/exit.ts rename to languages/typescript/packages/cli/src/cli/exit.ts diff --git a/packages/cli/src/cli/help.ts b/languages/typescript/packages/cli/src/cli/help.ts similarity index 100% rename from packages/cli/src/cli/help.ts rename to languages/typescript/packages/cli/src/cli/help.ts diff --git a/packages/cli/src/cli/manifest.ts b/languages/typescript/packages/cli/src/cli/manifest.ts similarity index 100% rename from packages/cli/src/cli/manifest.ts rename to languages/typescript/packages/cli/src/cli/manifest.ts diff --git a/packages/cli/src/cli/registry.ts b/languages/typescript/packages/cli/src/cli/registry.ts similarity index 100% rename from packages/cli/src/cli/registry.ts rename to languages/typescript/packages/cli/src/cli/registry.ts diff --git a/packages/cli/src/commands/auth/__tests__/failure.test.ts b/languages/typescript/packages/cli/src/commands/auth/__tests__/failure.test.ts similarity index 100% rename from packages/cli/src/commands/auth/__tests__/failure.test.ts rename to languages/typescript/packages/cli/src/commands/auth/__tests__/failure.test.ts diff --git a/packages/cli/src/commands/auth/__tests__/index.test.ts b/languages/typescript/packages/cli/src/commands/auth/__tests__/index.test.ts similarity index 100% rename from packages/cli/src/commands/auth/__tests__/index.test.ts rename to languages/typescript/packages/cli/src/commands/auth/__tests__/index.test.ts diff --git a/packages/cli/src/commands/auth/__tests__/login.test.ts b/languages/typescript/packages/cli/src/commands/auth/__tests__/login.test.ts similarity index 100% rename from packages/cli/src/commands/auth/__tests__/login.test.ts rename to languages/typescript/packages/cli/src/commands/auth/__tests__/login.test.ts diff --git a/packages/cli/src/commands/auth/__tests__/region.test.ts b/languages/typescript/packages/cli/src/commands/auth/__tests__/region.test.ts similarity index 100% rename from packages/cli/src/commands/auth/__tests__/region.test.ts rename to languages/typescript/packages/cli/src/commands/auth/__tests__/region.test.ts diff --git a/packages/cli/src/commands/auth/events.ts b/languages/typescript/packages/cli/src/commands/auth/events.ts similarity index 100% rename from packages/cli/src/commands/auth/events.ts rename to languages/typescript/packages/cli/src/commands/auth/events.ts diff --git a/packages/cli/src/commands/auth/failure.ts b/languages/typescript/packages/cli/src/commands/auth/failure.ts similarity index 100% rename from packages/cli/src/commands/auth/failure.ts rename to languages/typescript/packages/cli/src/commands/auth/failure.ts diff --git a/packages/cli/src/commands/auth/index.ts b/languages/typescript/packages/cli/src/commands/auth/index.ts similarity index 100% rename from packages/cli/src/commands/auth/index.ts rename to languages/typescript/packages/cli/src/commands/auth/index.ts diff --git a/packages/cli/src/commands/auth/login.ts b/languages/typescript/packages/cli/src/commands/auth/login.ts similarity index 100% rename from packages/cli/src/commands/auth/login.ts rename to languages/typescript/packages/cli/src/commands/auth/login.ts diff --git a/packages/cli/src/commands/auth/region.ts b/languages/typescript/packages/cli/src/commands/auth/region.ts similarity index 100% rename from packages/cli/src/commands/auth/region.ts rename to languages/typescript/packages/cli/src/commands/auth/region.ts diff --git a/packages/cli/src/commands/db/__tests__/config-scaffold.test.ts b/languages/typescript/packages/cli/src/commands/db/__tests__/config-scaffold.test.ts similarity index 100% rename from packages/cli/src/commands/db/__tests__/config-scaffold.test.ts rename to languages/typescript/packages/cli/src/commands/db/__tests__/config-scaffold.test.ts diff --git a/packages/cli/src/commands/db/__tests__/find-generated-migration.test.ts b/languages/typescript/packages/cli/src/commands/db/__tests__/find-generated-migration.test.ts similarity index 100% rename from packages/cli/src/commands/db/__tests__/find-generated-migration.test.ts rename to languages/typescript/packages/cli/src/commands/db/__tests__/find-generated-migration.test.ts diff --git a/packages/cli/src/commands/db/__tests__/install-verify-gate.test.ts b/languages/typescript/packages/cli/src/commands/db/__tests__/install-verify-gate.test.ts similarity index 100% rename from packages/cli/src/commands/db/__tests__/install-verify-gate.test.ts rename to languages/typescript/packages/cli/src/commands/db/__tests__/install-verify-gate.test.ts diff --git a/packages/cli/src/commands/db/__tests__/install.test.ts b/languages/typescript/packages/cli/src/commands/db/__tests__/install.test.ts similarity index 100% rename from packages/cli/src/commands/db/__tests__/install.test.ts rename to languages/typescript/packages/cli/src/commands/db/__tests__/install.test.ts diff --git a/packages/cli/src/commands/db/__tests__/preflight.test.ts b/languages/typescript/packages/cli/src/commands/db/__tests__/preflight.test.ts similarity index 100% rename from packages/cli/src/commands/db/__tests__/preflight.test.ts rename to languages/typescript/packages/cli/src/commands/db/__tests__/preflight.test.ts diff --git a/packages/cli/src/commands/db/__tests__/prisma-next-install-guard.test.ts b/languages/typescript/packages/cli/src/commands/db/__tests__/prisma-next-install-guard.test.ts similarity index 100% rename from packages/cli/src/commands/db/__tests__/prisma-next-install-guard.test.ts rename to languages/typescript/packages/cli/src/commands/db/__tests__/prisma-next-install-guard.test.ts diff --git a/packages/cli/src/commands/db/__tests__/status.test.ts b/languages/typescript/packages/cli/src/commands/db/__tests__/status.test.ts similarity index 100% rename from packages/cli/src/commands/db/__tests__/status.test.ts rename to languages/typescript/packages/cli/src/commands/db/__tests__/status.test.ts diff --git a/packages/cli/src/commands/db/__tests__/upgrade.test.ts b/languages/typescript/packages/cli/src/commands/db/__tests__/upgrade.test.ts similarity index 100% rename from packages/cli/src/commands/db/__tests__/upgrade.test.ts rename to languages/typescript/packages/cli/src/commands/db/__tests__/upgrade.test.ts diff --git a/packages/cli/src/commands/db/client-scaffold.ts b/languages/typescript/packages/cli/src/commands/db/client-scaffold.ts similarity index 100% rename from packages/cli/src/commands/db/client-scaffold.ts rename to languages/typescript/packages/cli/src/commands/db/client-scaffold.ts diff --git a/packages/cli/src/commands/db/config-scaffold.ts b/languages/typescript/packages/cli/src/commands/db/config-scaffold.ts similarity index 100% rename from packages/cli/src/commands/db/config-scaffold.ts rename to languages/typescript/packages/cli/src/commands/db/config-scaffold.ts diff --git a/packages/cli/src/commands/db/detect.ts b/languages/typescript/packages/cli/src/commands/db/detect.ts similarity index 100% rename from packages/cli/src/commands/db/detect.ts rename to languages/typescript/packages/cli/src/commands/db/detect.ts diff --git a/packages/cli/src/commands/db/grants-report.ts b/languages/typescript/packages/cli/src/commands/db/grants-report.ts similarity index 100% rename from packages/cli/src/commands/db/grants-report.ts rename to languages/typescript/packages/cli/src/commands/db/grants-report.ts diff --git a/packages/cli/src/commands/db/install.ts b/languages/typescript/packages/cli/src/commands/db/install.ts similarity index 100% rename from packages/cli/src/commands/db/install.ts rename to languages/typescript/packages/cli/src/commands/db/install.ts diff --git a/packages/cli/src/commands/db/preflight.ts b/languages/typescript/packages/cli/src/commands/db/preflight.ts similarity index 100% rename from packages/cli/src/commands/db/preflight.ts rename to languages/typescript/packages/cli/src/commands/db/preflight.ts diff --git a/packages/cli/src/commands/db/resolve-diagnostic-url.ts b/languages/typescript/packages/cli/src/commands/db/resolve-diagnostic-url.ts similarity index 100% rename from packages/cli/src/commands/db/resolve-diagnostic-url.ts rename to languages/typescript/packages/cli/src/commands/db/resolve-diagnostic-url.ts diff --git a/packages/cli/src/commands/db/rewrite-migrations.ts b/languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts similarity index 100% rename from packages/cli/src/commands/db/rewrite-migrations.ts rename to languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts diff --git a/packages/cli/src/commands/db/status.ts b/languages/typescript/packages/cli/src/commands/db/status.ts similarity index 100% rename from packages/cli/src/commands/db/status.ts rename to languages/typescript/packages/cli/src/commands/db/status.ts diff --git a/packages/cli/src/commands/db/test-connection.ts b/languages/typescript/packages/cli/src/commands/db/test-connection.ts similarity index 100% rename from packages/cli/src/commands/db/test-connection.ts rename to languages/typescript/packages/cli/src/commands/db/test-connection.ts diff --git a/packages/cli/src/commands/db/upgrade.ts b/languages/typescript/packages/cli/src/commands/db/upgrade.ts similarity index 100% rename from packages/cli/src/commands/db/upgrade.ts rename to languages/typescript/packages/cli/src/commands/db/upgrade.ts diff --git a/packages/cli/src/commands/doctor/index.ts b/languages/typescript/packages/cli/src/commands/doctor/index.ts similarity index 100% rename from packages/cli/src/commands/doctor/index.ts rename to languages/typescript/packages/cli/src/commands/doctor/index.ts diff --git a/packages/cli/src/commands/encrypt/__tests__/backfill-target.test.ts b/languages/typescript/packages/cli/src/commands/encrypt/__tests__/backfill-target.test.ts similarity index 100% rename from packages/cli/src/commands/encrypt/__tests__/backfill-target.test.ts rename to languages/typescript/packages/cli/src/commands/encrypt/__tests__/backfill-target.test.ts diff --git a/packages/cli/src/commands/encrypt/__tests__/context-placeholder.test.ts b/languages/typescript/packages/cli/src/commands/encrypt/__tests__/context-placeholder.test.ts similarity index 100% rename from packages/cli/src/commands/encrypt/__tests__/context-placeholder.test.ts rename to languages/typescript/packages/cli/src/commands/encrypt/__tests__/context-placeholder.test.ts diff --git a/packages/cli/src/commands/encrypt/__tests__/encrypt-v3.test.ts b/languages/typescript/packages/cli/src/commands/encrypt/__tests__/encrypt-v3.test.ts similarity index 100% rename from packages/cli/src/commands/encrypt/__tests__/encrypt-v3.test.ts rename to languages/typescript/packages/cli/src/commands/encrypt/__tests__/encrypt-v3.test.ts diff --git a/packages/cli/src/commands/encrypt/__tests__/prisma-next-context.test.ts b/languages/typescript/packages/cli/src/commands/encrypt/__tests__/prisma-next-context.test.ts similarity index 100% rename from packages/cli/src/commands/encrypt/__tests__/prisma-next-context.test.ts rename to languages/typescript/packages/cli/src/commands/encrypt/__tests__/prisma-next-context.test.ts diff --git a/packages/cli/src/commands/encrypt/backfill.ts b/languages/typescript/packages/cli/src/commands/encrypt/backfill.ts similarity index 100% rename from packages/cli/src/commands/encrypt/backfill.ts rename to languages/typescript/packages/cli/src/commands/encrypt/backfill.ts diff --git a/packages/cli/src/commands/encrypt/context.ts b/languages/typescript/packages/cli/src/commands/encrypt/context.ts similarity index 100% rename from packages/cli/src/commands/encrypt/context.ts rename to languages/typescript/packages/cli/src/commands/encrypt/context.ts diff --git a/packages/cli/src/commands/encrypt/drizzle-helper.ts b/languages/typescript/packages/cli/src/commands/encrypt/drizzle-helper.ts similarity index 100% rename from packages/cli/src/commands/encrypt/drizzle-helper.ts rename to languages/typescript/packages/cli/src/commands/encrypt/drizzle-helper.ts diff --git a/packages/cli/src/commands/encrypt/drop.ts b/languages/typescript/packages/cli/src/commands/encrypt/drop.ts similarity index 100% rename from packages/cli/src/commands/encrypt/drop.ts rename to languages/typescript/packages/cli/src/commands/encrypt/drop.ts diff --git a/packages/cli/src/commands/encrypt/lib/__tests__/resolve-eql.test.ts b/languages/typescript/packages/cli/src/commands/encrypt/lib/__tests__/resolve-eql.test.ts similarity index 100% rename from packages/cli/src/commands/encrypt/lib/__tests__/resolve-eql.test.ts rename to languages/typescript/packages/cli/src/commands/encrypt/lib/__tests__/resolve-eql.test.ts diff --git a/packages/cli/src/commands/encrypt/lib/db-readers.ts b/languages/typescript/packages/cli/src/commands/encrypt/lib/db-readers.ts similarity index 100% rename from packages/cli/src/commands/encrypt/lib/db-readers.ts rename to languages/typescript/packages/cli/src/commands/encrypt/lib/db-readers.ts diff --git a/packages/cli/src/commands/encrypt/lib/resolve-eql.ts b/languages/typescript/packages/cli/src/commands/encrypt/lib/resolve-eql.ts similarity index 100% rename from packages/cli/src/commands/encrypt/lib/resolve-eql.ts rename to languages/typescript/packages/cli/src/commands/encrypt/lib/resolve-eql.ts diff --git a/packages/cli/src/commands/encrypt/plan.ts b/languages/typescript/packages/cli/src/commands/encrypt/plan.ts similarity index 100% rename from packages/cli/src/commands/encrypt/plan.ts rename to languages/typescript/packages/cli/src/commands/encrypt/plan.ts diff --git a/packages/cli/src/commands/encrypt/status.ts b/languages/typescript/packages/cli/src/commands/encrypt/status.ts similarity index 100% rename from packages/cli/src/commands/encrypt/status.ts rename to languages/typescript/packages/cli/src/commands/encrypt/status.ts diff --git a/packages/cli/src/commands/env/__tests__/env.test.ts b/languages/typescript/packages/cli/src/commands/env/__tests__/env.test.ts similarity index 100% rename from packages/cli/src/commands/env/__tests__/env.test.ts rename to languages/typescript/packages/cli/src/commands/env/__tests__/env.test.ts diff --git a/packages/cli/src/commands/env/index.ts b/languages/typescript/packages/cli/src/commands/env/index.ts similarity index 100% rename from packages/cli/src/commands/env/index.ts rename to languages/typescript/packages/cli/src/commands/env/index.ts diff --git a/packages/cli/src/commands/eql/__tests__/applied.live.test.ts b/languages/typescript/packages/cli/src/commands/eql/__tests__/applied.live.test.ts similarity index 100% rename from packages/cli/src/commands/eql/__tests__/applied.live.test.ts rename to languages/typescript/packages/cli/src/commands/eql/__tests__/applied.live.test.ts diff --git a/packages/cli/src/commands/eql/__tests__/migration.test.ts b/languages/typescript/packages/cli/src/commands/eql/__tests__/migration.test.ts similarity index 100% rename from packages/cli/src/commands/eql/__tests__/migration.test.ts rename to languages/typescript/packages/cli/src/commands/eql/__tests__/migration.test.ts diff --git a/packages/cli/src/commands/eql/__tests__/repair.test.ts b/languages/typescript/packages/cli/src/commands/eql/__tests__/repair.test.ts similarity index 100% rename from packages/cli/src/commands/eql/__tests__/repair.test.ts rename to languages/typescript/packages/cli/src/commands/eql/__tests__/repair.test.ts diff --git a/packages/cli/src/commands/eql/__tests__/supabase-migration.test.ts b/languages/typescript/packages/cli/src/commands/eql/__tests__/supabase-migration.test.ts similarity index 100% rename from packages/cli/src/commands/eql/__tests__/supabase-migration.test.ts rename to languages/typescript/packages/cli/src/commands/eql/__tests__/supabase-migration.test.ts diff --git a/packages/cli/src/commands/eql/__tests__/supabase-push.live.test.ts b/languages/typescript/packages/cli/src/commands/eql/__tests__/supabase-push.live.test.ts similarity index 100% rename from packages/cli/src/commands/eql/__tests__/supabase-push.live.test.ts rename to languages/typescript/packages/cli/src/commands/eql/__tests__/supabase-push.live.test.ts diff --git a/packages/cli/src/commands/eql/__tests__/validate-command.test.ts b/languages/typescript/packages/cli/src/commands/eql/__tests__/validate-command.test.ts similarity index 100% rename from packages/cli/src/commands/eql/__tests__/validate-command.test.ts rename to languages/typescript/packages/cli/src/commands/eql/__tests__/validate-command.test.ts diff --git a/packages/cli/src/commands/eql/__tests__/validate.test.ts b/languages/typescript/packages/cli/src/commands/eql/__tests__/validate.test.ts similarity index 100% rename from packages/cli/src/commands/eql/__tests__/validate.test.ts rename to languages/typescript/packages/cli/src/commands/eql/__tests__/validate.test.ts diff --git a/packages/cli/src/commands/eql/applied.ts b/languages/typescript/packages/cli/src/commands/eql/applied.ts similarity index 100% rename from packages/cli/src/commands/eql/applied.ts rename to languages/typescript/packages/cli/src/commands/eql/applied.ts diff --git a/packages/cli/src/commands/eql/journal.ts b/languages/typescript/packages/cli/src/commands/eql/journal.ts similarity index 100% rename from packages/cli/src/commands/eql/journal.ts rename to languages/typescript/packages/cli/src/commands/eql/journal.ts diff --git a/packages/cli/src/commands/eql/migration.ts b/languages/typescript/packages/cli/src/commands/eql/migration.ts similarity index 100% rename from packages/cli/src/commands/eql/migration.ts rename to languages/typescript/packages/cli/src/commands/eql/migration.ts diff --git a/packages/cli/src/commands/eql/repair.ts b/languages/typescript/packages/cli/src/commands/eql/repair.ts similarity index 100% rename from packages/cli/src/commands/eql/repair.ts rename to languages/typescript/packages/cli/src/commands/eql/repair.ts diff --git a/packages/cli/src/commands/eql/supabase-migration.ts b/languages/typescript/packages/cli/src/commands/eql/supabase-migration.ts similarity index 100% rename from packages/cli/src/commands/eql/supabase-migration.ts rename to languages/typescript/packages/cli/src/commands/eql/supabase-migration.ts diff --git a/packages/cli/src/commands/eql/sweep-report.ts b/languages/typescript/packages/cli/src/commands/eql/sweep-report.ts similarity index 100% rename from packages/cli/src/commands/eql/sweep-report.ts rename to languages/typescript/packages/cli/src/commands/eql/sweep-report.ts diff --git a/packages/cli/src/commands/eql/validate.ts b/languages/typescript/packages/cli/src/commands/eql/validate.ts similarity index 100% rename from packages/cli/src/commands/eql/validate.ts rename to languages/typescript/packages/cli/src/commands/eql/validate.ts diff --git a/packages/cli/src/commands/eql/verify.ts b/languages/typescript/packages/cli/src/commands/eql/verify.ts similarity index 100% rename from packages/cli/src/commands/eql/verify.ts rename to languages/typescript/packages/cli/src/commands/eql/verify.ts diff --git a/packages/cli/src/commands/impl/__tests__/how-to-proceed.test.ts b/languages/typescript/packages/cli/src/commands/impl/__tests__/how-to-proceed.test.ts similarity index 100% rename from packages/cli/src/commands/impl/__tests__/how-to-proceed.test.ts rename to languages/typescript/packages/cli/src/commands/impl/__tests__/how-to-proceed.test.ts diff --git a/packages/cli/src/commands/impl/__tests__/impl.test.ts b/languages/typescript/packages/cli/src/commands/impl/__tests__/impl.test.ts similarity index 100% rename from packages/cli/src/commands/impl/__tests__/impl.test.ts rename to languages/typescript/packages/cli/src/commands/impl/__tests__/impl.test.ts diff --git a/packages/cli/src/commands/impl/index.ts b/languages/typescript/packages/cli/src/commands/impl/index.ts similarity index 100% rename from packages/cli/src/commands/impl/index.ts rename to languages/typescript/packages/cli/src/commands/impl/index.ts diff --git a/packages/cli/src/commands/impl/steps/__tests__/handoff-agents-md.test.ts b/languages/typescript/packages/cli/src/commands/impl/steps/__tests__/handoff-agents-md.test.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/__tests__/handoff-agents-md.test.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/__tests__/handoff-agents-md.test.ts diff --git a/packages/cli/src/commands/impl/steps/__tests__/handoff-claude.test.ts b/languages/typescript/packages/cli/src/commands/impl/steps/__tests__/handoff-claude.test.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/__tests__/handoff-claude.test.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/__tests__/handoff-claude.test.ts diff --git a/packages/cli/src/commands/impl/steps/__tests__/handoff-codex.test.ts b/languages/typescript/packages/cli/src/commands/impl/steps/__tests__/handoff-codex.test.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/__tests__/handoff-codex.test.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/__tests__/handoff-codex.test.ts diff --git a/packages/cli/src/commands/impl/steps/__tests__/handoff-lovable.test.ts b/languages/typescript/packages/cli/src/commands/impl/steps/__tests__/handoff-lovable.test.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/__tests__/handoff-lovable.test.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/__tests__/handoff-lovable.test.ts diff --git a/packages/cli/src/commands/impl/steps/__tests__/how-to-proceed-dispatch.test.ts b/languages/typescript/packages/cli/src/commands/impl/steps/__tests__/how-to-proceed-dispatch.test.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/__tests__/how-to-proceed-dispatch.test.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/__tests__/how-to-proceed-dispatch.test.ts diff --git a/packages/cli/src/commands/impl/steps/handoff-agents-md.ts b/languages/typescript/packages/cli/src/commands/impl/steps/handoff-agents-md.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/handoff-agents-md.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/handoff-agents-md.ts diff --git a/packages/cli/src/commands/impl/steps/handoff-claude.ts b/languages/typescript/packages/cli/src/commands/impl/steps/handoff-claude.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/handoff-claude.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/handoff-claude.ts diff --git a/packages/cli/src/commands/impl/steps/handoff-codex.ts b/languages/typescript/packages/cli/src/commands/impl/steps/handoff-codex.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/handoff-codex.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/handoff-codex.ts diff --git a/packages/cli/src/commands/impl/steps/handoff-lovable.ts b/languages/typescript/packages/cli/src/commands/impl/steps/handoff-lovable.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/handoff-lovable.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/handoff-lovable.ts diff --git a/packages/cli/src/commands/impl/steps/handoff-wizard.ts b/languages/typescript/packages/cli/src/commands/impl/steps/handoff-wizard.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/handoff-wizard.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/handoff-wizard.ts diff --git a/packages/cli/src/commands/impl/steps/how-to-proceed.ts b/languages/typescript/packages/cli/src/commands/impl/steps/how-to-proceed.ts similarity index 100% rename from packages/cli/src/commands/impl/steps/how-to-proceed.ts rename to languages/typescript/packages/cli/src/commands/impl/steps/how-to-proceed.ts diff --git a/packages/cli/src/commands/index.ts b/languages/typescript/packages/cli/src/commands/index.ts similarity index 100% rename from packages/cli/src/commands/index.ts rename to languages/typescript/packages/cli/src/commands/index.ts diff --git a/packages/cli/src/commands/init/__tests__/detect-agents.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/detect-agents.test.ts similarity index 100% rename from packages/cli/src/commands/init/__tests__/detect-agents.test.ts rename to languages/typescript/packages/cli/src/commands/init/__tests__/detect-agents.test.ts diff --git a/packages/cli/src/commands/init/__tests__/init-command.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/init-command.test.ts similarity index 100% rename from packages/cli/src/commands/init/__tests__/init-command.test.ts rename to languages/typescript/packages/cli/src/commands/init/__tests__/init-command.test.ts diff --git a/packages/cli/src/commands/init/__tests__/placeholder-client-fixture.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/placeholder-client-fixture.test.ts similarity index 100% rename from packages/cli/src/commands/init/__tests__/placeholder-client-fixture.test.ts rename to languages/typescript/packages/cli/src/commands/init/__tests__/placeholder-client-fixture.test.ts diff --git a/packages/cli/src/commands/init/__tests__/sentinel-upsert.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/sentinel-upsert.test.ts similarity index 100% rename from packages/cli/src/commands/init/__tests__/sentinel-upsert.test.ts rename to languages/typescript/packages/cli/src/commands/init/__tests__/sentinel-upsert.test.ts diff --git a/packages/cli/src/commands/init/__tests__/steps-wiring.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/steps-wiring.test.ts similarity index 100% rename from packages/cli/src/commands/init/__tests__/steps-wiring.test.ts rename to languages/typescript/packages/cli/src/commands/init/__tests__/steps-wiring.test.ts diff --git a/packages/cli/src/commands/init/__tests__/utils-codegen-drizzle.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/utils-codegen-drizzle.test.ts similarity index 100% rename from packages/cli/src/commands/init/__tests__/utils-codegen-drizzle.test.ts rename to languages/typescript/packages/cli/src/commands/init/__tests__/utils-codegen-drizzle.test.ts diff --git a/packages/cli/src/commands/init/__tests__/utils-codegen.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/utils-codegen.test.ts similarity index 100% rename from packages/cli/src/commands/init/__tests__/utils-codegen.test.ts rename to languages/typescript/packages/cli/src/commands/init/__tests__/utils-codegen.test.ts diff --git a/packages/cli/src/commands/init/__tests__/utils.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/utils.test.ts similarity index 100% rename from packages/cli/src/commands/init/__tests__/utils.test.ts rename to languages/typescript/packages/cli/src/commands/init/__tests__/utils.test.ts diff --git a/packages/cli/src/commands/init/detect-agents.ts b/languages/typescript/packages/cli/src/commands/init/detect-agents.ts similarity index 100% rename from packages/cli/src/commands/init/detect-agents.ts rename to languages/typescript/packages/cli/src/commands/init/detect-agents.ts diff --git a/packages/cli/src/commands/init/doctrine/AGENTS-doctrine.md b/languages/typescript/packages/cli/src/commands/init/doctrine/AGENTS-doctrine.md similarity index 100% rename from packages/cli/src/commands/init/doctrine/AGENTS-doctrine.md rename to languages/typescript/packages/cli/src/commands/init/doctrine/AGENTS-doctrine.md diff --git a/packages/cli/src/commands/init/index.ts b/languages/typescript/packages/cli/src/commands/init/index.ts similarity index 100% rename from packages/cli/src/commands/init/index.ts rename to languages/typescript/packages/cli/src/commands/init/index.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/build-agents-md.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/build-agents-md.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/build-agents-md.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/build-agents-md.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/build-flow.integration.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/build-flow.integration.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/build-flow.integration.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/build-flow.integration.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/handoff-helpers.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/handoff-helpers.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/handoff-helpers.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/handoff-helpers.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/install-skills.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/install-skills.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/install-skills.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/install-skills.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/introspect.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/introspect.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/introspect.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/introspect.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/parse-plan.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/parse-plan.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/parse-plan.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/parse-plan.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/read-context.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/read-context.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/read-context.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/read-context.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/rollout-state.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/rollout-state.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/rollout-state.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/rollout-state.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts diff --git a/packages/cli/src/commands/init/lib/__tests__/write-context.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/write-context.test.ts similarity index 100% rename from packages/cli/src/commands/init/lib/__tests__/write-context.test.ts rename to languages/typescript/packages/cli/src/commands/init/lib/__tests__/write-context.test.ts diff --git a/packages/cli/src/commands/init/lib/build-agents-md.ts b/languages/typescript/packages/cli/src/commands/init/lib/build-agents-md.ts similarity index 100% rename from packages/cli/src/commands/init/lib/build-agents-md.ts rename to languages/typescript/packages/cli/src/commands/init/lib/build-agents-md.ts diff --git a/packages/cli/src/commands/init/lib/bundled-paths.ts b/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts similarity index 100% rename from packages/cli/src/commands/init/lib/bundled-paths.ts rename to languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts diff --git a/packages/cli/src/commands/init/lib/env-keys.ts b/languages/typescript/packages/cli/src/commands/init/lib/env-keys.ts similarity index 100% rename from packages/cli/src/commands/init/lib/env-keys.ts rename to languages/typescript/packages/cli/src/commands/init/lib/env-keys.ts diff --git a/packages/cli/src/commands/init/lib/handoff-helpers.ts b/languages/typescript/packages/cli/src/commands/init/lib/handoff-helpers.ts similarity index 100% rename from packages/cli/src/commands/init/lib/handoff-helpers.ts rename to languages/typescript/packages/cli/src/commands/init/lib/handoff-helpers.ts diff --git a/packages/cli/src/commands/init/lib/install-skills.ts b/languages/typescript/packages/cli/src/commands/init/lib/install-skills.ts similarity index 100% rename from packages/cli/src/commands/init/lib/install-skills.ts rename to languages/typescript/packages/cli/src/commands/init/lib/install-skills.ts diff --git a/packages/cli/src/commands/init/lib/introspect.ts b/languages/typescript/packages/cli/src/commands/init/lib/introspect.ts similarity index 100% rename from packages/cli/src/commands/init/lib/introspect.ts rename to languages/typescript/packages/cli/src/commands/init/lib/introspect.ts diff --git a/packages/cli/src/commands/init/lib/parse-plan.ts b/languages/typescript/packages/cli/src/commands/init/lib/parse-plan.ts similarity index 100% rename from packages/cli/src/commands/init/lib/parse-plan.ts rename to languages/typescript/packages/cli/src/commands/init/lib/parse-plan.ts diff --git a/packages/cli/src/commands/init/lib/read-context.ts b/languages/typescript/packages/cli/src/commands/init/lib/read-context.ts similarity index 100% rename from packages/cli/src/commands/init/lib/read-context.ts rename to languages/typescript/packages/cli/src/commands/init/lib/read-context.ts diff --git a/packages/cli/src/commands/init/lib/rollout-state.ts b/languages/typescript/packages/cli/src/commands/init/lib/rollout-state.ts similarity index 100% rename from packages/cli/src/commands/init/lib/rollout-state.ts rename to languages/typescript/packages/cli/src/commands/init/lib/rollout-state.ts diff --git a/packages/cli/src/commands/init/lib/sentinel-upsert.ts b/languages/typescript/packages/cli/src/commands/init/lib/sentinel-upsert.ts similarity index 100% rename from packages/cli/src/commands/init/lib/sentinel-upsert.ts rename to languages/typescript/packages/cli/src/commands/init/lib/sentinel-upsert.ts diff --git a/packages/cli/src/commands/init/lib/setup-prompt.ts b/languages/typescript/packages/cli/src/commands/init/lib/setup-prompt.ts similarity index 100% rename from packages/cli/src/commands/init/lib/setup-prompt.ts rename to languages/typescript/packages/cli/src/commands/init/lib/setup-prompt.ts diff --git a/packages/cli/src/commands/init/lib/write-context.ts b/languages/typescript/packages/cli/src/commands/init/lib/write-context.ts similarity index 100% rename from packages/cli/src/commands/init/lib/write-context.ts rename to languages/typescript/packages/cli/src/commands/init/lib/write-context.ts diff --git a/packages/cli/src/commands/init/providers/__tests__/base.test.ts b/languages/typescript/packages/cli/src/commands/init/providers/__tests__/base.test.ts similarity index 100% rename from packages/cli/src/commands/init/providers/__tests__/base.test.ts rename to languages/typescript/packages/cli/src/commands/init/providers/__tests__/base.test.ts diff --git a/packages/cli/src/commands/init/providers/__tests__/drizzle.test.ts b/languages/typescript/packages/cli/src/commands/init/providers/__tests__/drizzle.test.ts similarity index 100% rename from packages/cli/src/commands/init/providers/__tests__/drizzle.test.ts rename to languages/typescript/packages/cli/src/commands/init/providers/__tests__/drizzle.test.ts diff --git a/packages/cli/src/commands/init/providers/__tests__/prisma.test.ts b/languages/typescript/packages/cli/src/commands/init/providers/__tests__/prisma.test.ts similarity index 100% rename from packages/cli/src/commands/init/providers/__tests__/prisma.test.ts rename to languages/typescript/packages/cli/src/commands/init/providers/__tests__/prisma.test.ts diff --git a/packages/cli/src/commands/init/providers/__tests__/supabase.test.ts b/languages/typescript/packages/cli/src/commands/init/providers/__tests__/supabase.test.ts similarity index 100% rename from packages/cli/src/commands/init/providers/__tests__/supabase.test.ts rename to languages/typescript/packages/cli/src/commands/init/providers/__tests__/supabase.test.ts diff --git a/packages/cli/src/commands/init/providers/base.ts b/languages/typescript/packages/cli/src/commands/init/providers/base.ts similarity index 100% rename from packages/cli/src/commands/init/providers/base.ts rename to languages/typescript/packages/cli/src/commands/init/providers/base.ts diff --git a/packages/cli/src/commands/init/providers/drizzle.ts b/languages/typescript/packages/cli/src/commands/init/providers/drizzle.ts similarity index 100% rename from packages/cli/src/commands/init/providers/drizzle.ts rename to languages/typescript/packages/cli/src/commands/init/providers/drizzle.ts diff --git a/packages/cli/src/commands/init/providers/prisma.ts b/languages/typescript/packages/cli/src/commands/init/providers/prisma.ts similarity index 100% rename from packages/cli/src/commands/init/providers/prisma.ts rename to languages/typescript/packages/cli/src/commands/init/providers/prisma.ts diff --git a/packages/cli/src/commands/init/providers/supabase.ts b/languages/typescript/packages/cli/src/commands/init/providers/supabase.ts similarity index 100% rename from packages/cli/src/commands/init/providers/supabase.ts rename to languages/typescript/packages/cli/src/commands/init/providers/supabase.ts diff --git a/packages/cli/src/commands/init/steps/__tests__/build-schema.test.ts b/languages/typescript/packages/cli/src/commands/init/steps/__tests__/build-schema.test.ts similarity index 100% rename from packages/cli/src/commands/init/steps/__tests__/build-schema.test.ts rename to languages/typescript/packages/cli/src/commands/init/steps/__tests__/build-schema.test.ts diff --git a/packages/cli/src/commands/init/steps/__tests__/install-deps.test.ts b/languages/typescript/packages/cli/src/commands/init/steps/__tests__/install-deps.test.ts similarity index 100% rename from packages/cli/src/commands/init/steps/__tests__/install-deps.test.ts rename to languages/typescript/packages/cli/src/commands/init/steps/__tests__/install-deps.test.ts diff --git a/packages/cli/src/commands/init/steps/__tests__/install-eql.test.ts b/languages/typescript/packages/cli/src/commands/init/steps/__tests__/install-eql.test.ts similarity index 100% rename from packages/cli/src/commands/init/steps/__tests__/install-eql.test.ts rename to languages/typescript/packages/cli/src/commands/init/steps/__tests__/install-eql.test.ts diff --git a/packages/cli/src/commands/init/steps/__tests__/install-skills.test.ts b/languages/typescript/packages/cli/src/commands/init/steps/__tests__/install-skills.test.ts similarity index 100% rename from packages/cli/src/commands/init/steps/__tests__/install-skills.test.ts rename to languages/typescript/packages/cli/src/commands/init/steps/__tests__/install-skills.test.ts diff --git a/packages/cli/src/commands/init/steps/__tests__/resolve-database.test.ts b/languages/typescript/packages/cli/src/commands/init/steps/__tests__/resolve-database.test.ts similarity index 100% rename from packages/cli/src/commands/init/steps/__tests__/resolve-database.test.ts rename to languages/typescript/packages/cli/src/commands/init/steps/__tests__/resolve-database.test.ts diff --git a/packages/cli/src/commands/init/steps/authenticate.ts b/languages/typescript/packages/cli/src/commands/init/steps/authenticate.ts similarity index 100% rename from packages/cli/src/commands/init/steps/authenticate.ts rename to languages/typescript/packages/cli/src/commands/init/steps/authenticate.ts diff --git a/packages/cli/src/commands/init/steps/build-schema.ts b/languages/typescript/packages/cli/src/commands/init/steps/build-schema.ts similarity index 100% rename from packages/cli/src/commands/init/steps/build-schema.ts rename to languages/typescript/packages/cli/src/commands/init/steps/build-schema.ts diff --git a/packages/cli/src/commands/init/steps/gather-context.ts b/languages/typescript/packages/cli/src/commands/init/steps/gather-context.ts similarity index 100% rename from packages/cli/src/commands/init/steps/gather-context.ts rename to languages/typescript/packages/cli/src/commands/init/steps/gather-context.ts diff --git a/packages/cli/src/commands/init/steps/install-deps.ts b/languages/typescript/packages/cli/src/commands/init/steps/install-deps.ts similarity index 100% rename from packages/cli/src/commands/init/steps/install-deps.ts rename to languages/typescript/packages/cli/src/commands/init/steps/install-deps.ts diff --git a/packages/cli/src/commands/init/steps/install-eql.ts b/languages/typescript/packages/cli/src/commands/init/steps/install-eql.ts similarity index 100% rename from packages/cli/src/commands/init/steps/install-eql.ts rename to languages/typescript/packages/cli/src/commands/init/steps/install-eql.ts diff --git a/packages/cli/src/commands/init/steps/install-skills.ts b/languages/typescript/packages/cli/src/commands/init/steps/install-skills.ts similarity index 100% rename from packages/cli/src/commands/init/steps/install-skills.ts rename to languages/typescript/packages/cli/src/commands/init/steps/install-skills.ts diff --git a/packages/cli/src/commands/init/steps/resolve-database.ts b/languages/typescript/packages/cli/src/commands/init/steps/resolve-database.ts similarity index 100% rename from packages/cli/src/commands/init/steps/resolve-database.ts rename to languages/typescript/packages/cli/src/commands/init/steps/resolve-database.ts diff --git a/packages/cli/src/commands/init/types.ts b/languages/typescript/packages/cli/src/commands/init/types.ts similarity index 100% rename from packages/cli/src/commands/init/types.ts rename to languages/typescript/packages/cli/src/commands/init/types.ts diff --git a/packages/cli/src/commands/init/utils.ts b/languages/typescript/packages/cli/src/commands/init/utils.ts similarity index 100% rename from packages/cli/src/commands/init/utils.ts rename to languages/typescript/packages/cli/src/commands/init/utils.ts diff --git a/packages/cli/src/commands/manifest/index.ts b/languages/typescript/packages/cli/src/commands/manifest/index.ts similarity index 100% rename from packages/cli/src/commands/manifest/index.ts rename to languages/typescript/packages/cli/src/commands/manifest/index.ts diff --git a/packages/cli/src/commands/plan/index.ts b/languages/typescript/packages/cli/src/commands/plan/index.ts similarity index 100% rename from packages/cli/src/commands/plan/index.ts rename to languages/typescript/packages/cli/src/commands/plan/index.ts diff --git a/packages/cli/src/commands/schema/build.ts b/languages/typescript/packages/cli/src/commands/schema/build.ts similarity index 100% rename from packages/cli/src/commands/schema/build.ts rename to languages/typescript/packages/cli/src/commands/schema/build.ts diff --git a/packages/cli/src/commands/status/__tests__/status.test.ts b/languages/typescript/packages/cli/src/commands/status/__tests__/status.test.ts similarity index 100% rename from packages/cli/src/commands/status/__tests__/status.test.ts rename to languages/typescript/packages/cli/src/commands/status/__tests__/status.test.ts diff --git a/packages/cli/src/commands/status/index.ts b/languages/typescript/packages/cli/src/commands/status/index.ts similarity index 100% rename from packages/cli/src/commands/status/index.ts rename to languages/typescript/packages/cli/src/commands/status/index.ts diff --git a/packages/cli/src/commands/status/quest.ts b/languages/typescript/packages/cli/src/commands/status/quest.ts similarity index 100% rename from packages/cli/src/commands/status/quest.ts rename to languages/typescript/packages/cli/src/commands/status/quest.ts diff --git a/packages/cli/src/commands/status/render.ts b/languages/typescript/packages/cli/src/commands/status/render.ts similarity index 100% rename from packages/cli/src/commands/status/render.ts rename to languages/typescript/packages/cli/src/commands/status/render.ts diff --git a/packages/cli/src/commands/telemetry/index.ts b/languages/typescript/packages/cli/src/commands/telemetry/index.ts similarity index 100% rename from packages/cli/src/commands/telemetry/index.ts rename to languages/typescript/packages/cli/src/commands/telemetry/index.ts diff --git a/packages/cli/src/commands/wizard/__tests__/index.test.ts b/languages/typescript/packages/cli/src/commands/wizard/__tests__/index.test.ts similarity index 100% rename from packages/cli/src/commands/wizard/__tests__/index.test.ts rename to languages/typescript/packages/cli/src/commands/wizard/__tests__/index.test.ts diff --git a/packages/cli/src/commands/wizard/index.ts b/languages/typescript/packages/cli/src/commands/wizard/index.ts similarity index 100% rename from packages/cli/src/commands/wizard/index.ts rename to languages/typescript/packages/cli/src/commands/wizard/index.ts diff --git a/packages/cli/src/config/__tests__/load-encrypt-schemas.test.ts b/languages/typescript/packages/cli/src/config/__tests__/load-encrypt-schemas.test.ts similarity index 100% rename from packages/cli/src/config/__tests__/load-encrypt-schemas.test.ts rename to languages/typescript/packages/cli/src/config/__tests__/load-encrypt-schemas.test.ts diff --git a/packages/cli/src/config/__tests__/missing-package.test.ts b/languages/typescript/packages/cli/src/config/__tests__/missing-package.test.ts similarity index 100% rename from packages/cli/src/config/__tests__/missing-package.test.ts rename to languages/typescript/packages/cli/src/config/__tests__/missing-package.test.ts diff --git a/packages/cli/src/config/__tests__/tty.test.ts b/languages/typescript/packages/cli/src/config/__tests__/tty.test.ts similarity index 100% rename from packages/cli/src/config/__tests__/tty.test.ts rename to languages/typescript/packages/cli/src/config/__tests__/tty.test.ts diff --git a/packages/cli/src/config/database-url.ts b/languages/typescript/packages/cli/src/config/database-url.ts similarity index 100% rename from packages/cli/src/config/database-url.ts rename to languages/typescript/packages/cli/src/config/database-url.ts diff --git a/packages/cli/src/config/index.ts b/languages/typescript/packages/cli/src/config/index.ts similarity index 100% rename from packages/cli/src/config/index.ts rename to languages/typescript/packages/cli/src/config/index.ts diff --git a/packages/cli/src/config/missing-package.ts b/languages/typescript/packages/cli/src/config/missing-package.ts similarity index 100% rename from packages/cli/src/config/missing-package.ts rename to languages/typescript/packages/cli/src/config/missing-package.ts diff --git a/packages/cli/src/config/tty.ts b/languages/typescript/packages/cli/src/config/tty.ts similarity index 100% rename from packages/cli/src/config/tty.ts rename to languages/typescript/packages/cli/src/config/tty.ts diff --git a/packages/cli/src/db/__tests__/client-wrap.test.ts b/languages/typescript/packages/cli/src/db/__tests__/client-wrap.test.ts similarity index 100% rename from packages/cli/src/db/__tests__/client-wrap.test.ts rename to languages/typescript/packages/cli/src/db/__tests__/client-wrap.test.ts diff --git a/packages/cli/src/db/__tests__/config.test.ts b/languages/typescript/packages/cli/src/db/__tests__/config.test.ts similarity index 100% rename from packages/cli/src/db/__tests__/config.test.ts rename to languages/typescript/packages/cli/src/db/__tests__/config.test.ts diff --git a/packages/cli/src/db/__tests__/no-sslmode-advisory.test.ts b/languages/typescript/packages/cli/src/db/__tests__/no-sslmode-advisory.test.ts similarity index 100% rename from packages/cli/src/db/__tests__/no-sslmode-advisory.test.ts rename to languages/typescript/packages/cli/src/db/__tests__/no-sslmode-advisory.test.ts diff --git a/packages/cli/src/db/__tests__/pg-construction-lint.test.ts b/languages/typescript/packages/cli/src/db/__tests__/pg-construction-lint.test.ts similarity index 100% rename from packages/cli/src/db/__tests__/pg-construction-lint.test.ts rename to languages/typescript/packages/cli/src/db/__tests__/pg-construction-lint.test.ts diff --git a/packages/cli/src/db/client.ts b/languages/typescript/packages/cli/src/db/client.ts similarity index 100% rename from packages/cli/src/db/client.ts rename to languages/typescript/packages/cli/src/db/client.ts diff --git a/packages/cli/src/db/config.ts b/languages/typescript/packages/cli/src/db/config.ts similarity index 100% rename from packages/cli/src/db/config.ts rename to languages/typescript/packages/cli/src/db/config.ts diff --git a/packages/cli/src/db/supabase-ca.ts b/languages/typescript/packages/cli/src/db/supabase-ca.ts similarity index 100% rename from packages/cli/src/db/supabase-ca.ts rename to languages/typescript/packages/cli/src/db/supabase-ca.ts diff --git a/packages/cli/src/index.ts b/languages/typescript/packages/cli/src/index.ts similarity index 100% rename from packages/cli/src/index.ts rename to languages/typescript/packages/cli/src/index.ts diff --git a/packages/cli/src/installer/__tests__/bundle-digest.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/bundle-digest.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/bundle-digest.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/bundle-digest.test.ts diff --git a/packages/cli/src/installer/__tests__/guarded-grants.live.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/guarded-grants.live.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/guarded-grants.live.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/guarded-grants.live.test.ts diff --git a/packages/cli/src/installer/__tests__/installation-state.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/installation-state.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/installation-state.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/installation-state.test.ts diff --git a/packages/cli/src/installer/__tests__/ore.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/ore.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/ore.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/ore.test.ts diff --git a/packages/cli/src/installer/__tests__/preflight.live.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/preflight.live.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/preflight.live.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/preflight.live.test.ts diff --git a/packages/cli/src/installer/__tests__/reinstall.live.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/reinstall.live.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/reinstall.live.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/reinstall.live.test.ts diff --git a/packages/cli/src/installer/__tests__/restoration-scenarios.ts b/languages/typescript/packages/cli/src/installer/__tests__/restoration-scenarios.ts similarity index 100% rename from packages/cli/src/installer/__tests__/restoration-scenarios.ts rename to languages/typescript/packages/cli/src/installer/__tests__/restoration-scenarios.ts diff --git a/packages/cli/src/installer/__tests__/upgrade-encrypted-indexes.live.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/upgrade-encrypted-indexes.live.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/upgrade-encrypted-indexes.live.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/upgrade-encrypted-indexes.live.test.ts diff --git a/packages/cli/src/installer/__tests__/verify.live.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/verify.live.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/verify.live.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/verify.live.test.ts diff --git a/packages/cli/src/installer/__tests__/verify.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/verify.test.ts similarity index 100% rename from packages/cli/src/installer/__tests__/verify.test.ts rename to languages/typescript/packages/cli/src/installer/__tests__/verify.test.ts diff --git a/packages/cli/src/installer/bundle-digest.ts b/languages/typescript/packages/cli/src/installer/bundle-digest.ts similarity index 100% rename from packages/cli/src/installer/bundle-digest.ts rename to languages/typescript/packages/cli/src/installer/bundle-digest.ts diff --git a/packages/cli/src/installer/derived-search-index-restoration.ts b/languages/typescript/packages/cli/src/installer/derived-search-index-restoration.ts similarity index 100% rename from packages/cli/src/installer/derived-search-index-restoration.ts rename to languages/typescript/packages/cli/src/installer/derived-search-index-restoration.ts diff --git a/packages/cli/src/installer/eql-bundle.ts b/languages/typescript/packages/cli/src/installer/eql-bundle.ts similarity index 100% rename from packages/cli/src/installer/eql-bundle.ts rename to languages/typescript/packages/cli/src/installer/eql-bundle.ts diff --git a/packages/cli/src/installer/grants.ts b/languages/typescript/packages/cli/src/installer/grants.ts similarity index 100% rename from packages/cli/src/installer/grants.ts rename to languages/typescript/packages/cli/src/installer/grants.ts diff --git a/packages/cli/src/installer/index.ts b/languages/typescript/packages/cli/src/installer/index.ts similarity index 100% rename from packages/cli/src/installer/index.ts rename to languages/typescript/packages/cli/src/installer/index.ts diff --git a/packages/cli/src/installer/installation-state.ts b/languages/typescript/packages/cli/src/installer/installation-state.ts similarity index 100% rename from packages/cli/src/installer/installation-state.ts rename to languages/typescript/packages/cli/src/installer/installation-state.ts diff --git a/packages/cli/src/installer/ore.ts b/languages/typescript/packages/cli/src/installer/ore.ts similarity index 100% rename from packages/cli/src/installer/ore.ts rename to languages/typescript/packages/cli/src/installer/ore.ts diff --git a/packages/cli/src/installer/verify.ts b/languages/typescript/packages/cli/src/installer/verify.ts similarity index 100% rename from packages/cli/src/installer/verify.ts rename to languages/typescript/packages/cli/src/installer/verify.ts diff --git a/packages/cli/src/messages.ts b/languages/typescript/packages/cli/src/messages.ts similarity index 100% rename from packages/cli/src/messages.ts rename to languages/typescript/packages/cli/src/messages.ts diff --git a/packages/cli/src/module-error.ts b/languages/typescript/packages/cli/src/module-error.ts similarity index 100% rename from packages/cli/src/module-error.ts rename to languages/typescript/packages/cli/src/module-error.ts diff --git a/packages/cli/src/native.ts b/languages/typescript/packages/cli/src/native.ts similarity index 100% rename from packages/cli/src/native.ts rename to languages/typescript/packages/cli/src/native.ts diff --git a/packages/cli/src/release-train.ts b/languages/typescript/packages/cli/src/release-train.ts similarity index 100% rename from packages/cli/src/release-train.ts rename to languages/typescript/packages/cli/src/release-train.ts diff --git a/packages/cli/src/runtime-versions.ts b/languages/typescript/packages/cli/src/runtime-versions.ts similarity index 100% rename from packages/cli/src/runtime-versions.ts rename to languages/typescript/packages/cli/src/runtime-versions.ts diff --git a/packages/cli/src/telemetry/__tests__/classify-command.test.ts b/languages/typescript/packages/cli/src/telemetry/__tests__/classify-command.test.ts similarity index 100% rename from packages/cli/src/telemetry/__tests__/classify-command.test.ts rename to languages/typescript/packages/cli/src/telemetry/__tests__/classify-command.test.ts diff --git a/packages/cli/src/telemetry/__tests__/state.test.ts b/languages/typescript/packages/cli/src/telemetry/__tests__/state.test.ts similarity index 100% rename from packages/cli/src/telemetry/__tests__/state.test.ts rename to languages/typescript/packages/cli/src/telemetry/__tests__/state.test.ts diff --git a/packages/cli/src/telemetry/__tests__/telemetry-lifecycle.test.ts b/languages/typescript/packages/cli/src/telemetry/__tests__/telemetry-lifecycle.test.ts similarity index 100% rename from packages/cli/src/telemetry/__tests__/telemetry-lifecycle.test.ts rename to languages/typescript/packages/cli/src/telemetry/__tests__/telemetry-lifecycle.test.ts diff --git a/packages/cli/src/telemetry/__tests__/telemetry.test.ts b/languages/typescript/packages/cli/src/telemetry/__tests__/telemetry.test.ts similarity index 100% rename from packages/cli/src/telemetry/__tests__/telemetry.test.ts rename to languages/typescript/packages/cli/src/telemetry/__tests__/telemetry.test.ts diff --git a/packages/cli/src/telemetry/classify-command.ts b/languages/typescript/packages/cli/src/telemetry/classify-command.ts similarity index 100% rename from packages/cli/src/telemetry/classify-command.ts rename to languages/typescript/packages/cli/src/telemetry/classify-command.ts diff --git a/packages/cli/src/telemetry/index.ts b/languages/typescript/packages/cli/src/telemetry/index.ts similarity index 100% rename from packages/cli/src/telemetry/index.ts rename to languages/typescript/packages/cli/src/telemetry/index.ts diff --git a/packages/cli/src/telemetry/state.ts b/languages/typescript/packages/cli/src/telemetry/state.ts similarity index 100% rename from packages/cli/src/telemetry/state.ts rename to languages/typescript/packages/cli/src/telemetry/state.ts diff --git a/packages/cli/tests/e2e/auth-login-cancel.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/auth-login-cancel.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/auth-login-cancel.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/auth-login-cancel.e2e.test.ts diff --git a/packages/cli/tests/e2e/auth-non-interactive.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/auth-non-interactive.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/auth-non-interactive.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/auth-non-interactive.e2e.test.ts diff --git a/packages/cli/tests/e2e/command-help.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/command-help.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/command-help.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/command-help.e2e.test.ts diff --git a/packages/cli/tests/e2e/config-scaffold.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/config-scaffold.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/config-scaffold.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/config-scaffold.e2e.test.ts diff --git a/packages/cli/tests/e2e/database-url.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/database-url.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/database-url.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/database-url.e2e.test.ts diff --git a/packages/cli/tests/e2e/doctor-missing-binary.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/doctor-missing-binary.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/doctor-missing-binary.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/doctor-missing-binary.e2e.test.ts diff --git a/packages/cli/tests/e2e/doctor-probe-classification.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/doctor-probe-classification.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/doctor-probe-classification.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/doctor-probe-classification.e2e.test.ts diff --git a/packages/cli/tests/e2e/doctor.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/doctor.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/doctor.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/doctor.e2e.test.ts diff --git a/packages/cli/tests/e2e/env-non-interactive.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/env-non-interactive.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/env-non-interactive.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/env-non-interactive.e2e.test.ts diff --git a/packages/cli/tests/e2e/eql-install-prisma-next.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/eql-install-prisma-next.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/eql-install-prisma-next.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/eql-install-prisma-next.e2e.test.ts diff --git a/packages/cli/tests/e2e/eql-repair.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/eql-repair.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/eql-repair.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/eql-repair.e2e.test.ts diff --git a/packages/cli/tests/e2e/impl-non-tty.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/impl-non-tty.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/impl-non-tty.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/impl-non-tty.e2e.test.ts diff --git a/packages/cli/tests/e2e/impl-pty-ci.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/impl-pty-ci.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/impl-pty-ci.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/impl-pty-ci.e2e.test.ts diff --git a/packages/cli/tests/e2e/manifest.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/manifest.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/manifest.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/manifest.e2e.test.ts diff --git a/packages/cli/tests/e2e/plan-complete-rollout.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/plan-complete-rollout.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/plan-complete-rollout.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/plan-complete-rollout.e2e.test.ts diff --git a/packages/cli/tests/e2e/plan-outcome.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/plan-outcome.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/plan-outcome.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/plan-outcome.e2e.test.ts diff --git a/packages/cli/tests/e2e/runner-aware-help.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/runner-aware-help.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/runner-aware-help.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/runner-aware-help.e2e.test.ts diff --git a/packages/cli/tests/e2e/runtime-versions-embed.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/runtime-versions-embed.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/runtime-versions-embed.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/runtime-versions-embed.e2e.test.ts diff --git a/packages/cli/tests/e2e/smoke.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/smoke.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/smoke.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/smoke.e2e.test.ts diff --git a/packages/cli/tests/e2e/v2-retirement.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/v2-retirement.e2e.test.ts similarity index 100% rename from packages/cli/tests/e2e/v2-retirement.e2e.test.ts rename to languages/typescript/packages/cli/tests/e2e/v2-retirement.e2e.test.ts diff --git a/packages/cli/tests/helpers/pty.ts b/languages/typescript/packages/cli/tests/helpers/pty.ts similarity index 100% rename from packages/cli/tests/helpers/pty.ts rename to languages/typescript/packages/cli/tests/helpers/pty.ts diff --git a/packages/cli/tests/helpers/run.test.ts b/languages/typescript/packages/cli/tests/helpers/run.test.ts similarity index 100% rename from packages/cli/tests/helpers/run.test.ts rename to languages/typescript/packages/cli/tests/helpers/run.test.ts diff --git a/packages/cli/tests/helpers/run.ts b/languages/typescript/packages/cli/tests/helpers/run.ts similarity index 100% rename from packages/cli/tests/helpers/run.ts rename to languages/typescript/packages/cli/tests/helpers/run.ts diff --git a/packages/cli/tests/helpers/spawn-piped.ts b/languages/typescript/packages/cli/tests/helpers/spawn-piped.ts similarity index 100% rename from packages/cli/tests/helpers/spawn-piped.ts rename to languages/typescript/packages/cli/tests/helpers/spawn-piped.ts diff --git a/packages/cli/tsconfig.json b/languages/typescript/packages/cli/tsconfig.json similarity index 100% rename from packages/cli/tsconfig.json rename to languages/typescript/packages/cli/tsconfig.json diff --git a/packages/cli/tsconfig.scaffold.json b/languages/typescript/packages/cli/tsconfig.scaffold.json similarity index 100% rename from packages/cli/tsconfig.scaffold.json rename to languages/typescript/packages/cli/tsconfig.scaffold.json diff --git a/packages/cli/tsup.config.ts b/languages/typescript/packages/cli/tsup.config.ts similarity index 100% rename from packages/cli/tsup.config.ts rename to languages/typescript/packages/cli/tsup.config.ts diff --git a/packages/cli/vitest.config.ts b/languages/typescript/packages/cli/vitest.config.ts similarity index 100% rename from packages/cli/vitest.config.ts rename to languages/typescript/packages/cli/vitest.config.ts diff --git a/packages/cli/vitest.integration.config.ts b/languages/typescript/packages/cli/vitest.integration.config.ts similarity index 100% rename from packages/cli/vitest.integration.config.ts rename to languages/typescript/packages/cli/vitest.integration.config.ts diff --git a/packages/migrate/CHANGELOG.md b/languages/typescript/packages/migrate/CHANGELOG.md similarity index 100% rename from packages/migrate/CHANGELOG.md rename to languages/typescript/packages/migrate/CHANGELOG.md diff --git a/packages/migrate/README.md b/languages/typescript/packages/migrate/README.md similarity index 100% rename from packages/migrate/README.md rename to languages/typescript/packages/migrate/README.md diff --git a/packages/migrate/package.json b/languages/typescript/packages/migrate/package.json similarity index 100% rename from packages/migrate/package.json rename to languages/typescript/packages/migrate/package.json diff --git a/packages/migrate/src/__tests__/backfill-v3.integration.test.ts b/languages/typescript/packages/migrate/src/__tests__/backfill-v3.integration.test.ts similarity index 100% rename from packages/migrate/src/__tests__/backfill-v3.integration.test.ts rename to languages/typescript/packages/migrate/src/__tests__/backfill-v3.integration.test.ts diff --git a/packages/migrate/src/__tests__/backfill.integration.test.ts b/languages/typescript/packages/migrate/src/__tests__/backfill.integration.test.ts similarity index 100% rename from packages/migrate/src/__tests__/backfill.integration.test.ts rename to languages/typescript/packages/migrate/src/__tests__/backfill.integration.test.ts diff --git a/packages/migrate/src/__tests__/manifest.test.ts b/languages/typescript/packages/migrate/src/__tests__/manifest.test.ts similarity index 100% rename from packages/migrate/src/__tests__/manifest.test.ts rename to languages/typescript/packages/migrate/src/__tests__/manifest.test.ts diff --git a/packages/migrate/src/__tests__/sql.test.ts b/languages/typescript/packages/migrate/src/__tests__/sql.test.ts similarity index 100% rename from packages/migrate/src/__tests__/sql.test.ts rename to languages/typescript/packages/migrate/src/__tests__/sql.test.ts diff --git a/packages/migrate/src/__tests__/state.test.ts b/languages/typescript/packages/migrate/src/__tests__/state.test.ts similarity index 100% rename from packages/migrate/src/__tests__/state.test.ts rename to languages/typescript/packages/migrate/src/__tests__/state.test.ts diff --git a/packages/migrate/src/__tests__/v2-retirement.test.ts b/languages/typescript/packages/migrate/src/__tests__/v2-retirement.test.ts similarity index 100% rename from packages/migrate/src/__tests__/v2-retirement.test.ts rename to languages/typescript/packages/migrate/src/__tests__/v2-retirement.test.ts diff --git a/packages/migrate/src/__tests__/version.test.ts b/languages/typescript/packages/migrate/src/__tests__/version.test.ts similarity index 100% rename from packages/migrate/src/__tests__/version.test.ts rename to languages/typescript/packages/migrate/src/__tests__/version.test.ts diff --git a/packages/migrate/src/backfill.ts b/languages/typescript/packages/migrate/src/backfill.ts similarity index 100% rename from packages/migrate/src/backfill.ts rename to languages/typescript/packages/migrate/src/backfill.ts diff --git a/packages/migrate/src/cursor.ts b/languages/typescript/packages/migrate/src/cursor.ts similarity index 100% rename from packages/migrate/src/cursor.ts rename to languages/typescript/packages/migrate/src/cursor.ts diff --git a/packages/migrate/src/index.ts b/languages/typescript/packages/migrate/src/index.ts similarity index 100% rename from packages/migrate/src/index.ts rename to languages/typescript/packages/migrate/src/index.ts diff --git a/packages/migrate/src/install.ts b/languages/typescript/packages/migrate/src/install.ts similarity index 100% rename from packages/migrate/src/install.ts rename to languages/typescript/packages/migrate/src/install.ts diff --git a/packages/migrate/src/manifest.ts b/languages/typescript/packages/migrate/src/manifest.ts similarity index 100% rename from packages/migrate/src/manifest.ts rename to languages/typescript/packages/migrate/src/manifest.ts diff --git a/packages/migrate/src/sql.ts b/languages/typescript/packages/migrate/src/sql.ts similarity index 100% rename from packages/migrate/src/sql.ts rename to languages/typescript/packages/migrate/src/sql.ts diff --git a/packages/migrate/src/state.ts b/languages/typescript/packages/migrate/src/state.ts similarity index 100% rename from packages/migrate/src/state.ts rename to languages/typescript/packages/migrate/src/state.ts diff --git a/packages/migrate/src/version.ts b/languages/typescript/packages/migrate/src/version.ts similarity index 100% rename from packages/migrate/src/version.ts rename to languages/typescript/packages/migrate/src/version.ts diff --git a/packages/migrate/tsconfig.json b/languages/typescript/packages/migrate/tsconfig.json similarity index 100% rename from packages/migrate/tsconfig.json rename to languages/typescript/packages/migrate/tsconfig.json diff --git a/packages/migrate/tsup.config.ts b/languages/typescript/packages/migrate/tsup.config.ts similarity index 100% rename from packages/migrate/tsup.config.ts rename to languages/typescript/packages/migrate/tsup.config.ts diff --git a/packages/migrate/vitest.config.ts b/languages/typescript/packages/migrate/vitest.config.ts similarity index 100% rename from packages/migrate/vitest.config.ts rename to languages/typescript/packages/migrate/vitest.config.ts diff --git a/packages/nextjs/CHANGELOG.md b/languages/typescript/packages/nextjs/CHANGELOG.md similarity index 100% rename from packages/nextjs/CHANGELOG.md rename to languages/typescript/packages/nextjs/CHANGELOG.md diff --git a/packages/nextjs/README.md b/languages/typescript/packages/nextjs/README.md similarity index 100% rename from packages/nextjs/README.md rename to languages/typescript/packages/nextjs/README.md diff --git a/packages/nextjs/__tests__/cts-refusal.test.ts b/languages/typescript/packages/nextjs/__tests__/cts-refusal.test.ts similarity index 100% rename from packages/nextjs/__tests__/cts-refusal.test.ts rename to languages/typescript/packages/nextjs/__tests__/cts-refusal.test.ts diff --git a/packages/nextjs/__tests__/nextjs.test.ts b/languages/typescript/packages/nextjs/__tests__/nextjs.test.ts similarity index 100% rename from packages/nextjs/__tests__/nextjs.test.ts rename to languages/typescript/packages/nextjs/__tests__/nextjs.test.ts diff --git a/packages/nextjs/package.json b/languages/typescript/packages/nextjs/package.json similarity index 100% rename from packages/nextjs/package.json rename to languages/typescript/packages/nextjs/package.json diff --git a/packages/nextjs/src/clerk/index.ts b/languages/typescript/packages/nextjs/src/clerk/index.ts similarity index 100% rename from packages/nextjs/src/clerk/index.ts rename to languages/typescript/packages/nextjs/src/clerk/index.ts diff --git a/packages/nextjs/src/cts/index.ts b/languages/typescript/packages/nextjs/src/cts/index.ts similarity index 100% rename from packages/nextjs/src/cts/index.ts rename to languages/typescript/packages/nextjs/src/cts/index.ts diff --git a/packages/nextjs/src/index.ts b/languages/typescript/packages/nextjs/src/index.ts similarity index 100% rename from packages/nextjs/src/index.ts rename to languages/typescript/packages/nextjs/src/index.ts diff --git a/packages/nextjs/tsconfig.jest.json b/languages/typescript/packages/nextjs/tsconfig.jest.json similarity index 100% rename from packages/nextjs/tsconfig.jest.json rename to languages/typescript/packages/nextjs/tsconfig.jest.json diff --git a/packages/nextjs/tsconfig.json b/languages/typescript/packages/nextjs/tsconfig.json similarity index 100% rename from packages/nextjs/tsconfig.json rename to languages/typescript/packages/nextjs/tsconfig.json diff --git a/packages/nextjs/tsup.config.ts b/languages/typescript/packages/nextjs/tsup.config.ts similarity index 100% rename from packages/nextjs/tsup.config.ts rename to languages/typescript/packages/nextjs/tsup.config.ts diff --git a/packages/protect-ffi/.gitignore b/languages/typescript/packages/protect-ffi/.gitignore similarity index 100% rename from packages/protect-ffi/.gitignore rename to languages/typescript/packages/protect-ffi/.gitignore diff --git a/packages/protect-ffi/CHANGELOG.md b/languages/typescript/packages/protect-ffi/CHANGELOG.md similarity index 100% rename from packages/protect-ffi/CHANGELOG.md rename to languages/typescript/packages/protect-ffi/CHANGELOG.md diff --git a/packages/protect-ffi/Cargo.lock b/languages/typescript/packages/protect-ffi/Cargo.lock similarity index 100% rename from packages/protect-ffi/Cargo.lock rename to languages/typescript/packages/protect-ffi/Cargo.lock diff --git a/packages/protect-ffi/Cargo.toml b/languages/typescript/packages/protect-ffi/Cargo.toml similarity index 100% rename from packages/protect-ffi/Cargo.toml rename to languages/typescript/packages/protect-ffi/Cargo.toml diff --git a/packages/protect-ffi/LICENSE.md b/languages/typescript/packages/protect-ffi/LICENSE.md similarity index 100% rename from packages/protect-ffi/LICENSE.md rename to languages/typescript/packages/protect-ffi/LICENSE.md diff --git a/packages/protect-ffi/README.md b/languages/typescript/packages/protect-ffi/README.md similarity index 100% rename from packages/protect-ffi/README.md rename to languages/typescript/packages/protect-ffi/README.md diff --git a/packages/protect-ffi/crates/protect-ffi/Cargo.toml b/languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml similarity index 100% rename from packages/protect-ffi/crates/protect-ffi/Cargo.toml rename to languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml diff --git a/packages/protect-ffi/crates/protect-ffi/src/client_options.rs b/languages/typescript/packages/protect-ffi/crates/protect-ffi/src/client_options.rs similarity index 100% rename from packages/protect-ffi/crates/protect-ffi/src/client_options.rs rename to languages/typescript/packages/protect-ffi/crates/protect-ffi/src/client_options.rs diff --git a/packages/protect-ffi/crates/protect-ffi/src/encrypt_config.rs b/languages/typescript/packages/protect-ffi/crates/protect-ffi/src/encrypt_config.rs similarity index 100% rename from packages/protect-ffi/crates/protect-ffi/src/encrypt_config.rs rename to languages/typescript/packages/protect-ffi/crates/protect-ffi/src/encrypt_config.rs diff --git a/packages/protect-ffi/crates/protect-ffi/src/eql_v3.rs b/languages/typescript/packages/protect-ffi/crates/protect-ffi/src/eql_v3.rs similarity index 100% rename from packages/protect-ffi/crates/protect-ffi/src/eql_v3.rs rename to languages/typescript/packages/protect-ffi/crates/protect-ffi/src/eql_v3.rs diff --git a/packages/protect-ffi/crates/protect-ffi/src/js_plaintext.rs b/languages/typescript/packages/protect-ffi/crates/protect-ffi/src/js_plaintext.rs similarity index 100% rename from packages/protect-ffi/crates/protect-ffi/src/js_plaintext.rs rename to languages/typescript/packages/protect-ffi/crates/protect-ffi/src/js_plaintext.rs diff --git a/packages/protect-ffi/crates/protect-ffi/src/lib.rs b/languages/typescript/packages/protect-ffi/crates/protect-ffi/src/lib.rs similarity index 100% rename from packages/protect-ffi/crates/protect-ffi/src/lib.rs rename to languages/typescript/packages/protect-ffi/crates/protect-ffi/src/lib.rs diff --git a/packages/protect-ffi/crates/protect-ffi/src/query_op.rs b/languages/typescript/packages/protect-ffi/crates/protect-ffi/src/query_op.rs similarity index 100% rename from packages/protect-ffi/crates/protect-ffi/src/query_op.rs rename to languages/typescript/packages/protect-ffi/crates/protect-ffi/src/query_op.rs diff --git a/packages/protect-ffi/crates/protect-ffi/src/wasm.rs b/languages/typescript/packages/protect-ffi/crates/protect-ffi/src/wasm.rs similarity index 100% rename from packages/protect-ffi/crates/protect-ffi/src/wasm.rs rename to languages/typescript/packages/protect-ffi/crates/protect-ffi/src/wasm.rs diff --git a/packages/protect-ffi/dist/wasm/errors.d.ts b/languages/typescript/packages/protect-ffi/dist/wasm/errors.d.ts similarity index 100% rename from packages/protect-ffi/dist/wasm/errors.d.ts rename to languages/typescript/packages/protect-ffi/dist/wasm/errors.d.ts diff --git a/packages/protect-ffi/dist/wasm/protect_ffi.d.ts b/languages/typescript/packages/protect-ffi/dist/wasm/protect_ffi.d.ts similarity index 100% rename from packages/protect-ffi/dist/wasm/protect_ffi.d.ts rename to languages/typescript/packages/protect-ffi/dist/wasm/protect_ffi.d.ts diff --git a/packages/protect-ffi/dist/wasm/protect_ffi_bg.wasm.d.ts b/languages/typescript/packages/protect-ffi/dist/wasm/protect_ffi_bg.wasm.d.ts similarity index 100% rename from packages/protect-ffi/dist/wasm/protect_ffi_bg.wasm.d.ts rename to languages/typescript/packages/protect-ffi/dist/wasm/protect_ffi_bg.wasm.d.ts diff --git a/packages/protect-ffi/docs/canonical-encryption-config-migration.md b/languages/typescript/packages/protect-ffi/docs/canonical-encryption-config-migration.md similarity index 100% rename from packages/protect-ffi/docs/canonical-encryption-config-migration.md rename to languages/typescript/packages/protect-ffi/docs/canonical-encryption-config-migration.md diff --git a/packages/protect-ffi/docs/jsonb-api-reference.md b/languages/typescript/packages/protect-ffi/docs/jsonb-api-reference.md similarity index 100% rename from packages/protect-ffi/docs/jsonb-api-reference.md rename to languages/typescript/packages/protect-ffi/docs/jsonb-api-reference.md diff --git a/packages/protect-ffi/docs/jsonb-integration.md b/languages/typescript/packages/protect-ffi/docs/jsonb-integration.md similarity index 100% rename from packages/protect-ffi/docs/jsonb-integration.md rename to languages/typescript/packages/protect-ffi/docs/jsonb-integration.md diff --git a/packages/protect-ffi/docs/jsonb-troubleshooting.md b/languages/typescript/packages/protect-ffi/docs/jsonb-troubleshooting.md similarity index 100% rename from packages/protect-ffi/docs/jsonb-troubleshooting.md rename to languages/typescript/packages/protect-ffi/docs/jsonb-troubleshooting.md diff --git a/packages/protect-ffi/integration-tests/CHANGELOG.md b/languages/typescript/packages/protect-ffi/integration-tests/CHANGELOG.md similarity index 100% rename from packages/protect-ffi/integration-tests/CHANGELOG.md rename to languages/typescript/packages/protect-ffi/integration-tests/CHANGELOG.md diff --git a/packages/protect-ffi/integration-tests/docker-compose.yml b/languages/typescript/packages/protect-ffi/integration-tests/docker-compose.yml similarity index 100% rename from packages/protect-ffi/integration-tests/docker-compose.yml rename to languages/typescript/packages/protect-ffi/integration-tests/docker-compose.yml diff --git a/packages/protect-ffi/integration-tests/package.json b/languages/typescript/packages/protect-ffi/integration-tests/package.json similarity index 100% rename from packages/protect-ffi/integration-tests/package.json rename to languages/typescript/packages/protect-ffi/integration-tests/package.json diff --git a/packages/protect-ffi/integration-tests/sql/.gitkeep b/languages/typescript/packages/protect-ffi/integration-tests/sql/.gitkeep similarity index 100% rename from packages/protect-ffi/integration-tests/sql/.gitkeep rename to languages/typescript/packages/protect-ffi/integration-tests/sql/.gitkeep diff --git a/packages/protect-ffi/integration-tests/tasks.toml b/languages/typescript/packages/protect-ffi/integration-tests/tasks.toml similarity index 100% rename from packages/protect-ffi/integration-tests/tasks.toml rename to languages/typescript/packages/protect-ffi/integration-tests/tasks.toml diff --git a/packages/protect-ffi/integration-tests/tests/common.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/common.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/common.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/common.ts diff --git a/packages/protect-ffi/integration-tests/tests/dates.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/dates.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/dates.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/dates.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/encrypt-config.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/encrypt-config.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/encrypt-config.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/encrypt-config.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/eql-v3.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/eql-v3.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/eql-v3.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/eql-v3.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/error-stack.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/error-stack.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/error-stack.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/error-stack.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/event-loop-exit.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/event-loop-exit.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/event-loop-exit.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/event-loop-exit.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-auto.cjs b/languages/typescript/packages/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-auto.cjs similarity index 100% rename from packages/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-auto.cjs rename to languages/typescript/packages/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-auto.cjs diff --git a/packages/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-jsbacked.cjs b/languages/typescript/packages/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-jsbacked.cjs similarity index 100% rename from packages/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-jsbacked.cjs rename to languages/typescript/packages/protect-ffi/integration-tests/tests/fixtures/event-loop-exit-jsbacked.cjs diff --git a/packages/protect-ffi/integration-tests/tests/js-strategy.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/js-strategy.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/js-strategy.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/js-strategy.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/json-bulk.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/json-bulk.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/json-bulk.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/json-bulk.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/json-containment.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/json-containment.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/json-containment.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/json-containment.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/json.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/json.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/json.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/json.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/keyset.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/keyset.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/keyset.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/keyset.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/lock-context.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/lock-context.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/lock-context.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/lock-context.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/oidc-federation.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/oidc-federation.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/oidc-federation.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/oidc-federation.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/postgres-v3.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/postgres-v3.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/postgres-v3.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/postgres-v3.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/postgres.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/postgres.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/postgres.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/postgres.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/query.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/query.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/query.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/query.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/scalar-bulk.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/scalar-bulk.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/scalar-bulk.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/scalar-bulk.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/scalar.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/scalar.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/scalar.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/scalar.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/strict-options.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/strict-options.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/strict-options.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/strict-options.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/wasm-error-codes.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/wasm-error-codes.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/wasm-error-codes.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/wasm-error-codes.test.ts diff --git a/packages/protect-ffi/integration-tests/tests/wasm-round-trip.test.ts b/languages/typescript/packages/protect-ffi/integration-tests/tests/wasm-round-trip.test.ts similarity index 100% rename from packages/protect-ffi/integration-tests/tests/wasm-round-trip.test.ts rename to languages/typescript/packages/protect-ffi/integration-tests/tests/wasm-round-trip.test.ts diff --git a/packages/protect-ffi/integration-tests/tsconfig.json b/languages/typescript/packages/protect-ffi/integration-tests/tsconfig.json similarity index 100% rename from packages/protect-ffi/integration-tests/tsconfig.json rename to languages/typescript/packages/protect-ffi/integration-tests/tsconfig.json diff --git a/packages/protect-ffi/integration-tests/vitest.config.ts b/languages/typescript/packages/protect-ffi/integration-tests/vitest.config.ts similarity index 100% rename from packages/protect-ffi/integration-tests/vitest.config.ts rename to languages/typescript/packages/protect-ffi/integration-tests/vitest.config.ts diff --git a/packages/protect-ffi/mise.toml b/languages/typescript/packages/protect-ffi/mise.toml similarity index 100% rename from packages/protect-ffi/mise.toml rename to languages/typescript/packages/protect-ffi/mise.toml diff --git a/packages/protect-ffi/package.json b/languages/typescript/packages/protect-ffi/package.json similarity index 100% rename from packages/protect-ffi/package.json rename to languages/typescript/packages/protect-ffi/package.json diff --git a/packages/protect-ffi/platforms/darwin-arm64/CHANGELOG.md b/languages/typescript/packages/protect-ffi/platforms/darwin-arm64/CHANGELOG.md similarity index 100% rename from packages/protect-ffi/platforms/darwin-arm64/CHANGELOG.md rename to languages/typescript/packages/protect-ffi/platforms/darwin-arm64/CHANGELOG.md diff --git a/packages/protect-ffi/platforms/darwin-arm64/README.md b/languages/typescript/packages/protect-ffi/platforms/darwin-arm64/README.md similarity index 100% rename from packages/protect-ffi/platforms/darwin-arm64/README.md rename to languages/typescript/packages/protect-ffi/platforms/darwin-arm64/README.md diff --git a/packages/protect-ffi/platforms/darwin-arm64/package.json b/languages/typescript/packages/protect-ffi/platforms/darwin-arm64/package.json similarity index 100% rename from packages/protect-ffi/platforms/darwin-arm64/package.json rename to languages/typescript/packages/protect-ffi/platforms/darwin-arm64/package.json diff --git a/packages/protect-ffi/platforms/darwin-x64/CHANGELOG.md b/languages/typescript/packages/protect-ffi/platforms/darwin-x64/CHANGELOG.md similarity index 100% rename from packages/protect-ffi/platforms/darwin-x64/CHANGELOG.md rename to languages/typescript/packages/protect-ffi/platforms/darwin-x64/CHANGELOG.md diff --git a/packages/protect-ffi/platforms/darwin-x64/README.md b/languages/typescript/packages/protect-ffi/platforms/darwin-x64/README.md similarity index 100% rename from packages/protect-ffi/platforms/darwin-x64/README.md rename to languages/typescript/packages/protect-ffi/platforms/darwin-x64/README.md diff --git a/packages/protect-ffi/platforms/darwin-x64/package.json b/languages/typescript/packages/protect-ffi/platforms/darwin-x64/package.json similarity index 100% rename from packages/protect-ffi/platforms/darwin-x64/package.json rename to languages/typescript/packages/protect-ffi/platforms/darwin-x64/package.json diff --git a/packages/protect-ffi/platforms/linux-arm64-gnu/CHANGELOG.md b/languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/CHANGELOG.md similarity index 100% rename from packages/protect-ffi/platforms/linux-arm64-gnu/CHANGELOG.md rename to languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/CHANGELOG.md diff --git a/packages/protect-ffi/platforms/linux-arm64-gnu/README.md b/languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/README.md similarity index 100% rename from packages/protect-ffi/platforms/linux-arm64-gnu/README.md rename to languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/README.md diff --git a/packages/protect-ffi/platforms/linux-arm64-gnu/package.json b/languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/package.json similarity index 100% rename from packages/protect-ffi/platforms/linux-arm64-gnu/package.json rename to languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/package.json diff --git a/packages/protect-ffi/platforms/linux-x64-gnu/CHANGELOG.md b/languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/CHANGELOG.md similarity index 100% rename from packages/protect-ffi/platforms/linux-x64-gnu/CHANGELOG.md rename to languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/CHANGELOG.md diff --git a/packages/protect-ffi/platforms/linux-x64-gnu/README.md b/languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/README.md similarity index 100% rename from packages/protect-ffi/platforms/linux-x64-gnu/README.md rename to languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/README.md diff --git a/packages/protect-ffi/platforms/linux-x64-gnu/package.json b/languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/package.json similarity index 100% rename from packages/protect-ffi/platforms/linux-x64-gnu/package.json rename to languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/package.json diff --git a/packages/protect-ffi/platforms/linux-x64-musl/CHANGELOG.md b/languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/CHANGELOG.md similarity index 100% rename from packages/protect-ffi/platforms/linux-x64-musl/CHANGELOG.md rename to languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/CHANGELOG.md diff --git a/packages/protect-ffi/platforms/linux-x64-musl/README.md b/languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/README.md similarity index 100% rename from packages/protect-ffi/platforms/linux-x64-musl/README.md rename to languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/README.md diff --git a/packages/protect-ffi/platforms/linux-x64-musl/package.json b/languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/package.json similarity index 100% rename from packages/protect-ffi/platforms/linux-x64-musl/package.json rename to languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/package.json diff --git a/packages/protect-ffi/platforms/win32-x64-msvc/CHANGELOG.md b/languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/CHANGELOG.md similarity index 100% rename from packages/protect-ffi/platforms/win32-x64-msvc/CHANGELOG.md rename to languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/CHANGELOG.md diff --git a/packages/protect-ffi/platforms/win32-x64-msvc/README.md b/languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/README.md similarity index 100% rename from packages/protect-ffi/platforms/win32-x64-msvc/README.md rename to languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/README.md diff --git a/packages/protect-ffi/platforms/win32-x64-msvc/package.json b/languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/package.json similarity index 100% rename from packages/protect-ffi/platforms/win32-x64-msvc/package.json rename to languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/package.json diff --git a/packages/protect-ffi/scripts/changelog-extract.mjs b/languages/typescript/packages/protect-ffi/scripts/changelog-extract.mjs similarity index 100% rename from packages/protect-ffi/scripts/changelog-extract.mjs rename to languages/typescript/packages/protect-ffi/scripts/changelog-extract.mjs diff --git a/packages/protect-ffi/scripts/inline-wasm.mjs b/languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs similarity index 100% rename from packages/protect-ffi/scripts/inline-wasm.mjs rename to languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs diff --git a/packages/protect-ffi/scripts/sync-eql-v3-types.sh b/languages/typescript/packages/protect-ffi/scripts/sync-eql-v3-types.sh similarity index 100% rename from packages/protect-ffi/scripts/sync-eql-v3-types.sh rename to languages/typescript/packages/protect-ffi/scripts/sync-eql-v3-types.sh diff --git a/packages/protect-ffi/src/bigintWire.test.ts b/languages/typescript/packages/protect-ffi/src/bigintWire.test.ts similarity index 100% rename from packages/protect-ffi/src/bigintWire.test.ts rename to languages/typescript/packages/protect-ffi/src/bigintWire.test.ts diff --git a/packages/protect-ffi/src/bigintWire.ts b/languages/typescript/packages/protect-ffi/src/bigintWire.ts similarity index 100% rename from packages/protect-ffi/src/bigintWire.ts rename to languages/typescript/packages/protect-ffi/src/bigintWire.ts diff --git a/packages/protect-ffi/src/credentials.ts b/languages/typescript/packages/protect-ffi/src/credentials.ts similarity index 100% rename from packages/protect-ffi/src/credentials.ts rename to languages/typescript/packages/protect-ffi/src/credentials.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Bigint.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Bigint.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Bigint.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Bigint.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BigintEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BigintEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BigintEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BigintEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BigintOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BigintOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BigintOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BigintOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BigintOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BigintOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BigintOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BigintOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BigintOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BigintOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BigintOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BigintOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BigintOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/BloomFilter.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/BloomFilter.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/BloomFilter.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/BloomFilter.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Boolean.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Boolean.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Boolean.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Boolean.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Ciphertext.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Ciphertext.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Ciphertext.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Ciphertext.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Date.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Date.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Date.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Date.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DateEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DateEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DateEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DateEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DateEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DateEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DateEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DateEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DateOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DateOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DateOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DateOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DateOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DateOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DateOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DateOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DateOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DateOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DateOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DateOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DateOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Double.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Double.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Double.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Double.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DoubleEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DoubleEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DoubleEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DoubleEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DoubleOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DoubleOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DoubleOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DoubleOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DoubleOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DoubleOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DoubleOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DoubleOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DoubleOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DoubleOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/DoubleOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/DoubleOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/DoubleOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/EntryCiphertext.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/EntryCiphertext.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/EntryCiphertext.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/EntryCiphertext.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Hmac256.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Hmac256.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Hmac256.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Hmac256.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Identifier.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Identifier.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Identifier.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Identifier.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Integer.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Integer.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Integer.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Integer.ts diff --git a/packages/protect-ffi/src/eql-v3-types/IntegerEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/IntegerEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/IntegerEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/IntegerEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/IntegerOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/IntegerOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/IntegerOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/IntegerOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/IntegerOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/IntegerOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/IntegerOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/IntegerOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/IntegerOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/IntegerOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/IntegerOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/IntegerOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/IntegerOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Json.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Json.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Json.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Json.ts diff --git a/packages/protect-ffi/src/eql-v3-types/KeyHeader.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/KeyHeader.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/KeyHeader.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/KeyHeader.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Numeric.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Numeric.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Numeric.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Numeric.ts diff --git a/packages/protect-ffi/src/eql-v3-types/NumericEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/NumericEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/NumericEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/NumericEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/NumericOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/NumericOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/NumericOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/NumericOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/NumericOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/NumericOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/NumericOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/NumericOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/NumericOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/NumericOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/NumericOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/NumericOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/NumericOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/OpeCllw.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/OpeCllw.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/OpeCllw.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/OpeCllw.ts diff --git a/packages/protect-ffi/src/eql-v3-types/OreBlock256.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/OreBlock256.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/OreBlock256.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/OreBlock256.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Real.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Real.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Real.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Real.ts diff --git a/packages/protect-ffi/src/eql-v3-types/RealEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/RealEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/RealEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/RealEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/RealEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/RealEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/RealEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/RealEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/RealOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/RealOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/RealOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/RealOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/RealOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/RealOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/RealOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/RealOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/RealOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/RealOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/RealOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/RealOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/RealOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SchemaVersion.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SchemaVersion.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SchemaVersion.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SchemaVersion.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Selector.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Selector.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Selector.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Selector.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Smallint.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Smallint.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Smallint.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Smallint.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SmallintEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SmallintEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SmallintEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SmallintEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SmallintOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SmallintOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SmallintOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SmallintOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SmallintOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SmallintOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SmallintOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SmallintOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SmallintOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SmallintOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SmallintOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SmallintOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SmallintOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SteVecDocument.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecDocument.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SteVecDocument.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecDocument.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SteVecEntry.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecEntry.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SteVecEntry.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecEntry.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SteVecForm.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecForm.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SteVecForm.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecForm.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SteVecQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SteVecQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/SteVecQueryEntry.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecQueryEntry.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/SteVecQueryEntry.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/SteVecQueryEntry.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Text.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Text.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Text.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Text.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextMatch.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextMatch.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextMatch.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextMatch.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextMatchQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextMatchQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextMatchQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextMatchQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextSearch.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextSearch.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextSearch.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextSearch.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextSearchOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextSearchOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextSearchOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextSearchOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextSearchOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextSearchOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextSearchOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextSearchOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TextSearchQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TextSearchQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TextSearchQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TextSearchQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/Timestamp.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/Timestamp.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/Timestamp.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/Timestamp.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TimestampEq.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampEq.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TimestampEq.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampEq.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TimestampEqQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampEqQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TimestampEqQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampEqQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TimestampOrd.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrd.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TimestampOrd.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrd.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TimestampOrdOpe.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdOpe.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TimestampOrdOpe.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdOpe.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TimestampOrdOpeQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdOpeQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TimestampOrdOpeQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdOpeQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TimestampOrdOre.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdOre.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TimestampOrdOre.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdOre.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TimestampOrdOreQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdOreQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TimestampOrdOreQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdOreQuery.ts diff --git a/packages/protect-ffi/src/eql-v3-types/TimestampOrdQuery.ts b/languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdQuery.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3-types/TimestampOrdQuery.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3-types/TimestampOrdQuery.ts diff --git a/packages/protect-ffi/src/eql-v3.ts b/languages/typescript/packages/protect-ffi/src/eql-v3.ts similarity index 100% rename from packages/protect-ffi/src/eql-v3.ts rename to languages/typescript/packages/protect-ffi/src/eql-v3.ts diff --git a/packages/protect-ffi/src/errorCodes.test.ts b/languages/typescript/packages/protect-ffi/src/errorCodes.test.ts similarity index 100% rename from packages/protect-ffi/src/errorCodes.test.ts rename to languages/typescript/packages/protect-ffi/src/errorCodes.test.ts diff --git a/packages/protect-ffi/src/errors.test.ts b/languages/typescript/packages/protect-ffi/src/errors.test.ts similarity index 100% rename from packages/protect-ffi/src/errors.test.ts rename to languages/typescript/packages/protect-ffi/src/errors.test.ts diff --git a/packages/protect-ffi/src/errors.ts b/languages/typescript/packages/protect-ffi/src/errors.ts similarity index 100% rename from packages/protect-ffi/src/errors.ts rename to languages/typescript/packages/protect-ffi/src/errors.ts diff --git a/packages/protect-ffi/src/index.cts b/languages/typescript/packages/protect-ffi/src/index.cts similarity index 100% rename from packages/protect-ffi/src/index.cts rename to languages/typescript/packages/protect-ffi/src/index.cts diff --git a/packages/protect-ffi/src/index.mts b/languages/typescript/packages/protect-ffi/src/index.mts similarity index 100% rename from packages/protect-ffi/src/index.mts rename to languages/typescript/packages/protect-ffi/src/index.mts diff --git a/packages/protect-ffi/src/index.types.test.ts b/languages/typescript/packages/protect-ffi/src/index.types.test.ts similarity index 100% rename from packages/protect-ffi/src/index.types.test.ts rename to languages/typescript/packages/protect-ffi/src/index.types.test.ts diff --git a/packages/protect-ffi/src/integrationSuiteCi.test.ts b/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts similarity index 100% rename from packages/protect-ffi/src/integrationSuiteCi.test.ts rename to languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts diff --git a/packages/protect-ffi/src/lintWiring.test.ts b/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts similarity index 100% rename from packages/protect-ffi/src/lintWiring.test.ts rename to languages/typescript/packages/protect-ffi/src/lintWiring.test.ts diff --git a/packages/protect-ffi/src/load.cts b/languages/typescript/packages/protect-ffi/src/load.cts similarity index 100% rename from packages/protect-ffi/src/load.cts rename to languages/typescript/packages/protect-ffi/src/load.cts diff --git a/packages/protect-ffi/src/nativeLoading.test.ts b/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts similarity index 100% rename from packages/protect-ffi/src/nativeLoading.test.ts rename to languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts diff --git a/packages/protect-ffi/src/newClientArgs.test.ts b/languages/typescript/packages/protect-ffi/src/newClientArgs.test.ts similarity index 100% rename from packages/protect-ffi/src/newClientArgs.test.ts rename to languages/typescript/packages/protect-ffi/src/newClientArgs.test.ts diff --git a/packages/protect-ffi/src/newClientArgs.ts b/languages/typescript/packages/protect-ffi/src/newClientArgs.ts similarity index 100% rename from packages/protect-ffi/src/newClientArgs.ts rename to languages/typescript/packages/protect-ffi/src/newClientArgs.ts diff --git a/packages/protect-ffi/src/types.ts b/languages/typescript/packages/protect-ffi/src/types.ts similarity index 100% rename from packages/protect-ffi/src/types.ts rename to languages/typescript/packages/protect-ffi/src/types.ts diff --git a/packages/protect-ffi/src/withEnvCredentials.test.ts b/languages/typescript/packages/protect-ffi/src/withEnvCredentials.test.ts similarity index 100% rename from packages/protect-ffi/src/withEnvCredentials.test.ts rename to languages/typescript/packages/protect-ffi/src/withEnvCredentials.test.ts diff --git a/packages/protect-ffi/tsconfig.json b/languages/typescript/packages/protect-ffi/tsconfig.json similarity index 100% rename from packages/protect-ffi/tsconfig.json rename to languages/typescript/packages/protect-ffi/tsconfig.json diff --git a/packages/protect-ffi/tsconfig.test.json b/languages/typescript/packages/protect-ffi/tsconfig.test.json similarity index 100% rename from packages/protect-ffi/tsconfig.test.json rename to languages/typescript/packages/protect-ffi/tsconfig.test.json diff --git a/packages/protect-ffi/tsconfig.wasm-errors.json b/languages/typescript/packages/protect-ffi/tsconfig.wasm-errors.json similarity index 100% rename from packages/protect-ffi/tsconfig.wasm-errors.json rename to languages/typescript/packages/protect-ffi/tsconfig.wasm-errors.json diff --git a/packages/protect-ffi/type-tests/tsconfig.json b/languages/typescript/packages/protect-ffi/type-tests/tsconfig.json similarity index 100% rename from packages/protect-ffi/type-tests/tsconfig.json rename to languages/typescript/packages/protect-ffi/type-tests/tsconfig.json diff --git a/packages/protect-ffi/type-tests/wasm.test-d.mts b/languages/typescript/packages/protect-ffi/type-tests/wasm.test-d.mts similarity index 100% rename from packages/protect-ffi/type-tests/wasm.test-d.mts rename to languages/typescript/packages/protect-ffi/type-tests/wasm.test-d.mts diff --git a/packages/protect-ffi/vitest.config.ts b/languages/typescript/packages/protect-ffi/vitest.config.ts similarity index 100% rename from packages/protect-ffi/vitest.config.ts rename to languages/typescript/packages/protect-ffi/vitest.config.ts diff --git a/packages/stack-drizzle/CHANGELOG.md b/languages/typescript/packages/stack-drizzle/CHANGELOG.md similarity index 100% rename from packages/stack-drizzle/CHANGELOG.md rename to languages/typescript/packages/stack-drizzle/CHANGELOG.md diff --git a/packages/stack-drizzle/README.md b/languages/typescript/packages/stack-drizzle/README.md similarity index 100% rename from packages/stack-drizzle/README.md rename to languages/typescript/packages/stack-drizzle/README.md diff --git a/packages/stack-drizzle/__tests__/bigint.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/bigint.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/bigint.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/bigint.test.ts diff --git a/packages/stack-drizzle/__tests__/codec.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/codec.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/codec.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/codec.test.ts diff --git a/packages/stack-drizzle/__tests__/column.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/column.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/column.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/column.test.ts diff --git a/packages/stack-drizzle/__tests__/exports.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/exports.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/exports.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/exports.test.ts diff --git a/packages/stack-drizzle/__tests__/indexes.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/indexes.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/indexes.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/indexes.test.ts diff --git a/packages/stack-drizzle/__tests__/operators.test-d.ts b/languages/typescript/packages/stack-drizzle/__tests__/operators.test-d.ts similarity index 100% rename from packages/stack-drizzle/__tests__/operators.test-d.ts rename to languages/typescript/packages/stack-drizzle/__tests__/operators.test-d.ts diff --git a/packages/stack-drizzle/__tests__/operators.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/operators.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/operators.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/operators.test.ts diff --git a/packages/stack-drizzle/__tests__/schema-extraction.test-d.ts b/languages/typescript/packages/stack-drizzle/__tests__/schema-extraction.test-d.ts similarity index 100% rename from packages/stack-drizzle/__tests__/schema-extraction.test-d.ts rename to languages/typescript/packages/stack-drizzle/__tests__/schema-extraction.test-d.ts diff --git a/packages/stack-drizzle/__tests__/schema-extraction.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/schema-extraction.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/schema-extraction.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/schema-extraction.test.ts diff --git a/packages/stack-drizzle/__tests__/selector.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/selector.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/selector.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/selector.test.ts diff --git a/packages/stack-drizzle/__tests__/sql-dialect.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/sql-dialect.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/sql-dialect.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/sql-dialect.test.ts diff --git a/packages/stack-drizzle/__tests__/types.test-d.ts b/languages/typescript/packages/stack-drizzle/__tests__/types.test-d.ts similarity index 100% rename from packages/stack-drizzle/__tests__/types.test-d.ts rename to languages/typescript/packages/stack-drizzle/__tests__/types.test-d.ts diff --git a/packages/stack-drizzle/__tests__/types.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/types.test.ts similarity index 100% rename from packages/stack-drizzle/__tests__/types.test.ts rename to languages/typescript/packages/stack-drizzle/__tests__/types.test.ts diff --git a/packages/stack-drizzle/integration/adapter.ts b/languages/typescript/packages/stack-drizzle/integration/adapter.ts similarity index 100% rename from packages/stack-drizzle/integration/adapter.ts rename to languages/typescript/packages/stack-drizzle/integration/adapter.ts diff --git a/packages/stack-drizzle/integration/families.integration.test.ts b/languages/typescript/packages/stack-drizzle/integration/families.integration.test.ts similarity index 100% rename from packages/stack-drizzle/integration/families.integration.test.ts rename to languages/typescript/packages/stack-drizzle/integration/families.integration.test.ts diff --git a/packages/stack-drizzle/integration/json-adapter.ts b/languages/typescript/packages/stack-drizzle/integration/json-adapter.ts similarity index 100% rename from packages/stack-drizzle/integration/json-adapter.ts rename to languages/typescript/packages/stack-drizzle/integration/json-adapter.ts diff --git a/packages/stack-drizzle/integration/json.integration.test.ts b/languages/typescript/packages/stack-drizzle/integration/json.integration.test.ts similarity index 100% rename from packages/stack-drizzle/integration/json.integration.test.ts rename to languages/typescript/packages/stack-drizzle/integration/json.integration.test.ts diff --git a/packages/stack-drizzle/integration/lock-context.integration.test.ts b/languages/typescript/packages/stack-drizzle/integration/lock-context.integration.test.ts similarity index 100% rename from packages/stack-drizzle/integration/lock-context.integration.test.ts rename to languages/typescript/packages/stack-drizzle/integration/lock-context.integration.test.ts diff --git a/packages/stack-drizzle/integration/null-persistence.integration.test.ts b/languages/typescript/packages/stack-drizzle/integration/null-persistence.integration.test.ts similarity index 100% rename from packages/stack-drizzle/integration/null-persistence.integration.test.ts rename to languages/typescript/packages/stack-drizzle/integration/null-persistence.integration.test.ts diff --git a/packages/stack-drizzle/integration/relational.integration.test.ts b/languages/typescript/packages/stack-drizzle/integration/relational.integration.test.ts similarity index 100% rename from packages/stack-drizzle/integration/relational.integration.test.ts rename to languages/typescript/packages/stack-drizzle/integration/relational.integration.test.ts diff --git a/packages/stack-drizzle/integration/vitest.config.ts b/languages/typescript/packages/stack-drizzle/integration/vitest.config.ts similarity index 100% rename from packages/stack-drizzle/integration/vitest.config.ts rename to languages/typescript/packages/stack-drizzle/integration/vitest.config.ts diff --git a/packages/stack-drizzle/package.json b/languages/typescript/packages/stack-drizzle/package.json similarity index 100% rename from packages/stack-drizzle/package.json rename to languages/typescript/packages/stack-drizzle/package.json diff --git a/packages/stack-drizzle/src/codec.ts b/languages/typescript/packages/stack-drizzle/src/codec.ts similarity index 100% rename from packages/stack-drizzle/src/codec.ts rename to languages/typescript/packages/stack-drizzle/src/codec.ts diff --git a/packages/stack-drizzle/src/column.ts b/languages/typescript/packages/stack-drizzle/src/column.ts similarity index 100% rename from packages/stack-drizzle/src/column.ts rename to languages/typescript/packages/stack-drizzle/src/column.ts diff --git a/packages/stack-drizzle/src/index.ts b/languages/typescript/packages/stack-drizzle/src/index.ts similarity index 100% rename from packages/stack-drizzle/src/index.ts rename to languages/typescript/packages/stack-drizzle/src/index.ts diff --git a/packages/stack-drizzle/src/indexes.ts b/languages/typescript/packages/stack-drizzle/src/indexes.ts similarity index 100% rename from packages/stack-drizzle/src/indexes.ts rename to languages/typescript/packages/stack-drizzle/src/indexes.ts diff --git a/packages/stack-drizzle/src/operators.ts b/languages/typescript/packages/stack-drizzle/src/operators.ts similarity index 100% rename from packages/stack-drizzle/src/operators.ts rename to languages/typescript/packages/stack-drizzle/src/operators.ts diff --git a/packages/stack-drizzle/src/schema-extraction.ts b/languages/typescript/packages/stack-drizzle/src/schema-extraction.ts similarity index 100% rename from packages/stack-drizzle/src/schema-extraction.ts rename to languages/typescript/packages/stack-drizzle/src/schema-extraction.ts diff --git a/packages/stack-drizzle/src/sql-dialect.ts b/languages/typescript/packages/stack-drizzle/src/sql-dialect.ts similarity index 100% rename from packages/stack-drizzle/src/sql-dialect.ts rename to languages/typescript/packages/stack-drizzle/src/sql-dialect.ts diff --git a/packages/stack-drizzle/src/types.ts b/languages/typescript/packages/stack-drizzle/src/types.ts similarity index 100% rename from packages/stack-drizzle/src/types.ts rename to languages/typescript/packages/stack-drizzle/src/types.ts diff --git a/packages/stack-drizzle/tsconfig.json b/languages/typescript/packages/stack-drizzle/tsconfig.json similarity index 100% rename from packages/stack-drizzle/tsconfig.json rename to languages/typescript/packages/stack-drizzle/tsconfig.json diff --git a/packages/stack-drizzle/tsconfig.typecheck.json b/languages/typescript/packages/stack-drizzle/tsconfig.typecheck.json similarity index 100% rename from packages/stack-drizzle/tsconfig.typecheck.json rename to languages/typescript/packages/stack-drizzle/tsconfig.typecheck.json diff --git a/packages/stack-drizzle/tsup.config.ts b/languages/typescript/packages/stack-drizzle/tsup.config.ts similarity index 100% rename from packages/stack-drizzle/tsup.config.ts rename to languages/typescript/packages/stack-drizzle/tsup.config.ts diff --git a/packages/stack-drizzle/vitest.config.ts b/languages/typescript/packages/stack-drizzle/vitest.config.ts similarity index 100% rename from packages/stack-drizzle/vitest.config.ts rename to languages/typescript/packages/stack-drizzle/vitest.config.ts diff --git a/packages/stack-prisma/CHANGELOG.md b/languages/typescript/packages/stack-prisma/CHANGELOG.md similarity index 100% rename from packages/stack-prisma/CHANGELOG.md rename to languages/typescript/packages/stack-prisma/CHANGELOG.md diff --git a/packages/stack-prisma/DEVELOPING.md b/languages/typescript/packages/stack-prisma/DEVELOPING.md similarity index 100% rename from packages/stack-prisma/DEVELOPING.md rename to languages/typescript/packages/stack-prisma/DEVELOPING.md diff --git a/packages/stack-prisma/README.md b/languages/typescript/packages/stack-prisma/README.md similarity index 100% rename from packages/stack-prisma/README.md rename to languages/typescript/packages/stack-prisma/README.md diff --git a/packages/stack-prisma/integration/adapter.ts b/languages/typescript/packages/stack-prisma/integration/adapter.ts similarity index 100% rename from packages/stack-prisma/integration/adapter.ts rename to languages/typescript/packages/stack-prisma/integration/adapter.ts diff --git a/packages/stack-prisma/integration/families.integration.test.ts b/languages/typescript/packages/stack-prisma/integration/families.integration.test.ts similarity index 100% rename from packages/stack-prisma/integration/families.integration.test.ts rename to languages/typescript/packages/stack-prisma/integration/families.integration.test.ts diff --git a/packages/stack-prisma/integration/json-adapter.ts b/languages/typescript/packages/stack-prisma/integration/json-adapter.ts similarity index 100% rename from packages/stack-prisma/integration/json-adapter.ts rename to languages/typescript/packages/stack-prisma/integration/json-adapter.ts diff --git a/packages/stack-prisma/integration/json.integration.test.ts b/languages/typescript/packages/stack-prisma/integration/json.integration.test.ts similarity index 100% rename from packages/stack-prisma/integration/json.integration.test.ts rename to languages/typescript/packages/stack-prisma/integration/json.integration.test.ts diff --git a/packages/stack-prisma/integration/vitest.config.ts b/languages/typescript/packages/stack-prisma/integration/vitest.config.ts similarity index 100% rename from packages/stack-prisma/integration/vitest.config.ts rename to languages/typescript/packages/stack-prisma/integration/vitest.config.ts diff --git a/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.json b/languages/typescript/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.json similarity index 100% rename from packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.json rename to languages/typescript/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.json diff --git a/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.ts b/languages/typescript/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.ts similarity index 100% rename from packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.ts rename to languages/typescript/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/migration.ts diff --git a/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/ops.json b/languages/typescript/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/ops.json similarity index 100% rename from packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/ops.json rename to languages/typescript/packages/stack-prisma/migrations/20260601T0100_install_eql_v3_bundle/ops.json diff --git a/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.json b/languages/typescript/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.json similarity index 100% rename from packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.json rename to languages/typescript/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.json diff --git a/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.ts b/languages/typescript/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.ts similarity index 100% rename from packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.ts rename to languages/typescript/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/migration.ts diff --git a/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/ops.json b/languages/typescript/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/ops.json similarity index 100% rename from packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/ops.json rename to languages/typescript/packages/stack-prisma/migrations/20260720T0000_upgrade_eql_v3_3_0_2/ops.json diff --git a/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.json b/languages/typescript/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.json similarity index 100% rename from packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.json rename to languages/typescript/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.json diff --git a/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.ts b/languages/typescript/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.ts similarity index 100% rename from packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.ts rename to languages/typescript/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/migration.ts diff --git a/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/ops.json b/languages/typescript/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/ops.json similarity index 100% rename from packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/ops.json rename to languages/typescript/packages/stack-prisma/migrations/20260728T0000_upgrade_eql_v3_3_0_4/ops.json diff --git a/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.json b/languages/typescript/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.json similarity index 100% rename from packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.json rename to languages/typescript/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.json diff --git a/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.ts b/languages/typescript/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.ts similarity index 100% rename from packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.ts rename to languages/typescript/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/migration.ts diff --git a/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/ops.json b/languages/typescript/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/ops.json similarity index 100% rename from packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/ops.json rename to languages/typescript/packages/stack-prisma/migrations/20260814T0000_upgrade_eql_v3_3_0_5/ops.json diff --git a/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.json b/languages/typescript/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.json similarity index 100% rename from packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.json rename to languages/typescript/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.json diff --git a/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.ts b/languages/typescript/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.ts similarity index 100% rename from packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.ts rename to languages/typescript/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/migration.ts diff --git a/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/ops.json b/languages/typescript/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/ops.json similarity index 100% rename from packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/ops.json rename to languages/typescript/packages/stack-prisma/migrations/20261002T0000_upgrade_eql_v3_3_0_6/ops.json diff --git a/packages/stack-prisma/migrations/refs/head.json b/languages/typescript/packages/stack-prisma/migrations/refs/head.json similarity index 100% rename from packages/stack-prisma/migrations/refs/head.json rename to languages/typescript/packages/stack-prisma/migrations/refs/head.json diff --git a/packages/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts b/languages/typescript/packages/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts similarity index 100% rename from packages/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts rename to languages/typescript/packages/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.d.ts diff --git a/packages/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json b/languages/typescript/packages/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json similarity index 100% rename from packages/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json rename to languages/typescript/packages/stack-prisma/migrations/snapshots/0c0734babd6eeb868fee1f281ca96963022475611560e9f170f465daa35f8599/contract.json diff --git a/packages/stack-prisma/package.json b/languages/typescript/packages/stack-prisma/package.json similarity index 100% rename from packages/stack-prisma/package.json rename to languages/typescript/packages/stack-prisma/package.json diff --git a/packages/stack-prisma/prisma-next.config.ts b/languages/typescript/packages/stack-prisma/prisma-next.config.ts similarity index 100% rename from packages/stack-prisma/prisma-next.config.ts rename to languages/typescript/packages/stack-prisma/prisma-next.config.ts diff --git a/packages/stack-prisma/src/contract-authoring.ts b/languages/typescript/packages/stack-prisma/src/contract-authoring.ts similarity index 100% rename from packages/stack-prisma/src/contract-authoring.ts rename to languages/typescript/packages/stack-prisma/src/contract-authoring.ts diff --git a/packages/stack-prisma/src/contract.d.ts b/languages/typescript/packages/stack-prisma/src/contract.d.ts similarity index 100% rename from packages/stack-prisma/src/contract.d.ts rename to languages/typescript/packages/stack-prisma/src/contract.d.ts diff --git a/packages/stack-prisma/src/contract.json b/languages/typescript/packages/stack-prisma/src/contract.json similarity index 100% rename from packages/stack-prisma/src/contract.json rename to languages/typescript/packages/stack-prisma/src/contract.json diff --git a/packages/stack-prisma/src/contract.prisma b/languages/typescript/packages/stack-prisma/src/contract.prisma similarity index 100% rename from packages/stack-prisma/src/contract.prisma rename to languages/typescript/packages/stack-prisma/src/contract.prisma diff --git a/packages/stack-prisma/src/execution/abort.ts b/languages/typescript/packages/stack-prisma/src/execution/abort.ts similarity index 100% rename from packages/stack-prisma/src/execution/abort.ts rename to languages/typescript/packages/stack-prisma/src/execution/abort.ts diff --git a/packages/stack-prisma/src/execution/decrypt-all.ts b/languages/typescript/packages/stack-prisma/src/execution/decrypt-all.ts similarity index 100% rename from packages/stack-prisma/src/execution/decrypt-all.ts rename to languages/typescript/packages/stack-prisma/src/execution/decrypt-all.ts diff --git a/packages/stack-prisma/src/execution/envelope-base.ts b/languages/typescript/packages/stack-prisma/src/execution/envelope-base.ts similarity index 100% rename from packages/stack-prisma/src/execution/envelope-base.ts rename to languages/typescript/packages/stack-prisma/src/execution/envelope-base.ts diff --git a/packages/stack-prisma/src/execution/envelope-bigint.ts b/languages/typescript/packages/stack-prisma/src/execution/envelope-bigint.ts similarity index 100% rename from packages/stack-prisma/src/execution/envelope-bigint.ts rename to languages/typescript/packages/stack-prisma/src/execution/envelope-bigint.ts diff --git a/packages/stack-prisma/src/execution/envelope-boolean.ts b/languages/typescript/packages/stack-prisma/src/execution/envelope-boolean.ts similarity index 100% rename from packages/stack-prisma/src/execution/envelope-boolean.ts rename to languages/typescript/packages/stack-prisma/src/execution/envelope-boolean.ts diff --git a/packages/stack-prisma/src/execution/envelope-date.ts b/languages/typescript/packages/stack-prisma/src/execution/envelope-date.ts similarity index 100% rename from packages/stack-prisma/src/execution/envelope-date.ts rename to languages/typescript/packages/stack-prisma/src/execution/envelope-date.ts diff --git a/packages/stack-prisma/src/execution/envelope-json.ts b/languages/typescript/packages/stack-prisma/src/execution/envelope-json.ts similarity index 100% rename from packages/stack-prisma/src/execution/envelope-json.ts rename to languages/typescript/packages/stack-prisma/src/execution/envelope-json.ts diff --git a/packages/stack-prisma/src/execution/envelope-string.ts b/languages/typescript/packages/stack-prisma/src/execution/envelope-string.ts similarity index 100% rename from packages/stack-prisma/src/execution/envelope-string.ts rename to languages/typescript/packages/stack-prisma/src/execution/envelope-string.ts diff --git a/packages/stack-prisma/src/execution/middleware-registry.ts b/languages/typescript/packages/stack-prisma/src/execution/middleware-registry.ts similarity index 100% rename from packages/stack-prisma/src/execution/middleware-registry.ts rename to languages/typescript/packages/stack-prisma/src/execution/middleware-registry.ts diff --git a/packages/stack-prisma/src/execution/routing.ts b/languages/typescript/packages/stack-prisma/src/execution/routing.ts similarity index 100% rename from packages/stack-prisma/src/execution/routing.ts rename to languages/typescript/packages/stack-prisma/src/execution/routing.ts diff --git a/packages/stack-prisma/src/execution/sdk.ts b/languages/typescript/packages/stack-prisma/src/execution/sdk.ts similarity index 100% rename from packages/stack-prisma/src/execution/sdk.ts rename to languages/typescript/packages/stack-prisma/src/execution/sdk.ts diff --git a/packages/stack-prisma/src/exports/codec-types.ts b/languages/typescript/packages/stack-prisma/src/exports/codec-types.ts similarity index 100% rename from packages/stack-prisma/src/exports/codec-types.ts rename to languages/typescript/packages/stack-prisma/src/exports/codec-types.ts diff --git a/packages/stack-prisma/src/exports/column-types.ts b/languages/typescript/packages/stack-prisma/src/exports/column-types.ts similarity index 100% rename from packages/stack-prisma/src/exports/column-types.ts rename to languages/typescript/packages/stack-prisma/src/exports/column-types.ts diff --git a/packages/stack-prisma/src/exports/contract-space-typing.ts b/languages/typescript/packages/stack-prisma/src/exports/contract-space-typing.ts similarity index 100% rename from packages/stack-prisma/src/exports/contract-space-typing.ts rename to languages/typescript/packages/stack-prisma/src/exports/contract-space-typing.ts diff --git a/packages/stack-prisma/src/exports/control.ts b/languages/typescript/packages/stack-prisma/src/exports/control.ts similarity index 100% rename from packages/stack-prisma/src/exports/control.ts rename to languages/typescript/packages/stack-prisma/src/exports/control.ts diff --git a/packages/stack-prisma/src/exports/operation-types.ts b/languages/typescript/packages/stack-prisma/src/exports/operation-types.ts similarity index 100% rename from packages/stack-prisma/src/exports/operation-types.ts rename to languages/typescript/packages/stack-prisma/src/exports/operation-types.ts diff --git a/packages/stack-prisma/src/exports/pack.ts b/languages/typescript/packages/stack-prisma/src/exports/pack.ts similarity index 100% rename from packages/stack-prisma/src/exports/pack.ts rename to languages/typescript/packages/stack-prisma/src/exports/pack.ts diff --git a/packages/stack-prisma/src/exports/runtime.ts b/languages/typescript/packages/stack-prisma/src/exports/runtime.ts similarity index 100% rename from packages/stack-prisma/src/exports/runtime.ts rename to languages/typescript/packages/stack-prisma/src/exports/runtime.ts diff --git a/packages/stack-prisma/src/exports/stack.ts b/languages/typescript/packages/stack-prisma/src/exports/stack.ts similarity index 100% rename from packages/stack-prisma/src/exports/stack.ts rename to languages/typescript/packages/stack-prisma/src/exports/stack.ts diff --git a/packages/stack-prisma/src/exports/v3.ts b/languages/typescript/packages/stack-prisma/src/exports/v3.ts similarity index 100% rename from packages/stack-prisma/src/exports/v3.ts rename to languages/typescript/packages/stack-prisma/src/exports/v3.ts diff --git a/packages/stack-prisma/src/extension-metadata/codec-metadata.ts b/languages/typescript/packages/stack-prisma/src/extension-metadata/codec-metadata.ts similarity index 100% rename from packages/stack-prisma/src/extension-metadata/codec-metadata.ts rename to languages/typescript/packages/stack-prisma/src/extension-metadata/codec-metadata.ts diff --git a/packages/stack-prisma/src/extension-metadata/constants-v3.ts b/languages/typescript/packages/stack-prisma/src/extension-metadata/constants-v3.ts similarity index 100% rename from packages/stack-prisma/src/extension-metadata/constants-v3.ts rename to languages/typescript/packages/stack-prisma/src/extension-metadata/constants-v3.ts diff --git a/packages/stack-prisma/src/extension-metadata/constants.ts b/languages/typescript/packages/stack-prisma/src/extension-metadata/constants.ts similarity index 100% rename from packages/stack-prisma/src/extension-metadata/constants.ts rename to languages/typescript/packages/stack-prisma/src/extension-metadata/constants.ts diff --git a/packages/stack-prisma/src/extension-metadata/descriptor-meta.ts b/languages/typescript/packages/stack-prisma/src/extension-metadata/descriptor-meta.ts similarity index 100% rename from packages/stack-prisma/src/extension-metadata/descriptor-meta.ts rename to languages/typescript/packages/stack-prisma/src/extension-metadata/descriptor-meta.ts diff --git a/packages/stack-prisma/src/migration/cipherstash-codec-v3.ts b/languages/typescript/packages/stack-prisma/src/migration/cipherstash-codec-v3.ts similarity index 100% rename from packages/stack-prisma/src/migration/cipherstash-codec-v3.ts rename to languages/typescript/packages/stack-prisma/src/migration/cipherstash-codec-v3.ts diff --git a/packages/stack-prisma/src/migration/eql-bundle-v3.ts b/languages/typescript/packages/stack-prisma/src/migration/eql-bundle-v3.ts similarity index 100% rename from packages/stack-prisma/src/migration/eql-bundle-v3.ts rename to languages/typescript/packages/stack-prisma/src/migration/eql-bundle-v3.ts diff --git a/packages/stack-prisma/src/stack/from-stack-v3.ts b/languages/typescript/packages/stack-prisma/src/stack/from-stack-v3.ts similarity index 100% rename from packages/stack-prisma/src/stack/from-stack-v3.ts rename to languages/typescript/packages/stack-prisma/src/stack/from-stack-v3.ts diff --git a/packages/stack-prisma/src/types/codec-types.ts b/languages/typescript/packages/stack-prisma/src/types/codec-types.ts similarity index 100% rename from packages/stack-prisma/src/types/codec-types.ts rename to languages/typescript/packages/stack-prisma/src/types/codec-types.ts diff --git a/packages/stack-prisma/src/types/operation-types.ts b/languages/typescript/packages/stack-prisma/src/types/operation-types.ts similarity index 100% rename from packages/stack-prisma/src/types/operation-types.ts rename to languages/typescript/packages/stack-prisma/src/types/operation-types.ts diff --git a/packages/stack-prisma/src/v3/barrel.ts b/languages/typescript/packages/stack-prisma/src/v3/barrel.ts similarity index 100% rename from packages/stack-prisma/src/v3/barrel.ts rename to languages/typescript/packages/stack-prisma/src/v3/barrel.ts diff --git a/packages/stack-prisma/src/v3/bulk-encrypt-v3.ts b/languages/typescript/packages/stack-prisma/src/v3/bulk-encrypt-v3.ts similarity index 100% rename from packages/stack-prisma/src/v3/bulk-encrypt-v3.ts rename to languages/typescript/packages/stack-prisma/src/v3/bulk-encrypt-v3.ts diff --git a/packages/stack-prisma/src/v3/catalog.ts b/languages/typescript/packages/stack-prisma/src/v3/catalog.ts similarity index 100% rename from packages/stack-prisma/src/v3/catalog.ts rename to languages/typescript/packages/stack-prisma/src/v3/catalog.ts diff --git a/packages/stack-prisma/src/v3/codec-runtime-v3.ts b/languages/typescript/packages/stack-prisma/src/v3/codec-runtime-v3.ts similarity index 100% rename from packages/stack-prisma/src/v3/codec-runtime-v3.ts rename to languages/typescript/packages/stack-prisma/src/v3/codec-runtime-v3.ts diff --git a/packages/stack-prisma/src/v3/derive-schemas-v3.ts b/languages/typescript/packages/stack-prisma/src/v3/derive-schemas-v3.ts similarity index 100% rename from packages/stack-prisma/src/v3/derive-schemas-v3.ts rename to languages/typescript/packages/stack-prisma/src/v3/derive-schemas-v3.ts diff --git a/packages/stack-prisma/src/v3/envelope-number.ts b/languages/typescript/packages/stack-prisma/src/v3/envelope-number.ts similarity index 100% rename from packages/stack-prisma/src/v3/envelope-number.ts rename to languages/typescript/packages/stack-prisma/src/v3/envelope-number.ts diff --git a/packages/stack-prisma/src/v3/from-stack-v3-validate.ts b/languages/typescript/packages/stack-prisma/src/v3/from-stack-v3-validate.ts similarity index 100% rename from packages/stack-prisma/src/v3/from-stack-v3-validate.ts rename to languages/typescript/packages/stack-prisma/src/v3/from-stack-v3-validate.ts diff --git a/packages/stack-prisma/src/v3/operators-v3.ts b/languages/typescript/packages/stack-prisma/src/v3/operators-v3.ts similarity index 100% rename from packages/stack-prisma/src/v3/operators-v3.ts rename to languages/typescript/packages/stack-prisma/src/v3/operators-v3.ts diff --git a/packages/stack-prisma/src/v3/query-term.ts b/languages/typescript/packages/stack-prisma/src/v3/query-term.ts similarity index 100% rename from packages/stack-prisma/src/v3/query-term.ts rename to languages/typescript/packages/stack-prisma/src/v3/query-term.ts diff --git a/packages/stack-prisma/src/v3/runtime-v3.ts b/languages/typescript/packages/stack-prisma/src/v3/runtime-v3.ts similarity index 100% rename from packages/stack-prisma/src/v3/runtime-v3.ts rename to languages/typescript/packages/stack-prisma/src/v3/runtime-v3.ts diff --git a/packages/stack-prisma/src/v3/sdk-adapter-v3.ts b/languages/typescript/packages/stack-prisma/src/v3/sdk-adapter-v3.ts similarity index 100% rename from packages/stack-prisma/src/v3/sdk-adapter-v3.ts rename to languages/typescript/packages/stack-prisma/src/v3/sdk-adapter-v3.ts diff --git a/packages/stack-prisma/src/v3/wire-v3.ts b/languages/typescript/packages/stack-prisma/src/v3/wire-v3.ts similarity index 100% rename from packages/stack-prisma/src/v3/wire-v3.ts rename to languages/typescript/packages/stack-prisma/src/v3/wire-v3.ts diff --git a/packages/stack-prisma/test/abort.test.ts b/languages/typescript/packages/stack-prisma/test/abort.test.ts similarity index 100% rename from packages/stack-prisma/test/abort.test.ts rename to languages/typescript/packages/stack-prisma/test/abort.test.ts diff --git a/packages/stack-prisma/test/authoring.test.ts b/languages/typescript/packages/stack-prisma/test/authoring.test.ts similarity index 100% rename from packages/stack-prisma/test/authoring.test.ts rename to languages/typescript/packages/stack-prisma/test/authoring.test.ts diff --git a/packages/stack-prisma/test/bulk-encrypt-middleware.helpers.ts b/languages/typescript/packages/stack-prisma/test/bulk-encrypt-middleware.helpers.ts similarity index 100% rename from packages/stack-prisma/test/bulk-encrypt-middleware.helpers.ts rename to languages/typescript/packages/stack-prisma/test/bulk-encrypt-middleware.helpers.ts diff --git a/packages/stack-prisma/test/bundling-isolation.test.ts b/languages/typescript/packages/stack-prisma/test/bundling-isolation.test.ts similarity index 100% rename from packages/stack-prisma/test/bundling-isolation.test.ts rename to languages/typescript/packages/stack-prisma/test/bundling-isolation.test.ts diff --git a/packages/stack-prisma/test/column-types.test.ts b/languages/typescript/packages/stack-prisma/test/column-types.test.ts similarity index 100% rename from packages/stack-prisma/test/column-types.test.ts rename to languages/typescript/packages/stack-prisma/test/column-types.test.ts diff --git a/packages/stack-prisma/test/decrypt-all.test.ts b/languages/typescript/packages/stack-prisma/test/decrypt-all.test.ts similarity index 100% rename from packages/stack-prisma/test/decrypt-all.test.ts rename to languages/typescript/packages/stack-prisma/test/decrypt-all.test.ts diff --git a/packages/stack-prisma/test/descriptor.test.ts b/languages/typescript/packages/stack-prisma/test/descriptor.test.ts similarity index 100% rename from packages/stack-prisma/test/descriptor.test.ts rename to languages/typescript/packages/stack-prisma/test/descriptor.test.ts diff --git a/packages/stack-prisma/test/envelope-bigint.test.ts b/languages/typescript/packages/stack-prisma/test/envelope-bigint.test.ts similarity index 100% rename from packages/stack-prisma/test/envelope-bigint.test.ts rename to languages/typescript/packages/stack-prisma/test/envelope-bigint.test.ts diff --git a/packages/stack-prisma/test/envelope-boolean.test.ts b/languages/typescript/packages/stack-prisma/test/envelope-boolean.test.ts similarity index 100% rename from packages/stack-prisma/test/envelope-boolean.test.ts rename to languages/typescript/packages/stack-prisma/test/envelope-boolean.test.ts diff --git a/packages/stack-prisma/test/envelope-date.test.ts b/languages/typescript/packages/stack-prisma/test/envelope-date.test.ts similarity index 100% rename from packages/stack-prisma/test/envelope-date.test.ts rename to languages/typescript/packages/stack-prisma/test/envelope-date.test.ts diff --git a/packages/stack-prisma/test/envelope-json.test.ts b/languages/typescript/packages/stack-prisma/test/envelope-json.test.ts similarity index 100% rename from packages/stack-prisma/test/envelope-json.test.ts rename to languages/typescript/packages/stack-prisma/test/envelope-json.test.ts diff --git a/packages/stack-prisma/test/envelope-string.test.ts b/languages/typescript/packages/stack-prisma/test/envelope-string.test.ts similarity index 100% rename from packages/stack-prisma/test/envelope-string.test.ts rename to languages/typescript/packages/stack-prisma/test/envelope-string.test.ts diff --git a/packages/stack-prisma/test/envelope.types.test-d.ts b/languages/typescript/packages/stack-prisma/test/envelope.types.test-d.ts similarity index 100% rename from packages/stack-prisma/test/envelope.types.test-d.ts rename to languages/typescript/packages/stack-prisma/test/envelope.types.test-d.ts diff --git a/packages/stack-prisma/test/equality-trait-removal.test.ts b/languages/typescript/packages/stack-prisma/test/equality-trait-removal.test.ts similarity index 100% rename from packages/stack-prisma/test/equality-trait-removal.test.ts rename to languages/typescript/packages/stack-prisma/test/equality-trait-removal.test.ts diff --git a/packages/stack-prisma/test/live/bigint-live-pg.test.ts b/languages/typescript/packages/stack-prisma/test/live/bigint-live-pg.test.ts similarity index 100% rename from packages/stack-prisma/test/live/bigint-live-pg.test.ts rename to languages/typescript/packages/stack-prisma/test/live/bigint-live-pg.test.ts diff --git a/packages/stack-prisma/test/live/boolean-storage-live-pg.test.ts b/languages/typescript/packages/stack-prisma/test/live/boolean-storage-live-pg.test.ts similarity index 100% rename from packages/stack-prisma/test/live/boolean-storage-live-pg.test.ts rename to languages/typescript/packages/stack-prisma/test/live/boolean-storage-live-pg.test.ts diff --git a/packages/stack-prisma/test/live/bulk-encrypt-live-pg.test.ts b/languages/typescript/packages/stack-prisma/test/live/bulk-encrypt-live-pg.test.ts similarity index 100% rename from packages/stack-prisma/test/live/bulk-encrypt-live-pg.test.ts rename to languages/typescript/packages/stack-prisma/test/live/bulk-encrypt-live-pg.test.ts diff --git a/packages/stack-prisma/test/live/helpers/eql-v3.ts b/languages/typescript/packages/stack-prisma/test/live/helpers/eql-v3.ts similarity index 100% rename from packages/stack-prisma/test/live/helpers/eql-v3.ts rename to languages/typescript/packages/stack-prisma/test/live/helpers/eql-v3.ts diff --git a/packages/stack-prisma/test/live/helpers/harness.ts b/languages/typescript/packages/stack-prisma/test/live/helpers/harness.ts similarity index 100% rename from packages/stack-prisma/test/live/helpers/harness.ts rename to languages/typescript/packages/stack-prisma/test/live/helpers/harness.ts diff --git a/packages/stack-prisma/test/live/helpers/live-gate.ts b/languages/typescript/packages/stack-prisma/test/live/helpers/live-gate.ts similarity index 100% rename from packages/stack-prisma/test/live/helpers/live-gate.ts rename to languages/typescript/packages/stack-prisma/test/live/helpers/live-gate.ts diff --git a/packages/stack-prisma/test/live/migration-apply-live-pg.test.ts b/languages/typescript/packages/stack-prisma/test/live/migration-apply-live-pg.test.ts similarity index 100% rename from packages/stack-prisma/test/live/migration-apply-live-pg.test.ts rename to languages/typescript/packages/stack-prisma/test/live/migration-apply-live-pg.test.ts diff --git a/packages/stack-prisma/test/live/operators-live-pg.test.ts b/languages/typescript/packages/stack-prisma/test/live/operators-live-pg.test.ts similarity index 100% rename from packages/stack-prisma/test/live/operators-live-pg.test.ts rename to languages/typescript/packages/stack-prisma/test/live/operators-live-pg.test.ts diff --git a/packages/stack-prisma/test/live/operators-null-live-pg.test.ts b/languages/typescript/packages/stack-prisma/test/live/operators-null-live-pg.test.ts similarity index 100% rename from packages/stack-prisma/test/live/operators-null-live-pg.test.ts rename to languages/typescript/packages/stack-prisma/test/live/operators-null-live-pg.test.ts diff --git a/packages/stack-prisma/test/operation-types.types.test-d.ts b/languages/typescript/packages/stack-prisma/test/operation-types.types.test-d.ts similarity index 100% rename from packages/stack-prisma/test/operation-types.types.test-d.ts rename to languages/typescript/packages/stack-prisma/test/operation-types.types.test-d.ts diff --git a/packages/stack-prisma/test/psl-interpretation.test.ts b/languages/typescript/packages/stack-prisma/test/psl-interpretation.test.ts similarity index 100% rename from packages/stack-prisma/test/psl-interpretation.test.ts rename to languages/typescript/packages/stack-prisma/test/psl-interpretation.test.ts diff --git a/packages/stack-prisma/test/routing.test.ts b/languages/typescript/packages/stack-prisma/test/routing.test.ts similarity index 100% rename from packages/stack-prisma/test/routing.test.ts rename to languages/typescript/packages/stack-prisma/test/routing.test.ts diff --git a/packages/stack-prisma/test/sdk.types.test-d.ts b/languages/typescript/packages/stack-prisma/test/sdk.types.test-d.ts similarity index 100% rename from packages/stack-prisma/test/sdk.types.test-d.ts rename to languages/typescript/packages/stack-prisma/test/sdk.types.test-d.ts diff --git a/packages/stack-prisma/test/v3/bulk-encrypt-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/bulk-encrypt-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/bulk-encrypt-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/bulk-encrypt-v3.test.ts diff --git a/packages/stack-prisma/test/v3/catalog-invariants.test.ts b/languages/typescript/packages/stack-prisma/test/v3/catalog-invariants.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/catalog-invariants.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/catalog-invariants.test.ts diff --git a/packages/stack-prisma/test/v3/catalog.test.ts b/languages/typescript/packages/stack-prisma/test/v3/catalog.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/catalog.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/catalog.test.ts diff --git a/packages/stack-prisma/test/v3/codec-runtime-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/codec-runtime-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/codec-runtime-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/codec-runtime-v3.test.ts diff --git a/packages/stack-prisma/test/v3/codec-types-v3.test-d.ts b/languages/typescript/packages/stack-prisma/test/v3/codec-types-v3.test-d.ts similarity index 100% rename from packages/stack-prisma/test/v3/codec-types-v3.test-d.ts rename to languages/typescript/packages/stack-prisma/test/v3/codec-types-v3.test-d.ts diff --git a/packages/stack-prisma/test/v3/column-types.test-d.ts b/languages/typescript/packages/stack-prisma/test/v3/column-types.test-d.ts similarity index 100% rename from packages/stack-prisma/test/v3/column-types.test-d.ts rename to languages/typescript/packages/stack-prisma/test/v3/column-types.test-d.ts diff --git a/packages/stack-prisma/test/v3/constants-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/constants-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/constants-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/constants-v3.test.ts diff --git a/packages/stack-prisma/test/v3/derive-schemas-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/derive-schemas-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/derive-schemas-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/derive-schemas-v3.test.ts diff --git a/packages/stack-prisma/test/v3/envelope-number.test.ts b/languages/typescript/packages/stack-prisma/test/v3/envelope-number.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/envelope-number.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/envelope-number.test.ts diff --git a/packages/stack-prisma/test/v3/from-stack-divergence-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/from-stack-divergence-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/from-stack-divergence-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/from-stack-divergence-v3.test.ts diff --git a/packages/stack-prisma/test/v3/from-stack-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/from-stack-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/from-stack-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/from-stack-v3.test.ts diff --git a/packages/stack-prisma/test/v3/migration-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/migration-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/migration-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/migration-v3.test.ts diff --git a/packages/stack-prisma/test/v3/operator-gating-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-gating-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/operator-gating-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/operator-gating-v3.test.ts diff --git a/packages/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts diff --git a/packages/stack-prisma/test/v3/operator-lowering-v3-json.test.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-json.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/operator-lowering-v3-json.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-json.test.ts diff --git a/packages/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts diff --git a/packages/stack-prisma/test/v3/operator-lowering-v3-text-search.test.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-text-search.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/operator-lowering-v3-text-search.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-text-search.test.ts diff --git a/packages/stack-prisma/test/v3/operator-lowering-v3.helpers.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3.helpers.ts similarity index 100% rename from packages/stack-prisma/test/v3/operator-lowering-v3.helpers.ts rename to languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3.helpers.ts diff --git a/packages/stack-prisma/test/v3/properties.test.ts b/languages/typescript/packages/stack-prisma/test/v3/properties.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/properties.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/properties.test.ts diff --git a/packages/stack-prisma/test/v3/runtime-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/runtime-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/runtime-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/runtime-v3.test.ts diff --git a/packages/stack-prisma/test/v3/sdk-adapter-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/sdk-adapter-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/sdk-adapter-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/sdk-adapter-v3.test.ts diff --git a/packages/stack-prisma/test/v3/stale-vendored-space.test.ts b/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/stale-vendored-space.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts diff --git a/packages/stack-prisma/test/v3/vendored-space-parity.test.ts b/languages/typescript/packages/stack-prisma/test/v3/vendored-space-parity.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/vendored-space-parity.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/vendored-space-parity.test.ts diff --git a/packages/stack-prisma/test/v3/wire-v3.test.ts b/languages/typescript/packages/stack-prisma/test/v3/wire-v3.test.ts similarity index 100% rename from packages/stack-prisma/test/v3/wire-v3.test.ts rename to languages/typescript/packages/stack-prisma/test/v3/wire-v3.test.ts diff --git a/packages/stack-prisma/tsconfig.json b/languages/typescript/packages/stack-prisma/tsconfig.json similarity index 100% rename from packages/stack-prisma/tsconfig.json rename to languages/typescript/packages/stack-prisma/tsconfig.json diff --git a/packages/stack-prisma/tsup.config.ts b/languages/typescript/packages/stack-prisma/tsup.config.ts similarity index 100% rename from packages/stack-prisma/tsup.config.ts rename to languages/typescript/packages/stack-prisma/tsup.config.ts diff --git a/packages/stack-prisma/turbo.json b/languages/typescript/packages/stack-prisma/turbo.json similarity index 100% rename from packages/stack-prisma/turbo.json rename to languages/typescript/packages/stack-prisma/turbo.json diff --git a/packages/stack-prisma/vitest.config.ts b/languages/typescript/packages/stack-prisma/vitest.config.ts similarity index 100% rename from packages/stack-prisma/vitest.config.ts rename to languages/typescript/packages/stack-prisma/vitest.config.ts diff --git a/packages/stack-supabase/CHANGELOG.md b/languages/typescript/packages/stack-supabase/CHANGELOG.md similarity index 100% rename from packages/stack-supabase/CHANGELOG.md rename to languages/typescript/packages/stack-supabase/CHANGELOG.md diff --git a/packages/stack-supabase/README.md b/languages/typescript/packages/stack-supabase/README.md similarity index 100% rename from packages/stack-supabase/README.md rename to languages/typescript/packages/stack-supabase/README.md diff --git a/packages/stack-supabase/__tests__/browser-export-condition.test.ts b/languages/typescript/packages/stack-supabase/__tests__/browser-export-condition.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/browser-export-condition.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/browser-export-condition.test.ts diff --git a/packages/stack-supabase/__tests__/column-map-predicate.test.ts b/languages/typescript/packages/stack-supabase/__tests__/column-map-predicate.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/column-map-predicate.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/column-map-predicate.test.ts diff --git a/packages/stack-supabase/__tests__/helpers/postgrest-wire.ts b/languages/typescript/packages/stack-supabase/__tests__/helpers/postgrest-wire.ts similarity index 100% rename from packages/stack-supabase/__tests__/helpers/postgrest-wire.ts rename to languages/typescript/packages/stack-supabase/__tests__/helpers/postgrest-wire.ts diff --git a/packages/stack-supabase/__tests__/helpers/supabase-mock.ts b/languages/typescript/packages/stack-supabase/__tests__/helpers/supabase-mock.ts similarity index 100% rename from packages/stack-supabase/__tests__/helpers/supabase-mock.ts rename to languages/typescript/packages/stack-supabase/__tests__/helpers/supabase-mock.ts diff --git a/packages/stack-supabase/__tests__/like-pattern.test.ts b/languages/typescript/packages/stack-supabase/__tests__/like-pattern.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/like-pattern.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/like-pattern.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-declared-mode.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-declared-mode.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-declared-mode.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-declared-mode.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-encryption-error.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-encryption-error.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-encryption-error.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-encryption-error.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-helpers.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-helpers.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-helpers.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-helpers.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-introspect.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-introspect.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-introspect.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-introspect.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-schema-builder.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-schema-builder.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-schema-builder.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-schema-builder.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-v3-builder.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-v3-builder.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-v3-builder.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-v3-builder.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-v3-factory.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-v3-factory.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-v3-factory.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-v3-factory.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-v3-json.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-v3-json.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-v3-json.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-v3-json.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-v3-matrix.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-v3-matrix.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-v3-matrix.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-v3-matrix.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-v3-select-star.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-v3-select-star.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-v3-select-star.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-v3-select-star.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-v3-wire.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-v3-wire.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-v3-wire.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-v3-wire.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-v3.test-d.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-v3.test-d.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-v3.test-d.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-v3.test-d.ts diff --git a/packages/stack-supabase/__tests__/supabase-verify.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-verify.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-verify.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-verify.test.ts diff --git a/packages/stack-supabase/__tests__/supabase-wasm-config.test-d.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-wasm-config.test-d.ts similarity index 100% rename from packages/stack-supabase/__tests__/supabase-wasm-config.test-d.ts rename to languages/typescript/packages/stack-supabase/__tests__/supabase-wasm-config.test-d.ts diff --git a/packages/stack-supabase/__tests__/wasm-client-adapter.test.ts b/languages/typescript/packages/stack-supabase/__tests__/wasm-client-adapter.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/wasm-client-adapter.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/wasm-client-adapter.test.ts diff --git a/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts b/languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts similarity index 100% rename from packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts rename to languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts diff --git a/packages/stack-supabase/integration/adapter.ts b/languages/typescript/packages/stack-supabase/integration/adapter.ts similarity index 100% rename from packages/stack-supabase/integration/adapter.ts rename to languages/typescript/packages/stack-supabase/integration/adapter.ts diff --git a/packages/stack-supabase/integration/families.integration.test.ts b/languages/typescript/packages/stack-supabase/integration/families.integration.test.ts similarity index 100% rename from packages/stack-supabase/integration/families.integration.test.ts rename to languages/typescript/packages/stack-supabase/integration/families.integration.test.ts diff --git a/packages/stack-supabase/integration/grants.integration.test.ts b/languages/typescript/packages/stack-supabase/integration/grants.integration.test.ts similarity index 100% rename from packages/stack-supabase/integration/grants.integration.test.ts rename to languages/typescript/packages/stack-supabase/integration/grants.integration.test.ts diff --git a/packages/stack-supabase/integration/helpers/pgrest.ts b/languages/typescript/packages/stack-supabase/integration/helpers/pgrest.ts similarity index 100% rename from packages/stack-supabase/integration/helpers/pgrest.ts rename to languages/typescript/packages/stack-supabase/integration/helpers/pgrest.ts diff --git a/packages/stack-supabase/integration/helpers/v3-envelope.ts b/languages/typescript/packages/stack-supabase/integration/helpers/v3-envelope.ts similarity index 100% rename from packages/stack-supabase/integration/helpers/v3-envelope.ts rename to languages/typescript/packages/stack-supabase/integration/helpers/v3-envelope.ts diff --git a/packages/stack-supabase/integration/introspect.integration.test.ts b/languages/typescript/packages/stack-supabase/integration/introspect.integration.test.ts similarity index 100% rename from packages/stack-supabase/integration/introspect.integration.test.ts rename to languages/typescript/packages/stack-supabase/integration/introspect.integration.test.ts diff --git a/packages/stack-supabase/integration/json.integration.test.ts b/languages/typescript/packages/stack-supabase/integration/json.integration.test.ts similarity index 100% rename from packages/stack-supabase/integration/json.integration.test.ts rename to languages/typescript/packages/stack-supabase/integration/json.integration.test.ts diff --git a/packages/stack-supabase/integration/select-alias.integration.test.ts b/languages/typescript/packages/stack-supabase/integration/select-alias.integration.test.ts similarity index 100% rename from packages/stack-supabase/integration/select-alias.integration.test.ts rename to languages/typescript/packages/stack-supabase/integration/select-alias.integration.test.ts diff --git a/packages/stack-supabase/integration/vitest.config.ts b/languages/typescript/packages/stack-supabase/integration/vitest.config.ts similarity index 100% rename from packages/stack-supabase/integration/vitest.config.ts rename to languages/typescript/packages/stack-supabase/integration/vitest.config.ts diff --git a/packages/stack-supabase/integration/wire.integration.test.ts b/languages/typescript/packages/stack-supabase/integration/wire.integration.test.ts similarity index 100% rename from packages/stack-supabase/integration/wire.integration.test.ts rename to languages/typescript/packages/stack-supabase/integration/wire.integration.test.ts diff --git a/packages/stack-supabase/package.json b/languages/typescript/packages/stack-supabase/package.json similarity index 100% rename from packages/stack-supabase/package.json rename to languages/typescript/packages/stack-supabase/package.json diff --git a/packages/stack-supabase/src/column-map.ts b/languages/typescript/packages/stack-supabase/src/column-map.ts similarity index 100% rename from packages/stack-supabase/src/column-map.ts rename to languages/typescript/packages/stack-supabase/src/column-map.ts diff --git a/packages/stack-supabase/src/create.ts b/languages/typescript/packages/stack-supabase/src/create.ts similarity index 100% rename from packages/stack-supabase/src/create.ts rename to languages/typescript/packages/stack-supabase/src/create.ts diff --git a/packages/stack-supabase/src/helpers.ts b/languages/typescript/packages/stack-supabase/src/helpers.ts similarity index 100% rename from packages/stack-supabase/src/helpers.ts rename to languages/typescript/packages/stack-supabase/src/helpers.ts diff --git a/packages/stack-supabase/src/index.ts b/languages/typescript/packages/stack-supabase/src/index.ts similarity index 100% rename from packages/stack-supabase/src/index.ts rename to languages/typescript/packages/stack-supabase/src/index.ts diff --git a/packages/stack-supabase/src/introspect.ts b/languages/typescript/packages/stack-supabase/src/introspect.ts similarity index 100% rename from packages/stack-supabase/src/introspect.ts rename to languages/typescript/packages/stack-supabase/src/introspect.ts diff --git a/packages/stack-supabase/src/like-pattern.ts b/languages/typescript/packages/stack-supabase/src/like-pattern.ts similarity index 100% rename from packages/stack-supabase/src/like-pattern.ts rename to languages/typescript/packages/stack-supabase/src/like-pattern.ts diff --git a/packages/stack-supabase/src/query-builder.ts b/languages/typescript/packages/stack-supabase/src/query-builder.ts similarity index 100% rename from packages/stack-supabase/src/query-builder.ts rename to languages/typescript/packages/stack-supabase/src/query-builder.ts diff --git a/packages/stack-supabase/src/query-dbspace.ts b/languages/typescript/packages/stack-supabase/src/query-dbspace.ts similarity index 100% rename from packages/stack-supabase/src/query-dbspace.ts rename to languages/typescript/packages/stack-supabase/src/query-dbspace.ts diff --git a/packages/stack-supabase/src/query-encrypt.ts b/languages/typescript/packages/stack-supabase/src/query-encrypt.ts similarity index 100% rename from packages/stack-supabase/src/query-encrypt.ts rename to languages/typescript/packages/stack-supabase/src/query-encrypt.ts diff --git a/packages/stack-supabase/src/query-filters.ts b/languages/typescript/packages/stack-supabase/src/query-filters.ts similarity index 100% rename from packages/stack-supabase/src/query-filters.ts rename to languages/typescript/packages/stack-supabase/src/query-filters.ts diff --git a/packages/stack-supabase/src/query-mutation.ts b/languages/typescript/packages/stack-supabase/src/query-mutation.ts similarity index 100% rename from packages/stack-supabase/src/query-mutation.ts rename to languages/typescript/packages/stack-supabase/src/query-mutation.ts diff --git a/packages/stack-supabase/src/query-results.ts b/languages/typescript/packages/stack-supabase/src/query-results.ts similarity index 100% rename from packages/stack-supabase/src/query-results.ts rename to languages/typescript/packages/stack-supabase/src/query-results.ts diff --git a/packages/stack-supabase/src/query-terms.ts b/languages/typescript/packages/stack-supabase/src/query-terms.ts similarity index 100% rename from packages/stack-supabase/src/query-terms.ts rename to languages/typescript/packages/stack-supabase/src/query-terms.ts diff --git a/packages/stack-supabase/src/schema-builder.ts b/languages/typescript/packages/stack-supabase/src/schema-builder.ts similarity index 100% rename from packages/stack-supabase/src/schema-builder.ts rename to languages/typescript/packages/stack-supabase/src/schema-builder.ts diff --git a/packages/stack-supabase/src/types.ts b/languages/typescript/packages/stack-supabase/src/types.ts similarity index 100% rename from packages/stack-supabase/src/types.ts rename to languages/typescript/packages/stack-supabase/src/types.ts diff --git a/packages/stack-supabase/src/verify.ts b/languages/typescript/packages/stack-supabase/src/verify.ts similarity index 100% rename from packages/stack-supabase/src/verify.ts rename to languages/typescript/packages/stack-supabase/src/verify.ts diff --git a/packages/stack-supabase/src/wasm-client-adapter.ts b/languages/typescript/packages/stack-supabase/src/wasm-client-adapter.ts similarity index 100% rename from packages/stack-supabase/src/wasm-client-adapter.ts rename to languages/typescript/packages/stack-supabase/src/wasm-client-adapter.ts diff --git a/packages/stack-supabase/src/wasm-inline.ts b/languages/typescript/packages/stack-supabase/src/wasm-inline.ts similarity index 100% rename from packages/stack-supabase/src/wasm-inline.ts rename to languages/typescript/packages/stack-supabase/src/wasm-inline.ts diff --git a/packages/stack-supabase/tsconfig.json b/languages/typescript/packages/stack-supabase/tsconfig.json similarity index 100% rename from packages/stack-supabase/tsconfig.json rename to languages/typescript/packages/stack-supabase/tsconfig.json diff --git a/packages/stack-supabase/tsconfig.typecheck.json b/languages/typescript/packages/stack-supabase/tsconfig.typecheck.json similarity index 100% rename from packages/stack-supabase/tsconfig.typecheck.json rename to languages/typescript/packages/stack-supabase/tsconfig.typecheck.json diff --git a/packages/stack-supabase/tsup.config.ts b/languages/typescript/packages/stack-supabase/tsup.config.ts similarity index 100% rename from packages/stack-supabase/tsup.config.ts rename to languages/typescript/packages/stack-supabase/tsup.config.ts diff --git a/packages/stack-supabase/turbo.json b/languages/typescript/packages/stack-supabase/turbo.json similarity index 100% rename from packages/stack-supabase/turbo.json rename to languages/typescript/packages/stack-supabase/turbo.json diff --git a/packages/stack-supabase/vitest.config.ts b/languages/typescript/packages/stack-supabase/vitest.config.ts similarity index 100% rename from packages/stack-supabase/vitest.config.ts rename to languages/typescript/packages/stack-supabase/vitest.config.ts diff --git a/packages/stack/CHANGELOG.md b/languages/typescript/packages/stack/CHANGELOG.md similarity index 100% rename from packages/stack/CHANGELOG.md rename to languages/typescript/packages/stack/CHANGELOG.md diff --git a/packages/stack/README.md b/languages/typescript/packages/stack/README.md similarity index 100% rename from packages/stack/README.md rename to languages/typescript/packages/stack/README.md diff --git a/packages/stack/__tests__/audit.test.ts b/languages/typescript/packages/stack/__tests__/audit.test.ts similarity index 100% rename from packages/stack/__tests__/audit.test.ts rename to languages/typescript/packages/stack/__tests__/audit.test.ts diff --git a/packages/stack/__tests__/auth-failure-propagation.test.ts b/languages/typescript/packages/stack/__tests__/auth-failure-propagation.test.ts similarity index 100% rename from packages/stack/__tests__/auth-failure-propagation.test.ts rename to languages/typescript/packages/stack/__tests__/auth-failure-propagation.test.ts diff --git a/packages/stack/__tests__/auth-reexports.test.ts b/languages/typescript/packages/stack/__tests__/auth-reexports.test.ts similarity index 100% rename from packages/stack/__tests__/auth-reexports.test.ts rename to languages/typescript/packages/stack/__tests__/auth-reexports.test.ts diff --git a/packages/stack/__tests__/basic-protect.test.ts b/languages/typescript/packages/stack/__tests__/basic-protect.test.ts similarity index 100% rename from packages/stack/__tests__/basic-protect.test.ts rename to languages/typescript/packages/stack/__tests__/basic-protect.test.ts diff --git a/packages/stack/__tests__/browser-export-condition.test.ts b/languages/typescript/packages/stack/__tests__/browser-export-condition.test.ts similarity index 100% rename from packages/stack/__tests__/browser-export-condition.test.ts rename to languages/typescript/packages/stack/__tests__/browser-export-condition.test.ts diff --git a/packages/stack/__tests__/bulk-decrypt-item-failure.test.ts b/languages/typescript/packages/stack/__tests__/bulk-decrypt-item-failure.test.ts similarity index 100% rename from packages/stack/__tests__/bulk-decrypt-item-failure.test.ts rename to languages/typescript/packages/stack/__tests__/bulk-decrypt-item-failure.test.ts diff --git a/packages/stack/__tests__/bulk-encrypt-validation.test.ts b/languages/typescript/packages/stack/__tests__/bulk-encrypt-validation.test.ts similarity index 100% rename from packages/stack/__tests__/bulk-encrypt-validation.test.ts rename to languages/typescript/packages/stack/__tests__/bulk-encrypt-validation.test.ts diff --git a/packages/stack/__tests__/bulk-model-hyphen-fields.test.ts b/languages/typescript/packages/stack/__tests__/bulk-model-hyphen-fields.test.ts similarity index 100% rename from packages/stack/__tests__/bulk-model-hyphen-fields.test.ts rename to languages/typescript/packages/stack/__tests__/bulk-model-hyphen-fields.test.ts diff --git a/packages/stack/__tests__/bulk-protect.test.ts b/languages/typescript/packages/stack/__tests__/bulk-protect.test.ts similarity index 100% rename from packages/stack/__tests__/bulk-protect.test.ts rename to languages/typescript/packages/stack/__tests__/bulk-protect.test.ts diff --git a/packages/stack/__tests__/cjs-require.test.ts b/languages/typescript/packages/stack/__tests__/cjs-require.test.ts similarity index 100% rename from packages/stack/__tests__/cjs-require.test.ts rename to languages/typescript/packages/stack/__tests__/cjs-require.test.ts diff --git a/packages/stack/__tests__/clerk-provider.test.ts b/languages/typescript/packages/stack/__tests__/clerk-provider.test.ts similarity index 100% rename from packages/stack/__tests__/clerk-provider.test.ts rename to languages/typescript/packages/stack/__tests__/clerk-provider.test.ts diff --git a/packages/stack/__tests__/client-get-schemas.test.ts b/languages/typescript/packages/stack/__tests__/client-get-schemas.test.ts similarity index 100% rename from packages/stack/__tests__/client-get-schemas.test.ts rename to languages/typescript/packages/stack/__tests__/client-get-schemas.test.ts diff --git a/packages/stack/__tests__/config.test.ts b/languages/typescript/packages/stack/__tests__/config.test.ts similarity index 100% rename from packages/stack/__tests__/config.test.ts rename to languages/typescript/packages/stack/__tests__/config.test.ts diff --git a/packages/stack/__tests__/decrypt-audit-forwarding.test.ts b/languages/typescript/packages/stack/__tests__/decrypt-audit-forwarding.test.ts similarity index 100% rename from packages/stack/__tests__/decrypt-audit-forwarding.test.ts rename to languages/typescript/packages/stack/__tests__/decrypt-audit-forwarding.test.ts diff --git a/packages/stack/__tests__/diagnostics-entry.test.ts b/languages/typescript/packages/stack/__tests__/diagnostics-entry.test.ts similarity index 100% rename from packages/stack/__tests__/diagnostics-entry.test.ts rename to languages/typescript/packages/stack/__tests__/diagnostics-entry.test.ts diff --git a/packages/stack/__tests__/dynamodb/client-compat.test-d.ts b/languages/typescript/packages/stack/__tests__/dynamodb/client-compat.test-d.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/client-compat.test-d.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/client-compat.test-d.ts diff --git a/packages/stack/__tests__/dynamodb/construct-guard.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/construct-guard.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/construct-guard.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/construct-guard.test.ts diff --git a/packages/stack/__tests__/dynamodb/encrypted-dynamodb-v3.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/encrypted-dynamodb-v3.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/encrypted-dynamodb-v3.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/encrypted-dynamodb-v3.test.ts diff --git a/packages/stack/__tests__/dynamodb/helpers-v3.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/helpers-v3.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/helpers-v3.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/helpers-v3.test.ts diff --git a/packages/stack/__tests__/dynamodb/hmac-domains.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/hmac-domains.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/hmac-domains.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/hmac-domains.test.ts diff --git a/packages/stack/__tests__/dynamodb/properties.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/properties.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/properties.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/properties.test.ts diff --git a/packages/stack/__tests__/dynamodb/resolve-decrypt.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/resolve-decrypt.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/resolve-decrypt.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/resolve-decrypt.test.ts diff --git a/packages/stack/__tests__/dynamodb/v2-grouped-date.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/v2-grouped-date.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/v2-grouped-date.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/v2-grouped-date.test.ts diff --git a/packages/stack/__tests__/dynamodb/v2-table-forwarding.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/v2-table-forwarding.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/v2-table-forwarding.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/v2-table-forwarding.test.ts diff --git a/packages/stack/__tests__/dynamodb/v2-type-coverage.test.ts b/languages/typescript/packages/stack/__tests__/dynamodb/v2-type-coverage.test.ts similarity index 100% rename from packages/stack/__tests__/dynamodb/v2-type-coverage.test.ts rename to languages/typescript/packages/stack/__tests__/dynamodb/v2-type-coverage.test.ts diff --git a/packages/stack/__tests__/empty-schemas-boundary.test.ts b/languages/typescript/packages/stack/__tests__/empty-schemas-boundary.test.ts similarity index 100% rename from packages/stack/__tests__/empty-schemas-boundary.test.ts rename to languages/typescript/packages/stack/__tests__/empty-schemas-boundary.test.ts diff --git a/packages/stack/__tests__/encrypt-lock-context-guards.test.ts b/languages/typescript/packages/stack/__tests__/encrypt-lock-context-guards.test.ts similarity index 100% rename from packages/stack/__tests__/encrypt-lock-context-guards.test.ts rename to languages/typescript/packages/stack/__tests__/encrypt-lock-context-guards.test.ts diff --git a/packages/stack/__tests__/encrypt-query-match-preflight.test.ts b/languages/typescript/packages/stack/__tests__/encrypt-query-match-preflight.test.ts similarity index 100% rename from packages/stack/__tests__/encrypt-query-match-preflight.test.ts rename to languages/typescript/packages/stack/__tests__/encrypt-query-match-preflight.test.ts diff --git a/packages/stack/__tests__/encrypt-query-searchable-json.test.ts b/languages/typescript/packages/stack/__tests__/encrypt-query-searchable-json.test.ts similarity index 100% rename from packages/stack/__tests__/encrypt-query-searchable-json.test.ts rename to languages/typescript/packages/stack/__tests__/encrypt-query-searchable-json.test.ts diff --git a/packages/stack/__tests__/encrypt-query-stevec.test.ts b/languages/typescript/packages/stack/__tests__/encrypt-query-stevec.test.ts similarity index 100% rename from packages/stack/__tests__/encrypt-query-stevec.test.ts rename to languages/typescript/packages/stack/__tests__/encrypt-query-stevec.test.ts diff --git a/packages/stack/__tests__/encrypt-query.test.ts b/languages/typescript/packages/stack/__tests__/encrypt-query.test.ts similarity index 100% rename from packages/stack/__tests__/encrypt-query.test.ts rename to languages/typescript/packages/stack/__tests__/encrypt-query.test.ts diff --git a/packages/stack/__tests__/encryption-helpers.test.ts b/languages/typescript/packages/stack/__tests__/encryption-helpers.test.ts similarity index 100% rename from packages/stack/__tests__/encryption-helpers.test.ts rename to languages/typescript/packages/stack/__tests__/encryption-helpers.test.ts diff --git a/packages/stack/__tests__/encryption-v3-only.test-d.ts b/languages/typescript/packages/stack/__tests__/encryption-v3-only.test-d.ts similarity index 100% rename from packages/stack/__tests__/encryption-v3-only.test-d.ts rename to languages/typescript/packages/stack/__tests__/encryption-v3-only.test-d.ts diff --git a/packages/stack/__tests__/eql-v3-capability-matrix-skill.test.ts b/languages/typescript/packages/stack/__tests__/eql-v3-capability-matrix-skill.test.ts similarity index 100% rename from packages/stack/__tests__/eql-v3-capability-matrix-skill.test.ts rename to languages/typescript/packages/stack/__tests__/eql-v3-capability-matrix-skill.test.ts diff --git a/packages/stack/__tests__/eql-v3-domain-registry.test.ts b/languages/typescript/packages/stack/__tests__/eql-v3-domain-registry.test.ts similarity index 100% rename from packages/stack/__tests__/eql-v3-domain-registry.test.ts rename to languages/typescript/packages/stack/__tests__/eql-v3-domain-registry.test.ts diff --git a/packages/stack/__tests__/error-codes.test.ts b/languages/typescript/packages/stack/__tests__/error-codes.test.ts similarity index 100% rename from packages/stack/__tests__/error-codes.test.ts rename to languages/typescript/packages/stack/__tests__/error-codes.test.ts diff --git a/packages/stack/__tests__/error-discriminated-union.test-d.ts b/languages/typescript/packages/stack/__tests__/error-discriminated-union.test-d.ts similarity index 100% rename from packages/stack/__tests__/error-discriminated-union.test-d.ts rename to languages/typescript/packages/stack/__tests__/error-discriminated-union.test-d.ts diff --git a/packages/stack/__tests__/error-helpers.test.ts b/languages/typescript/packages/stack/__tests__/error-helpers.test.ts similarity index 100% rename from packages/stack/__tests__/error-helpers.test.ts rename to languages/typescript/packages/stack/__tests__/error-helpers.test.ts diff --git a/packages/stack/__tests__/fixtures-query-contract.test.ts b/languages/typescript/packages/stack/__tests__/fixtures-query-contract.test.ts similarity index 100% rename from packages/stack/__tests__/fixtures-query-contract.test.ts rename to languages/typescript/packages/stack/__tests__/fixtures-query-contract.test.ts diff --git a/packages/stack/__tests__/fixtures/index.ts b/languages/typescript/packages/stack/__tests__/fixtures/index.ts similarity index 100% rename from packages/stack/__tests__/fixtures/index.ts rename to languages/typescript/packages/stack/__tests__/fixtures/index.ts diff --git a/packages/stack/__tests__/helpers.test.ts b/languages/typescript/packages/stack/__tests__/helpers.test.ts similarity index 100% rename from packages/stack/__tests__/helpers.test.ts rename to languages/typescript/packages/stack/__tests__/helpers.test.ts diff --git a/packages/stack/__tests__/helpers/expect-result.ts b/languages/typescript/packages/stack/__tests__/helpers/expect-result.ts similarity index 100% rename from packages/stack/__tests__/helpers/expect-result.ts rename to languages/typescript/packages/stack/__tests__/helpers/expect-result.ts diff --git a/packages/stack/__tests__/helpers/process-free-realm.mjs b/languages/typescript/packages/stack/__tests__/helpers/process-free-realm.mjs similarity index 100% rename from packages/stack/__tests__/helpers/process-free-realm.mjs rename to languages/typescript/packages/stack/__tests__/helpers/process-free-realm.mjs diff --git a/packages/stack/__tests__/helpers/stub-auth-wasm-inline.ts b/languages/typescript/packages/stack/__tests__/helpers/stub-auth-wasm-inline.ts similarity index 100% rename from packages/stack/__tests__/helpers/stub-auth-wasm-inline.ts rename to languages/typescript/packages/stack/__tests__/helpers/stub-auth-wasm-inline.ts diff --git a/packages/stack/__tests__/helpers/stub-protect-ffi-wasm-inline.ts b/languages/typescript/packages/stack/__tests__/helpers/stub-protect-ffi-wasm-inline.ts similarity index 100% rename from packages/stack/__tests__/helpers/stub-protect-ffi-wasm-inline.ts rename to languages/typescript/packages/stack/__tests__/helpers/stub-protect-ffi-wasm-inline.ts diff --git a/packages/stack/__tests__/identify-cts-refusal.test.ts b/languages/typescript/packages/stack/__tests__/identify-cts-refusal.test.ts similarity index 100% rename from packages/stack/__tests__/identify-cts-refusal.test.ts rename to languages/typescript/packages/stack/__tests__/identify-cts-refusal.test.ts diff --git a/packages/stack/__tests__/infer-index-type.test.ts b/languages/typescript/packages/stack/__tests__/infer-index-type.test.ts similarity index 100% rename from packages/stack/__tests__/infer-index-type.test.ts rename to languages/typescript/packages/stack/__tests__/infer-index-type.test.ts diff --git a/packages/stack/__tests__/init-strategy.test.ts b/languages/typescript/packages/stack/__tests__/init-strategy.test.ts similarity index 100% rename from packages/stack/__tests__/init-strategy.test.ts rename to languages/typescript/packages/stack/__tests__/init-strategy.test.ts diff --git a/packages/stack/__tests__/jsonb-helpers.test.ts b/languages/typescript/packages/stack/__tests__/jsonb-helpers.test.ts similarity index 100% rename from packages/stack/__tests__/jsonb-helpers.test.ts rename to languages/typescript/packages/stack/__tests__/jsonb-helpers.test.ts diff --git a/packages/stack/__tests__/keysets.test.ts b/languages/typescript/packages/stack/__tests__/keysets.test.ts similarity index 100% rename from packages/stack/__tests__/keysets.test.ts rename to languages/typescript/packages/stack/__tests__/keysets.test.ts diff --git a/packages/stack/__tests__/lock-context-wiring.test.ts b/languages/typescript/packages/stack/__tests__/lock-context-wiring.test.ts similarity index 100% rename from packages/stack/__tests__/lock-context-wiring.test.ts rename to languages/typescript/packages/stack/__tests__/lock-context-wiring.test.ts diff --git a/packages/stack/__tests__/lock-context.test.ts b/languages/typescript/packages/stack/__tests__/lock-context.test.ts similarity index 100% rename from packages/stack/__tests__/lock-context.test.ts rename to languages/typescript/packages/stack/__tests__/lock-context.test.ts diff --git a/packages/stack/__tests__/logger-edge-safety.test.ts b/languages/typescript/packages/stack/__tests__/logger-edge-safety.test.ts similarity index 100% rename from packages/stack/__tests__/logger-edge-safety.test.ts rename to languages/typescript/packages/stack/__tests__/logger-edge-safety.test.ts diff --git a/packages/stack/__tests__/match-bloom-live.test.ts b/languages/typescript/packages/stack/__tests__/match-bloom-live.test.ts similarity index 100% rename from packages/stack/__tests__/match-bloom-live.test.ts rename to languages/typescript/packages/stack/__tests__/match-bloom-live.test.ts diff --git a/packages/stack/__tests__/match-needle-guard.test.ts b/languages/typescript/packages/stack/__tests__/match-needle-guard.test.ts similarity index 100% rename from packages/stack/__tests__/match-needle-guard.test.ts rename to languages/typescript/packages/stack/__tests__/match-needle-guard.test.ts diff --git a/packages/stack/__tests__/model-column-mapping.test.ts b/languages/typescript/packages/stack/__tests__/model-column-mapping.test.ts similarity index 100% rename from packages/stack/__tests__/model-column-mapping.test.ts rename to languages/typescript/packages/stack/__tests__/model-column-mapping.test.ts diff --git a/packages/stack/__tests__/null-guards.test.ts b/languages/typescript/packages/stack/__tests__/null-guards.test.ts similarity index 100% rename from packages/stack/__tests__/null-guards.test.ts rename to languages/typescript/packages/stack/__tests__/null-guards.test.ts diff --git a/packages/stack/__tests__/operation-failure-diagnostics.test.ts b/languages/typescript/packages/stack/__tests__/operation-failure-diagnostics.test.ts similarity index 100% rename from packages/stack/__tests__/operation-failure-diagnostics.test.ts rename to languages/typescript/packages/stack/__tests__/operation-failure-diagnostics.test.ts diff --git a/packages/stack/__tests__/protect-ops.test.ts b/languages/typescript/packages/stack/__tests__/protect-ops.test.ts similarity index 100% rename from packages/stack/__tests__/protect-ops.test.ts rename to languages/typescript/packages/stack/__tests__/protect-ops.test.ts diff --git a/packages/stack/__tests__/readme-sync.test.ts b/languages/typescript/packages/stack/__tests__/readme-sync.test.ts similarity index 100% rename from packages/stack/__tests__/readme-sync.test.ts rename to languages/typescript/packages/stack/__tests__/readme-sync.test.ts diff --git a/packages/stack/__tests__/resolve-lock-context.test.ts b/languages/typescript/packages/stack/__tests__/resolve-lock-context.test.ts similarity index 100% rename from packages/stack/__tests__/resolve-lock-context.test.ts rename to languages/typescript/packages/stack/__tests__/resolve-lock-context.test.ts diff --git a/packages/stack/__tests__/schema-v3.test.ts b/languages/typescript/packages/stack/__tests__/schema-v3.test.ts similarity index 100% rename from packages/stack/__tests__/schema-v3.test.ts rename to languages/typescript/packages/stack/__tests__/schema-v3.test.ts diff --git a/packages/stack/__tests__/selector-path.test.ts b/languages/typescript/packages/stack/__tests__/selector-path.test.ts similarity index 100% rename from packages/stack/__tests__/selector-path.test.ts rename to languages/typescript/packages/stack/__tests__/selector-path.test.ts diff --git a/packages/stack/__tests__/subpath-types-parity.test.ts b/languages/typescript/packages/stack/__tests__/subpath-types-parity.test.ts similarity index 100% rename from packages/stack/__tests__/subpath-types-parity.test.ts rename to languages/typescript/packages/stack/__tests__/subpath-types-parity.test.ts diff --git a/packages/stack/__tests__/test-kit-env.test.ts b/languages/typescript/packages/stack/__tests__/test-kit-env.test.ts similarity index 100% rename from packages/stack/__tests__/test-kit-env.test.ts rename to languages/typescript/packages/stack/__tests__/test-kit-env.test.ts diff --git a/packages/stack/__tests__/test-kit-families.test.ts b/languages/typescript/packages/stack/__tests__/test-kit-families.test.ts similarity index 100% rename from packages/stack/__tests__/test-kit-families.test.ts rename to languages/typescript/packages/stack/__tests__/test-kit-families.test.ts diff --git a/packages/stack/__tests__/test-kit-v2-fixtures.test.ts b/languages/typescript/packages/stack/__tests__/test-kit-v2-fixtures.test.ts similarity index 100% rename from packages/stack/__tests__/test-kit-v2-fixtures.test.ts rename to languages/typescript/packages/stack/__tests__/test-kit-v2-fixtures.test.ts diff --git a/packages/stack/__tests__/typed-client-v3.test-d.ts b/languages/typescript/packages/stack/__tests__/typed-client-v3.test-d.ts similarity index 100% rename from packages/stack/__tests__/typed-client-v3.test-d.ts rename to languages/typescript/packages/stack/__tests__/typed-client-v3.test-d.ts diff --git a/packages/stack/__tests__/typed-client-v3.test.ts b/languages/typescript/packages/stack/__tests__/typed-client-v3.test.ts similarity index 100% rename from packages/stack/__tests__/typed-client-v3.test.ts rename to languages/typescript/packages/stack/__tests__/typed-client-v3.test.ts diff --git a/packages/stack/__tests__/types-public-surface.test-d.ts b/languages/typescript/packages/stack/__tests__/types-public-surface.test-d.ts similarity index 100% rename from packages/stack/__tests__/types-public-surface.test-d.ts rename to languages/typescript/packages/stack/__tests__/types-public-surface.test-d.ts diff --git a/packages/stack/__tests__/v3-matrix/catalog.ts b/languages/typescript/packages/stack/__tests__/v3-matrix/catalog.ts similarity index 100% rename from packages/stack/__tests__/v3-matrix/catalog.ts rename to languages/typescript/packages/stack/__tests__/v3-matrix/catalog.ts diff --git a/packages/stack/__tests__/v3-matrix/matrix-audit.test-d.ts b/languages/typescript/packages/stack/__tests__/v3-matrix/matrix-audit.test-d.ts similarity index 100% rename from packages/stack/__tests__/v3-matrix/matrix-audit.test-d.ts rename to languages/typescript/packages/stack/__tests__/v3-matrix/matrix-audit.test-d.ts diff --git a/packages/stack/__tests__/v3-matrix/matrix-lock-context.test.ts b/languages/typescript/packages/stack/__tests__/v3-matrix/matrix-lock-context.test.ts similarity index 100% rename from packages/stack/__tests__/v3-matrix/matrix-lock-context.test.ts rename to languages/typescript/packages/stack/__tests__/v3-matrix/matrix-lock-context.test.ts diff --git a/packages/stack/__tests__/v3-matrix/matrix.test-d.ts b/languages/typescript/packages/stack/__tests__/v3-matrix/matrix.test-d.ts similarity index 100% rename from packages/stack/__tests__/v3-matrix/matrix.test-d.ts rename to languages/typescript/packages/stack/__tests__/v3-matrix/matrix.test-d.ts diff --git a/packages/stack/__tests__/v3-matrix/matrix.test.ts b/languages/typescript/packages/stack/__tests__/v3-matrix/matrix.test.ts similarity index 100% rename from packages/stack/__tests__/v3-matrix/matrix.test.ts rename to languages/typescript/packages/stack/__tests__/v3-matrix/matrix.test.ts diff --git a/packages/stack/__tests__/v3-matrix/needle-for.test.ts b/languages/typescript/packages/stack/__tests__/v3-matrix/needle-for.test.ts similarity index 100% rename from packages/stack/__tests__/v3-matrix/needle-for.test.ts rename to languages/typescript/packages/stack/__tests__/v3-matrix/needle-for.test.ts diff --git a/packages/stack/__tests__/v3-only-public-surface.test.ts b/languages/typescript/packages/stack/__tests__/v3-only-public-surface.test.ts similarity index 100% rename from packages/stack/__tests__/v3-only-public-surface.test.ts rename to languages/typescript/packages/stack/__tests__/v3-only-public-surface.test.ts diff --git a/packages/stack/__tests__/wasm-inline-auth-failure.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-auth-failure.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-auth-failure.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-auth-failure.test.ts diff --git a/packages/stack/__tests__/wasm-inline-bulk.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-bulk.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-bulk.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-bulk.test.ts diff --git a/packages/stack/__tests__/wasm-inline-bundle-isolation.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-bundle-isolation.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-bundle-isolation.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-bundle-isolation.test.ts diff --git a/packages/stack/__tests__/wasm-inline-column-name.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-column-name.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-column-name.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-column-name.test.ts diff --git a/packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts diff --git a/packages/stack/__tests__/wasm-inline-models.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-models.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-models.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-models.test.ts diff --git a/packages/stack/__tests__/wasm-inline-new-client.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-new-client.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-new-client.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-new-client.test.ts diff --git a/packages/stack/__tests__/wasm-inline-normalize.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-normalize.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-normalize.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-normalize.test.ts diff --git a/packages/stack/__tests__/wasm-inline-query.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-query.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-query.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-query.test.ts diff --git a/packages/stack/__tests__/wasm-inline-result-contract.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-result-contract.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-result-contract.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-result-contract.test.ts diff --git a/packages/stack/__tests__/wasm-inline-schemas.test-d.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-schemas.test-d.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-schemas.test-d.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-schemas.test-d.ts diff --git a/packages/stack/__tests__/wasm-inline-strategy.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-strategy.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-strategy.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-strategy.test.ts diff --git a/packages/stack/__tests__/wasm-inline-v3.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-v3.test.ts similarity index 100% rename from packages/stack/__tests__/wasm-inline-v3.test.ts rename to languages/typescript/packages/stack/__tests__/wasm-inline-v3.test.ts diff --git a/packages/stack/__tests__/wasm-plaintext.test-d.ts b/languages/typescript/packages/stack/__tests__/wasm-plaintext.test-d.ts similarity index 100% rename from packages/stack/__tests__/wasm-plaintext.test-d.ts rename to languages/typescript/packages/stack/__tests__/wasm-plaintext.test-d.ts diff --git a/packages/stack/dist-types/README.md b/languages/typescript/packages/stack/dist-types/README.md similarity index 100% rename from packages/stack/dist-types/README.md rename to languages/typescript/packages/stack/dist-types/README.md diff --git a/packages/stack/dist-types/encrypt-query.ts b/languages/typescript/packages/stack/dist-types/encrypt-query.ts similarity index 100% rename from packages/stack/dist-types/encrypt-query.ts rename to languages/typescript/packages/stack/dist-types/encrypt-query.ts diff --git a/packages/stack/dist-types/node16/encrypt-query.cts b/languages/typescript/packages/stack/dist-types/node16/encrypt-query.cts similarity index 100% rename from packages/stack/dist-types/node16/encrypt-query.cts rename to languages/typescript/packages/stack/dist-types/node16/encrypt-query.cts diff --git a/packages/stack/dist-types/node16/encrypt-query.mts b/languages/typescript/packages/stack/dist-types/node16/encrypt-query.mts similarity index 100% rename from packages/stack/dist-types/node16/encrypt-query.mts rename to languages/typescript/packages/stack/dist-types/node16/encrypt-query.mts diff --git a/packages/stack/dist-types/node16/tsconfig.json b/languages/typescript/packages/stack/dist-types/node16/tsconfig.json similarity index 100% rename from packages/stack/dist-types/node16/tsconfig.json rename to languages/typescript/packages/stack/dist-types/node16/tsconfig.json diff --git a/packages/stack/dist-types/node16/wasm-inline.mts b/languages/typescript/packages/stack/dist-types/node16/wasm-inline.mts similarity index 100% rename from packages/stack/dist-types/node16/wasm-inline.mts rename to languages/typescript/packages/stack/dist-types/node16/wasm-inline.mts diff --git a/packages/stack/dist-types/schemas-and-config.ts b/languages/typescript/packages/stack/dist-types/schemas-and-config.ts similarity index 100% rename from packages/stack/dist-types/schemas-and-config.ts rename to languages/typescript/packages/stack/dist-types/schemas-and-config.ts diff --git a/packages/stack/dist-types/tsconfig.json b/languages/typescript/packages/stack/dist-types/tsconfig.json similarity index 100% rename from packages/stack/dist-types/tsconfig.json rename to languages/typescript/packages/stack/dist-types/tsconfig.json diff --git a/packages/stack/dist-types/wasm-inline-type-identity.ts b/languages/typescript/packages/stack/dist-types/wasm-inline-type-identity.ts similarity index 100% rename from packages/stack/dist-types/wasm-inline-type-identity.ts rename to languages/typescript/packages/stack/dist-types/wasm-inline-type-identity.ts diff --git a/packages/stack/integration/identity/matrix-identity.integration.test.ts b/languages/typescript/packages/stack/integration/identity/matrix-identity.integration.test.ts similarity index 100% rename from packages/stack/integration/identity/matrix-identity.integration.test.ts rename to languages/typescript/packages/stack/integration/identity/matrix-identity.integration.test.ts diff --git a/packages/stack/integration/shared/harness.integration.test.ts b/languages/typescript/packages/stack/integration/shared/harness.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/harness.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/harness.integration.test.ts diff --git a/packages/stack/integration/shared/json-crypto.integration.test.ts b/languages/typescript/packages/stack/integration/shared/json-crypto.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/json-crypto.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/json-crypto.integration.test.ts diff --git a/packages/stack/integration/shared/match-bloom.integration.test.ts b/languages/typescript/packages/stack/integration/shared/match-bloom.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/match-bloom.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/match-bloom.integration.test.ts diff --git a/packages/stack/integration/shared/matrix-bulk.integration.test.ts b/languages/typescript/packages/stack/integration/shared/matrix-bulk.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/matrix-bulk.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/matrix-bulk.integration.test.ts diff --git a/packages/stack/integration/shared/matrix-crypto.integration.test.ts b/languages/typescript/packages/stack/integration/shared/matrix-crypto.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/matrix-crypto.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/matrix-crypto.integration.test.ts diff --git a/packages/stack/integration/shared/matrix-keyset.integration.test.ts b/languages/typescript/packages/stack/integration/shared/matrix-keyset.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/matrix-keyset.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/matrix-keyset.integration.test.ts diff --git a/packages/stack/integration/shared/matrix-sql.integration.test.ts b/languages/typescript/packages/stack/integration/shared/matrix-sql.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/matrix-sql.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/matrix-sql.integration.test.ts diff --git a/packages/stack/integration/shared/ope-term.integration.test.ts b/languages/typescript/packages/stack/integration/shared/ope-term.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/ope-term.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/ope-term.integration.test.ts diff --git a/packages/stack/integration/shared/schema-pg.integration.test.ts b/languages/typescript/packages/stack/integration/shared/schema-pg.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/schema-pg.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/schema-pg.integration.test.ts diff --git a/packages/stack/integration/shared/schema-v3-client.integration.test.ts b/languages/typescript/packages/stack/integration/shared/schema-v3-client.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/schema-v3-client.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/schema-v3-client.integration.test.ts diff --git a/packages/stack/integration/shared/v2-decrypt-compat.integration.test.ts b/languages/typescript/packages/stack/integration/shared/v2-decrypt-compat.integration.test.ts similarity index 100% rename from packages/stack/integration/shared/v2-decrypt-compat.integration.test.ts rename to languages/typescript/packages/stack/integration/shared/v2-decrypt-compat.integration.test.ts diff --git a/packages/stack/integration/vitest.config.ts b/languages/typescript/packages/stack/integration/vitest.config.ts similarity index 100% rename from packages/stack/integration/vitest.config.ts rename to languages/typescript/packages/stack/integration/vitest.config.ts diff --git a/packages/stack/integration/wasm/adapter.ts b/languages/typescript/packages/stack/integration/wasm/adapter.ts similarity index 100% rename from packages/stack/integration/wasm/adapter.ts rename to languages/typescript/packages/stack/integration/wasm/adapter.ts diff --git a/packages/stack/integration/wasm/families.integration.test.ts b/languages/typescript/packages/stack/integration/wasm/families.integration.test.ts similarity index 100% rename from packages/stack/integration/wasm/families.integration.test.ts rename to languages/typescript/packages/stack/integration/wasm/families.integration.test.ts diff --git a/packages/stack/integration/wasm/v2-decrypt-compat.integration.test.ts b/languages/typescript/packages/stack/integration/wasm/v2-decrypt-compat.integration.test.ts similarity index 100% rename from packages/stack/integration/wasm/v2-decrypt-compat.integration.test.ts rename to languages/typescript/packages/stack/integration/wasm/v2-decrypt-compat.integration.test.ts diff --git a/packages/stack/package.json b/languages/typescript/packages/stack/package.json similarity index 100% rename from packages/stack/package.json rename to languages/typescript/packages/stack/package.json diff --git a/packages/stack/scripts/install-eql-v3.ts b/languages/typescript/packages/stack/scripts/install-eql-v3.ts similarity index 100% rename from packages/stack/scripts/install-eql-v3.ts rename to languages/typescript/packages/stack/scripts/install-eql-v3.ts diff --git a/packages/stack/src/adapter-kit.ts b/languages/typescript/packages/stack/src/adapter-kit.ts similarity index 100% rename from packages/stack/src/adapter-kit.ts rename to languages/typescript/packages/stack/src/adapter-kit.ts diff --git a/packages/stack/src/diagnostics.ts b/languages/typescript/packages/stack/src/diagnostics.ts similarity index 100% rename from packages/stack/src/diagnostics.ts rename to languages/typescript/packages/stack/src/diagnostics.ts diff --git a/packages/stack/src/dynamodb/helpers.ts b/languages/typescript/packages/stack/src/dynamodb/helpers.ts similarity index 100% rename from packages/stack/src/dynamodb/helpers.ts rename to languages/typescript/packages/stack/src/dynamodb/helpers.ts diff --git a/packages/stack/src/dynamodb/index.ts b/languages/typescript/packages/stack/src/dynamodb/index.ts similarity index 100% rename from packages/stack/src/dynamodb/index.ts rename to languages/typescript/packages/stack/src/dynamodb/index.ts diff --git a/packages/stack/src/dynamodb/operations/base-operation.ts b/languages/typescript/packages/stack/src/dynamodb/operations/base-operation.ts similarity index 100% rename from packages/stack/src/dynamodb/operations/base-operation.ts rename to languages/typescript/packages/stack/src/dynamodb/operations/base-operation.ts diff --git a/packages/stack/src/dynamodb/operations/bulk-decrypt-models.ts b/languages/typescript/packages/stack/src/dynamodb/operations/bulk-decrypt-models.ts similarity index 100% rename from packages/stack/src/dynamodb/operations/bulk-decrypt-models.ts rename to languages/typescript/packages/stack/src/dynamodb/operations/bulk-decrypt-models.ts diff --git a/packages/stack/src/dynamodb/operations/bulk-encrypt-models.ts b/languages/typescript/packages/stack/src/dynamodb/operations/bulk-encrypt-models.ts similarity index 100% rename from packages/stack/src/dynamodb/operations/bulk-encrypt-models.ts rename to languages/typescript/packages/stack/src/dynamodb/operations/bulk-encrypt-models.ts diff --git a/packages/stack/src/dynamodb/operations/decrypt-model.ts b/languages/typescript/packages/stack/src/dynamodb/operations/decrypt-model.ts similarity index 100% rename from packages/stack/src/dynamodb/operations/decrypt-model.ts rename to languages/typescript/packages/stack/src/dynamodb/operations/decrypt-model.ts diff --git a/packages/stack/src/dynamodb/operations/encrypt-model.ts b/languages/typescript/packages/stack/src/dynamodb/operations/encrypt-model.ts similarity index 100% rename from packages/stack/src/dynamodb/operations/encrypt-model.ts rename to languages/typescript/packages/stack/src/dynamodb/operations/encrypt-model.ts diff --git a/packages/stack/src/dynamodb/types.ts b/languages/typescript/packages/stack/src/dynamodb/types.ts similarity index 100% rename from packages/stack/src/dynamodb/types.ts rename to languages/typescript/packages/stack/src/dynamodb/types.ts diff --git a/packages/stack/src/encryption/client-v3.ts b/languages/typescript/packages/stack/src/encryption/client-v3.ts similarity index 100% rename from packages/stack/src/encryption/client-v3.ts rename to languages/typescript/packages/stack/src/encryption/client-v3.ts diff --git a/packages/stack/src/encryption/helpers/auth-failure.ts b/languages/typescript/packages/stack/src/encryption/helpers/auth-failure.ts similarity index 100% rename from packages/stack/src/encryption/helpers/auth-failure.ts rename to languages/typescript/packages/stack/src/encryption/helpers/auth-failure.ts diff --git a/packages/stack/src/encryption/helpers/error-code.ts b/languages/typescript/packages/stack/src/encryption/helpers/error-code.ts similarity index 100% rename from packages/stack/src/encryption/helpers/error-code.ts rename to languages/typescript/packages/stack/src/encryption/helpers/error-code.ts diff --git a/packages/stack/src/encryption/helpers/index.ts b/languages/typescript/packages/stack/src/encryption/helpers/index.ts similarity index 100% rename from packages/stack/src/encryption/helpers/index.ts rename to languages/typescript/packages/stack/src/encryption/helpers/index.ts diff --git a/packages/stack/src/encryption/helpers/infer-index-type.ts b/languages/typescript/packages/stack/src/encryption/helpers/infer-index-type.ts similarity index 100% rename from packages/stack/src/encryption/helpers/infer-index-type.ts rename to languages/typescript/packages/stack/src/encryption/helpers/infer-index-type.ts diff --git a/packages/stack/src/encryption/helpers/jsonb.ts b/languages/typescript/packages/stack/src/encryption/helpers/jsonb.ts similarity index 100% rename from packages/stack/src/encryption/helpers/jsonb.ts rename to languages/typescript/packages/stack/src/encryption/helpers/jsonb.ts diff --git a/packages/stack/src/encryption/helpers/model-helpers.ts b/languages/typescript/packages/stack/src/encryption/helpers/model-helpers.ts similarity index 100% rename from packages/stack/src/encryption/helpers/model-helpers.ts rename to languages/typescript/packages/stack/src/encryption/helpers/model-helpers.ts diff --git a/packages/stack/src/encryption/helpers/model-traversal.ts b/languages/typescript/packages/stack/src/encryption/helpers/model-traversal.ts similarity index 100% rename from packages/stack/src/encryption/helpers/model-traversal.ts rename to languages/typescript/packages/stack/src/encryption/helpers/model-traversal.ts diff --git a/packages/stack/src/encryption/helpers/type-guards.ts b/languages/typescript/packages/stack/src/encryption/helpers/type-guards.ts similarity index 100% rename from packages/stack/src/encryption/helpers/type-guards.ts rename to languages/typescript/packages/stack/src/encryption/helpers/type-guards.ts diff --git a/packages/stack/src/encryption/helpers/validation.ts b/languages/typescript/packages/stack/src/encryption/helpers/validation.ts similarity index 100% rename from packages/stack/src/encryption/helpers/validation.ts rename to languages/typescript/packages/stack/src/encryption/helpers/validation.ts diff --git a/packages/stack/src/encryption/index.ts b/languages/typescript/packages/stack/src/encryption/index.ts similarity index 100% rename from packages/stack/src/encryption/index.ts rename to languages/typescript/packages/stack/src/encryption/index.ts diff --git a/packages/stack/src/encryption/operations/base-operation.ts b/languages/typescript/packages/stack/src/encryption/operations/base-operation.ts similarity index 100% rename from packages/stack/src/encryption/operations/base-operation.ts rename to languages/typescript/packages/stack/src/encryption/operations/base-operation.ts diff --git a/packages/stack/src/encryption/operations/batch-encrypt-query.ts b/languages/typescript/packages/stack/src/encryption/operations/batch-encrypt-query.ts similarity index 100% rename from packages/stack/src/encryption/operations/batch-encrypt-query.ts rename to languages/typescript/packages/stack/src/encryption/operations/batch-encrypt-query.ts diff --git a/packages/stack/src/encryption/operations/bulk-decrypt-models.ts b/languages/typescript/packages/stack/src/encryption/operations/bulk-decrypt-models.ts similarity index 100% rename from packages/stack/src/encryption/operations/bulk-decrypt-models.ts rename to languages/typescript/packages/stack/src/encryption/operations/bulk-decrypt-models.ts diff --git a/packages/stack/src/encryption/operations/bulk-decrypt.ts b/languages/typescript/packages/stack/src/encryption/operations/bulk-decrypt.ts similarity index 100% rename from packages/stack/src/encryption/operations/bulk-decrypt.ts rename to languages/typescript/packages/stack/src/encryption/operations/bulk-decrypt.ts diff --git a/packages/stack/src/encryption/operations/bulk-encrypt-models.ts b/languages/typescript/packages/stack/src/encryption/operations/bulk-encrypt-models.ts similarity index 100% rename from packages/stack/src/encryption/operations/bulk-encrypt-models.ts rename to languages/typescript/packages/stack/src/encryption/operations/bulk-encrypt-models.ts diff --git a/packages/stack/src/encryption/operations/bulk-encrypt.ts b/languages/typescript/packages/stack/src/encryption/operations/bulk-encrypt.ts similarity index 100% rename from packages/stack/src/encryption/operations/bulk-encrypt.ts rename to languages/typescript/packages/stack/src/encryption/operations/bulk-encrypt.ts diff --git a/packages/stack/src/encryption/operations/decrypt-model.ts b/languages/typescript/packages/stack/src/encryption/operations/decrypt-model.ts similarity index 100% rename from packages/stack/src/encryption/operations/decrypt-model.ts rename to languages/typescript/packages/stack/src/encryption/operations/decrypt-model.ts diff --git a/packages/stack/src/encryption/operations/decrypt.ts b/languages/typescript/packages/stack/src/encryption/operations/decrypt.ts similarity index 100% rename from packages/stack/src/encryption/operations/decrypt.ts rename to languages/typescript/packages/stack/src/encryption/operations/decrypt.ts diff --git a/packages/stack/src/encryption/operations/encrypt-model.ts b/languages/typescript/packages/stack/src/encryption/operations/encrypt-model.ts similarity index 100% rename from packages/stack/src/encryption/operations/encrypt-model.ts rename to languages/typescript/packages/stack/src/encryption/operations/encrypt-model.ts diff --git a/packages/stack/src/encryption/operations/encrypt-query.ts b/languages/typescript/packages/stack/src/encryption/operations/encrypt-query.ts similarity index 100% rename from packages/stack/src/encryption/operations/encrypt-query.ts rename to languages/typescript/packages/stack/src/encryption/operations/encrypt-query.ts diff --git a/packages/stack/src/encryption/operations/encrypt.ts b/languages/typescript/packages/stack/src/encryption/operations/encrypt.ts similarity index 100% rename from packages/stack/src/encryption/operations/encrypt.ts rename to languages/typescript/packages/stack/src/encryption/operations/encrypt.ts diff --git a/packages/stack/src/encryption/operations/mapped-decrypt.ts b/languages/typescript/packages/stack/src/encryption/operations/mapped-decrypt.ts similarity index 100% rename from packages/stack/src/encryption/operations/mapped-decrypt.ts rename to languages/typescript/packages/stack/src/encryption/operations/mapped-decrypt.ts diff --git a/packages/stack/src/encryption/v3.ts b/languages/typescript/packages/stack/src/encryption/v3.ts similarity index 100% rename from packages/stack/src/encryption/v3.ts rename to languages/typescript/packages/stack/src/encryption/v3.ts diff --git a/packages/stack/src/eql/v3/columns.ts b/languages/typescript/packages/stack/src/eql/v3/columns.ts similarity index 100% rename from packages/stack/src/eql/v3/columns.ts rename to languages/typescript/packages/stack/src/eql/v3/columns.ts diff --git a/packages/stack/src/eql/v3/date-reconstruction.ts b/languages/typescript/packages/stack/src/eql/v3/date-reconstruction.ts similarity index 100% rename from packages/stack/src/eql/v3/date-reconstruction.ts rename to languages/typescript/packages/stack/src/eql/v3/date-reconstruction.ts diff --git a/packages/stack/src/eql/v3/domain-registry.ts b/languages/typescript/packages/stack/src/eql/v3/domain-registry.ts similarity index 100% rename from packages/stack/src/eql/v3/domain-registry.ts rename to languages/typescript/packages/stack/src/eql/v3/domain-registry.ts diff --git a/packages/stack/src/eql/v3/index.ts b/languages/typescript/packages/stack/src/eql/v3/index.ts similarity index 100% rename from packages/stack/src/eql/v3/index.ts rename to languages/typescript/packages/stack/src/eql/v3/index.ts diff --git a/packages/stack/src/eql/v3/selector-path.ts b/languages/typescript/packages/stack/src/eql/v3/selector-path.ts similarity index 100% rename from packages/stack/src/eql/v3/selector-path.ts rename to languages/typescript/packages/stack/src/eql/v3/selector-path.ts diff --git a/packages/stack/src/eql/v3/table.ts b/languages/typescript/packages/stack/src/eql/v3/table.ts similarity index 100% rename from packages/stack/src/eql/v3/table.ts rename to languages/typescript/packages/stack/src/eql/v3/table.ts diff --git a/packages/stack/src/eql/v3/types.ts b/languages/typescript/packages/stack/src/eql/v3/types.ts similarity index 100% rename from packages/stack/src/eql/v3/types.ts rename to languages/typescript/packages/stack/src/eql/v3/types.ts diff --git a/packages/stack/src/errors/index.ts b/languages/typescript/packages/stack/src/errors/index.ts similarity index 100% rename from packages/stack/src/errors/index.ts rename to languages/typescript/packages/stack/src/errors/index.ts diff --git a/packages/stack/src/identity/index.ts b/languages/typescript/packages/stack/src/identity/index.ts similarity index 100% rename from packages/stack/src/identity/index.ts rename to languages/typescript/packages/stack/src/identity/index.ts diff --git a/packages/stack/src/index.ts b/languages/typescript/packages/stack/src/index.ts similarity index 100% rename from packages/stack/src/index.ts rename to languages/typescript/packages/stack/src/index.ts diff --git a/packages/stack/src/schema/index.ts b/languages/typescript/packages/stack/src/schema/index.ts similarity index 100% rename from packages/stack/src/schema/index.ts rename to languages/typescript/packages/stack/src/schema/index.ts diff --git a/packages/stack/src/schema/internal.ts b/languages/typescript/packages/stack/src/schema/internal.ts similarity index 100% rename from packages/stack/src/schema/internal.ts rename to languages/typescript/packages/stack/src/schema/internal.ts diff --git a/packages/stack/src/schema/match-defaults.ts b/languages/typescript/packages/stack/src/schema/match-defaults.ts similarity index 100% rename from packages/stack/src/schema/match-defaults.ts rename to languages/typescript/packages/stack/src/schema/match-defaults.ts diff --git a/packages/stack/src/types-public.ts b/languages/typescript/packages/stack/src/types-public.ts similarity index 100% rename from packages/stack/src/types-public.ts rename to languages/typescript/packages/stack/src/types-public.ts diff --git a/packages/stack/src/types.ts b/languages/typescript/packages/stack/src/types.ts similarity index 100% rename from packages/stack/src/types.ts rename to languages/typescript/packages/stack/src/types.ts diff --git a/packages/stack/src/utils/config/index.ts b/languages/typescript/packages/stack/src/utils/config/index.ts similarity index 100% rename from packages/stack/src/utils/config/index.ts rename to languages/typescript/packages/stack/src/utils/config/index.ts diff --git a/packages/stack/src/utils/logger/index.ts b/languages/typescript/packages/stack/src/utils/logger/index.ts similarity index 100% rename from packages/stack/src/utils/logger/index.ts rename to languages/typescript/packages/stack/src/utils/logger/index.ts diff --git a/packages/stack/src/wasm-inline.ts b/languages/typescript/packages/stack/src/wasm-inline.ts similarity index 100% rename from packages/stack/src/wasm-inline.ts rename to languages/typescript/packages/stack/src/wasm-inline.ts diff --git a/packages/stack/tsconfig.json b/languages/typescript/packages/stack/tsconfig.json similarity index 100% rename from packages/stack/tsconfig.json rename to languages/typescript/packages/stack/tsconfig.json diff --git a/packages/stack/tsconfig.typecheck.json b/languages/typescript/packages/stack/tsconfig.typecheck.json similarity index 100% rename from packages/stack/tsconfig.typecheck.json rename to languages/typescript/packages/stack/tsconfig.typecheck.json diff --git a/packages/stack/tsup.config.ts b/languages/typescript/packages/stack/tsup.config.ts similarity index 100% rename from packages/stack/tsup.config.ts rename to languages/typescript/packages/stack/tsup.config.ts diff --git a/packages/stack/turbo.json b/languages/typescript/packages/stack/turbo.json similarity index 100% rename from packages/stack/turbo.json rename to languages/typescript/packages/stack/turbo.json diff --git a/packages/stack/vitest.config.ts b/languages/typescript/packages/stack/vitest.config.ts similarity index 100% rename from packages/stack/vitest.config.ts rename to languages/typescript/packages/stack/vitest.config.ts diff --git a/packages/stack/vitest.wasm-core.config.ts b/languages/typescript/packages/stack/vitest.wasm-core.config.ts similarity index 100% rename from packages/stack/vitest.wasm-core.config.ts rename to languages/typescript/packages/stack/vitest.wasm-core.config.ts diff --git a/packages/test-kit/CHANGELOG.md b/languages/typescript/packages/test-kit/CHANGELOG.md similarity index 100% rename from packages/test-kit/CHANGELOG.md rename to languages/typescript/packages/test-kit/CHANGELOG.md diff --git a/packages/test-kit/package.json b/languages/typescript/packages/test-kit/package.json similarity index 100% rename from packages/test-kit/package.json rename to languages/typescript/packages/test-kit/package.json diff --git a/packages/test-kit/src/__tests__/install.test.ts b/languages/typescript/packages/test-kit/src/__tests__/install.test.ts similarity index 100% rename from packages/test-kit/src/__tests__/install.test.ts rename to languages/typescript/packages/test-kit/src/__tests__/install.test.ts diff --git a/packages/test-kit/src/adapter.ts b/languages/typescript/packages/test-kit/src/adapter.ts similarity index 100% rename from packages/test-kit/src/adapter.ts rename to languages/typescript/packages/test-kit/src/adapter.ts diff --git a/packages/test-kit/src/catalog.ts b/languages/typescript/packages/test-kit/src/catalog.ts similarity index 100% rename from packages/test-kit/src/catalog.ts rename to languages/typescript/packages/test-kit/src/catalog.ts diff --git a/packages/test-kit/src/env.ts b/languages/typescript/packages/test-kit/src/env.ts similarity index 100% rename from packages/test-kit/src/env.ts rename to languages/typescript/packages/test-kit/src/env.ts diff --git a/packages/test-kit/src/families.ts b/languages/typescript/packages/test-kit/src/families.ts similarity index 100% rename from packages/test-kit/src/families.ts rename to languages/typescript/packages/test-kit/src/families.ts diff --git a/packages/test-kit/src/index.ts b/languages/typescript/packages/test-kit/src/index.ts similarity index 100% rename from packages/test-kit/src/index.ts rename to languages/typescript/packages/test-kit/src/index.ts diff --git a/packages/test-kit/src/install.ts b/languages/typescript/packages/test-kit/src/install.ts similarity index 100% rename from packages/test-kit/src/install.ts rename to languages/typescript/packages/test-kit/src/install.ts diff --git a/packages/test-kit/src/integration/clerk.ts b/languages/typescript/packages/test-kit/src/integration/clerk.ts similarity index 100% rename from packages/test-kit/src/integration/clerk.ts rename to languages/typescript/packages/test-kit/src/integration/clerk.ts diff --git a/packages/test-kit/src/integration/config.ts b/languages/typescript/packages/test-kit/src/integration/config.ts similarity index 100% rename from packages/test-kit/src/integration/config.ts rename to languages/typescript/packages/test-kit/src/integration/config.ts diff --git a/packages/test-kit/src/integration/global-setup.ts b/languages/typescript/packages/test-kit/src/integration/global-setup.ts similarity index 100% rename from packages/test-kit/src/integration/global-setup.ts rename to languages/typescript/packages/test-kit/src/integration/global-setup.ts diff --git a/packages/test-kit/src/integration/no-skips-reporter.ts b/languages/typescript/packages/test-kit/src/integration/no-skips-reporter.ts similarity index 100% rename from packages/test-kit/src/integration/no-skips-reporter.ts rename to languages/typescript/packages/test-kit/src/integration/no-skips-reporter.ts diff --git a/packages/test-kit/src/json-adapter.ts b/languages/typescript/packages/test-kit/src/json-adapter.ts similarity index 100% rename from packages/test-kit/src/json-adapter.ts rename to languages/typescript/packages/test-kit/src/json-adapter.ts diff --git a/packages/test-kit/src/needle-for.ts b/languages/typescript/packages/test-kit/src/needle-for.ts similarity index 100% rename from packages/test-kit/src/needle-for.ts rename to languages/typescript/packages/test-kit/src/needle-for.ts diff --git a/packages/test-kit/src/ops.ts b/languages/typescript/packages/test-kit/src/ops.ts similarity index 100% rename from packages/test-kit/src/ops.ts rename to languages/typescript/packages/test-kit/src/ops.ts diff --git a/packages/test-kit/src/oracle.ts b/languages/typescript/packages/test-kit/src/oracle.ts similarity index 100% rename from packages/test-kit/src/oracle.ts rename to languages/typescript/packages/test-kit/src/oracle.ts diff --git a/packages/test-kit/src/results.ts b/languages/typescript/packages/test-kit/src/results.ts similarity index 100% rename from packages/test-kit/src/results.ts rename to languages/typescript/packages/test-kit/src/results.ts diff --git a/packages/test-kit/src/rows.ts b/languages/typescript/packages/test-kit/src/rows.ts similarity index 100% rename from packages/test-kit/src/rows.ts rename to languages/typescript/packages/test-kit/src/rows.ts diff --git a/packages/test-kit/src/run-family-suite.ts b/languages/typescript/packages/test-kit/src/run-family-suite.ts similarity index 100% rename from packages/test-kit/src/run-family-suite.ts rename to languages/typescript/packages/test-kit/src/run-family-suite.ts diff --git a/packages/test-kit/src/run-json-suite.ts b/languages/typescript/packages/test-kit/src/run-json-suite.ts similarity index 100% rename from packages/test-kit/src/run-json-suite.ts rename to languages/typescript/packages/test-kit/src/run-json-suite.ts diff --git a/packages/test-kit/src/v2-fixtures.ts b/languages/typescript/packages/test-kit/src/v2-fixtures.ts similarity index 100% rename from packages/test-kit/src/v2-fixtures.ts rename to languages/typescript/packages/test-kit/src/v2-fixtures.ts diff --git a/packages/test-kit/tsconfig.json b/languages/typescript/packages/test-kit/tsconfig.json similarity index 100% rename from packages/test-kit/tsconfig.json rename to languages/typescript/packages/test-kit/tsconfig.json diff --git a/packages/utils/config/index.ts b/languages/typescript/packages/utils/config/index.ts similarity index 100% rename from packages/utils/config/index.ts rename to languages/typescript/packages/utils/config/index.ts diff --git a/packages/utils/logger/index.ts b/languages/typescript/packages/utils/logger/index.ts similarity index 100% rename from packages/utils/logger/index.ts rename to languages/typescript/packages/utils/logger/index.ts diff --git a/packages/wizard/CHANGELOG.md b/languages/typescript/packages/wizard/CHANGELOG.md similarity index 100% rename from packages/wizard/CHANGELOG.md rename to languages/typescript/packages/wizard/CHANGELOG.md diff --git a/packages/wizard/README.md b/languages/typescript/packages/wizard/README.md similarity index 100% rename from packages/wizard/README.md rename to languages/typescript/packages/wizard/README.md diff --git a/packages/wizard/package.json b/languages/typescript/packages/wizard/package.json similarity index 100% rename from packages/wizard/package.json rename to languages/typescript/packages/wizard/package.json diff --git a/packages/wizard/src/__tests__/agent-sdk.test.ts b/languages/typescript/packages/wizard/src/__tests__/agent-sdk.test.ts similarity index 100% rename from packages/wizard/src/__tests__/agent-sdk.test.ts rename to languages/typescript/packages/wizard/src/__tests__/agent-sdk.test.ts diff --git a/packages/wizard/src/__tests__/commandments.test.ts b/languages/typescript/packages/wizard/src/__tests__/commandments.test.ts similarity index 100% rename from packages/wizard/src/__tests__/commandments.test.ts rename to languages/typescript/packages/wizard/src/__tests__/commandments.test.ts diff --git a/packages/wizard/src/__tests__/detect.test.ts b/languages/typescript/packages/wizard/src/__tests__/detect.test.ts similarity index 100% rename from packages/wizard/src/__tests__/detect.test.ts rename to languages/typescript/packages/wizard/src/__tests__/detect.test.ts diff --git a/packages/wizard/src/__tests__/errors-runner.test.ts b/languages/typescript/packages/wizard/src/__tests__/errors-runner.test.ts similarity index 100% rename from packages/wizard/src/__tests__/errors-runner.test.ts rename to languages/typescript/packages/wizard/src/__tests__/errors-runner.test.ts diff --git a/packages/wizard/src/__tests__/format.test.ts b/languages/typescript/packages/wizard/src/__tests__/format.test.ts similarity index 100% rename from packages/wizard/src/__tests__/format.test.ts rename to languages/typescript/packages/wizard/src/__tests__/format.test.ts diff --git a/packages/wizard/src/__tests__/gateway-messages.test.ts b/languages/typescript/packages/wizard/src/__tests__/gateway-messages.test.ts similarity index 100% rename from packages/wizard/src/__tests__/gateway-messages.test.ts rename to languages/typescript/packages/wizard/src/__tests__/gateway-messages.test.ts diff --git a/packages/wizard/src/__tests__/health-checks.test.ts b/languages/typescript/packages/wizard/src/__tests__/health-checks.test.ts similarity index 100% rename from packages/wizard/src/__tests__/health-checks.test.ts rename to languages/typescript/packages/wizard/src/__tests__/health-checks.test.ts diff --git a/packages/wizard/src/__tests__/hooks.test.ts b/languages/typescript/packages/wizard/src/__tests__/hooks.test.ts similarity index 100% rename from packages/wizard/src/__tests__/hooks.test.ts rename to languages/typescript/packages/wizard/src/__tests__/hooks.test.ts diff --git a/packages/wizard/src/__tests__/install-skills.test.ts b/languages/typescript/packages/wizard/src/__tests__/install-skills.test.ts similarity index 100% rename from packages/wizard/src/__tests__/install-skills.test.ts rename to languages/typescript/packages/wizard/src/__tests__/install-skills.test.ts diff --git a/packages/wizard/src/__tests__/interface.test.ts b/languages/typescript/packages/wizard/src/__tests__/interface.test.ts similarity index 100% rename from packages/wizard/src/__tests__/interface.test.ts rename to languages/typescript/packages/wizard/src/__tests__/interface.test.ts diff --git a/packages/wizard/src/__tests__/parse-args.test.ts b/languages/typescript/packages/wizard/src/__tests__/parse-args.test.ts similarity index 100% rename from packages/wizard/src/__tests__/parse-args.test.ts rename to languages/typescript/packages/wizard/src/__tests__/parse-args.test.ts diff --git a/packages/wizard/src/__tests__/post-agent.test.ts b/languages/typescript/packages/wizard/src/__tests__/post-agent.test.ts similarity index 100% rename from packages/wizard/src/__tests__/post-agent.test.ts rename to languages/typescript/packages/wizard/src/__tests__/post-agent.test.ts diff --git a/packages/wizard/src/__tests__/prerequisites.test.ts b/languages/typescript/packages/wizard/src/__tests__/prerequisites.test.ts similarity index 100% rename from packages/wizard/src/__tests__/prerequisites.test.ts rename to languages/typescript/packages/wizard/src/__tests__/prerequisites.test.ts diff --git a/packages/wizard/src/__tests__/rewrite-migrations.test.ts b/languages/typescript/packages/wizard/src/__tests__/rewrite-migrations.test.ts similarity index 100% rename from packages/wizard/src/__tests__/rewrite-migrations.test.ts rename to languages/typescript/packages/wizard/src/__tests__/rewrite-migrations.test.ts diff --git a/packages/wizard/src/__tests__/wizard-tools.test.ts b/languages/typescript/packages/wizard/src/__tests__/wizard-tools.test.ts similarity index 100% rename from packages/wizard/src/__tests__/wizard-tools.test.ts rename to languages/typescript/packages/wizard/src/__tests__/wizard-tools.test.ts diff --git a/packages/wizard/src/agent/__tests__/interface.test.ts b/languages/typescript/packages/wizard/src/agent/__tests__/interface.test.ts similarity index 100% rename from packages/wizard/src/agent/__tests__/interface.test.ts rename to languages/typescript/packages/wizard/src/agent/__tests__/interface.test.ts diff --git a/packages/wizard/src/agent/commandments.ts b/languages/typescript/packages/wizard/src/agent/commandments.ts similarity index 100% rename from packages/wizard/src/agent/commandments.ts rename to languages/typescript/packages/wizard/src/agent/commandments.ts diff --git a/packages/wizard/src/agent/errors.ts b/languages/typescript/packages/wizard/src/agent/errors.ts similarity index 100% rename from packages/wizard/src/agent/errors.ts rename to languages/typescript/packages/wizard/src/agent/errors.ts diff --git a/packages/wizard/src/agent/fetch-prompt.ts b/languages/typescript/packages/wizard/src/agent/fetch-prompt.ts similarity index 100% rename from packages/wizard/src/agent/fetch-prompt.ts rename to languages/typescript/packages/wizard/src/agent/fetch-prompt.ts diff --git a/packages/wizard/src/agent/hooks.ts b/languages/typescript/packages/wizard/src/agent/hooks.ts similarity index 100% rename from packages/wizard/src/agent/hooks.ts rename to languages/typescript/packages/wizard/src/agent/hooks.ts diff --git a/packages/wizard/src/agent/interface.ts b/languages/typescript/packages/wizard/src/agent/interface.ts similarity index 100% rename from packages/wizard/src/agent/interface.ts rename to languages/typescript/packages/wizard/src/agent/interface.ts diff --git a/packages/wizard/src/bin/parse-args.ts b/languages/typescript/packages/wizard/src/bin/parse-args.ts similarity index 100% rename from packages/wizard/src/bin/parse-args.ts rename to languages/typescript/packages/wizard/src/bin/parse-args.ts diff --git a/packages/wizard/src/bin/wizard.ts b/languages/typescript/packages/wizard/src/bin/wizard.ts similarity index 100% rename from packages/wizard/src/bin/wizard.ts rename to languages/typescript/packages/wizard/src/bin/wizard.ts diff --git a/packages/wizard/src/health-checks/index.ts b/languages/typescript/packages/wizard/src/health-checks/index.ts similarity index 100% rename from packages/wizard/src/health-checks/index.ts rename to languages/typescript/packages/wizard/src/health-checks/index.ts diff --git a/packages/wizard/src/lib/analytics.ts b/languages/typescript/packages/wizard/src/lib/analytics.ts similarity index 100% rename from packages/wizard/src/lib/analytics.ts rename to languages/typescript/packages/wizard/src/lib/analytics.ts diff --git a/packages/wizard/src/lib/changelog.ts b/languages/typescript/packages/wizard/src/lib/changelog.ts similarity index 100% rename from packages/wizard/src/lib/changelog.ts rename to languages/typescript/packages/wizard/src/lib/changelog.ts diff --git a/packages/wizard/src/lib/constants.ts b/languages/typescript/packages/wizard/src/lib/constants.ts similarity index 100% rename from packages/wizard/src/lib/constants.ts rename to languages/typescript/packages/wizard/src/lib/constants.ts diff --git a/packages/wizard/src/lib/detect.ts b/languages/typescript/packages/wizard/src/lib/detect.ts similarity index 100% rename from packages/wizard/src/lib/detect.ts rename to languages/typescript/packages/wizard/src/lib/detect.ts diff --git a/packages/wizard/src/lib/format.ts b/languages/typescript/packages/wizard/src/lib/format.ts similarity index 100% rename from packages/wizard/src/lib/format.ts rename to languages/typescript/packages/wizard/src/lib/format.ts diff --git a/packages/wizard/src/lib/gather.ts b/languages/typescript/packages/wizard/src/lib/gather.ts similarity index 100% rename from packages/wizard/src/lib/gather.ts rename to languages/typescript/packages/wizard/src/lib/gather.ts diff --git a/packages/wizard/src/lib/install-skills.ts b/languages/typescript/packages/wizard/src/lib/install-skills.ts similarity index 100% rename from packages/wizard/src/lib/install-skills.ts rename to languages/typescript/packages/wizard/src/lib/install-skills.ts diff --git a/packages/wizard/src/lib/post-agent.ts b/languages/typescript/packages/wizard/src/lib/post-agent.ts similarity index 100% rename from packages/wizard/src/lib/post-agent.ts rename to languages/typescript/packages/wizard/src/lib/post-agent.ts diff --git a/packages/wizard/src/lib/prerequisites.ts b/languages/typescript/packages/wizard/src/lib/prerequisites.ts similarity index 100% rename from packages/wizard/src/lib/prerequisites.ts rename to languages/typescript/packages/wizard/src/lib/prerequisites.ts diff --git a/packages/wizard/src/lib/rewrite-migrations.ts b/languages/typescript/packages/wizard/src/lib/rewrite-migrations.ts similarity index 100% rename from packages/wizard/src/lib/rewrite-migrations.ts rename to languages/typescript/packages/wizard/src/lib/rewrite-migrations.ts diff --git a/packages/wizard/src/lib/types.ts b/languages/typescript/packages/wizard/src/lib/types.ts similarity index 100% rename from packages/wizard/src/lib/types.ts rename to languages/typescript/packages/wizard/src/lib/types.ts diff --git a/packages/wizard/src/lib/wire-call-sites.ts b/languages/typescript/packages/wizard/src/lib/wire-call-sites.ts similarity index 100% rename from packages/wizard/src/lib/wire-call-sites.ts rename to languages/typescript/packages/wizard/src/lib/wire-call-sites.ts diff --git a/packages/wizard/src/run.ts b/languages/typescript/packages/wizard/src/run.ts similarity index 100% rename from packages/wizard/src/run.ts rename to languages/typescript/packages/wizard/src/run.ts diff --git a/packages/wizard/src/tools/wizard-tools.ts b/languages/typescript/packages/wizard/src/tools/wizard-tools.ts similarity index 100% rename from packages/wizard/src/tools/wizard-tools.ts rename to languages/typescript/packages/wizard/src/tools/wizard-tools.ts diff --git a/packages/wizard/tsconfig.json b/languages/typescript/packages/wizard/tsconfig.json similarity index 100% rename from packages/wizard/tsconfig.json rename to languages/typescript/packages/wizard/tsconfig.json diff --git a/packages/wizard/tsup.config.ts b/languages/typescript/packages/wizard/tsup.config.ts similarity index 100% rename from packages/wizard/tsup.config.ts rename to languages/typescript/packages/wizard/tsup.config.ts From 61960da45918296a23a463f3e8b9ad5525c27beb Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 17:45:34 +1000 Subject: [PATCH 2/9] refactor: rewrite root-relative paths for languages/typescript Mechanical rewrite of every root-relative reference to a moved package or to examples/: workflows, the build-ffi-binding action, Dependabot, scripts, turbo.json, biome.json, vitest.shared.ts, .gitignore, e2e/, skills/, the agent guides and current docs, each package's own files (including repository.directory in every published manifest), and the importer keys and link: paths in pnpm-lock.yaml. The lock change is path-only. pnpm then puts the importers in its own order, which moves the packages/eql/packages/eql block; regenerating the lock changes no version. Left alone because they record history: docs/plans/, docs/superpowers/, every CHANGELOG.md and pending .changeset/*.md files, as scripts/lint-no-dead-package-paths.mjs already requires. This commit is generated, then formatted with biome format. Relative paths that climb out of a moved package, bare-string package roots in the linters, and prose follow in separate commits. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- .github/actions/build-ffi-binding/action.yml | 42 ++++----- .github/dependabot.yml | 6 +- .github/workflows/_build-ffi-artifacts.yml | 22 ++--- .github/workflows/fta-v3.yml | 20 ++--- .github/workflows/integration-drizzle.yml | 80 ++++++++--------- .github/workflows/integration-prisma-next.yml | 48 +++++------ .github/workflows/integration-protect-ffi.yml | 56 ++++++------ .github/workflows/integration-supabase.yml | 68 +++++++-------- .../workflows/prisma-example-readme-e2e.yml | 36 ++++---- .github/workflows/prisma-next-e2e.yml | 54 ++++++------ .github/workflows/release.yml | 2 +- .github/workflows/test-eql.yml | 2 +- .github/workflows/tests-bench.yml | 28 +++--- .github/workflows/tests-rust.yml | 22 ++--- .github/workflows/tests.yml | 64 +++++++------- .gitignore | 20 ++--- AGENTS.md | 84 +++++++++--------- CLAUDE.md | 6 +- CONTRIBUTING.md | 4 +- README.md | 2 +- biome.json | 8 +- docs/agents/issue-tracker.md | 2 +- docs/eql-v3-ord-term-ordering-defect.md | 2 +- docs/query-api-walkthrough.md | 4 +- e2e/README.md | 2 +- e2e/tests/package-managers.e2e.test.ts | 15 +++- e2e/tests/prisma-example-readme.e2e.test.ts | 6 +- e2e/tests/supply-chain.e2e.test.ts | 10 +-- e2e/wasm/deno.json | 4 +- languages/typescript/examples/basic/README.md | 2 +- .../examples/prisma/test/e2e/README.md | 2 +- .../examples/prisma/test/e2e/global-setup.ts | 4 +- .../drizzle/operators.explain.test.ts | 2 +- .../packages/bench/vitest.config.ts | 2 +- languages/typescript/packages/cli/AGENTS.md | 10 +-- .../typescript/packages/cli/package.json | 2 +- .../packages/cli/scripts/e2e-encrypt.sh | 2 +- .../cli/src/__tests__/installer.test.ts | 2 +- .../module-error-classification.test.ts | 4 +- .../src/__tests__/rewrite-migrations.test.ts | 2 +- .../typescript/packages/cli/src/bin/main.ts | 2 +- .../cli/src/commands/db/rewrite-migrations.ts | 2 +- .../commands/eql/__tests__/validate.test.ts | 2 +- .../packages/cli/src/commands/eql/validate.ts | 2 +- .../init/__tests__/utils-codegen.test.ts | 2 +- .../init/lib/__tests__/introspect.test.ts | 4 +- .../init/lib/__tests__/setup-prompt.test.ts | 2 +- .../src/commands/init/lib/bundled-paths.ts | 2 +- .../cli/src/commands/init/lib/introspect.ts | 2 +- .../cli/src/commands/init/lib/setup-prompt.ts | 2 +- .../installer/__tests__/bundle-digest.test.ts | 2 +- .../cli/src/installer/bundle-digest.ts | 2 +- .../packages/cli/src/installer/grants.ts | 2 +- .../typescript/packages/cli/src/messages.ts | 2 +- .../packages/cli/src/release-train.ts | 2 +- .../e2e/doctor-missing-binary.e2e.test.ts | 2 +- .../packages/cli/tsconfig.scaffold.json | 2 +- .../typescript/packages/cli/tsup.config.ts | 2 +- .../typescript/packages/cli/vitest.config.ts | 8 +- .../typescript/packages/migrate/package.json | 2 +- .../typescript/packages/nextjs/package.json | 2 +- .../packages/protect-ffi/.gitignore | 2 +- .../typescript/packages/protect-ffi/README.md | 2 +- .../typescript/packages/protect-ffi/mise.toml | 4 +- .../platforms/darwin-arm64/package.json | 2 +- .../platforms/darwin-x64/package.json | 2 +- .../platforms/linux-arm64-gnu/package.json | 2 +- .../platforms/linux-x64-gnu/package.json | 2 +- .../platforms/linux-x64-musl/package.json | 2 +- .../platforms/win32-x64-msvc/package.json | 2 +- .../protect-ffi/scripts/inline-wasm.mjs | 2 +- .../src/integrationSuiteCi.test.ts | 10 +-- .../protect-ffi/src/lintWiring.test.ts | 16 ++-- .../protect-ffi/src/nativeLoading.test.ts | 20 ++--- .../stack-drizzle/__tests__/operators.test.ts | 2 +- .../packages/stack-drizzle/package.json | 2 +- .../packages/stack-prisma/DEVELOPING.md | 4 +- .../packages/stack-prisma/README.md | 4 +- .../packages/stack-prisma/package.json | 2 +- .../src/migration/eql-bundle-v3.ts | 2 +- .../stack-prisma/src/v3/operators-v3.ts | 2 +- .../test/live/helpers/live-gate.ts | 4 +- .../v3/operator-lowering-v3-equality.test.ts | 2 +- .../test/v3/operator-lowering-v3-json.test.ts | 2 +- .../operator-lowering-v3-order-range.test.ts | 2 +- .../test/v3/stale-vendored-space.test.ts | 12 +-- .../test/v3/vendored-space-parity.test.ts | 4 +- .../packages/stack-prisma/tsconfig.json | 4 +- .../browser-export-condition.test.ts | 2 +- .../__tests__/helpers/supabase-mock.ts | 2 +- .../__tests__/supabase-schema-builder.test.ts | 2 +- .../__tests__/supabase-wasm-config.test-d.ts | 6 +- .../__tests__/wasm-entry-edge-safety.test.ts | 10 +-- .../integration/grants.integration.test.ts | 2 +- .../packages/stack-supabase/package.json | 2 +- .../packages/stack-supabase/src/column-map.ts | 12 +-- .../packages/stack-supabase/src/index.ts | 2 +- .../packages/stack-supabase/src/introspect.ts | 2 +- .../stack-supabase/src/wasm-inline.ts | 2 +- .../packages/stack-supabase/turbo.json | 2 +- languages/typescript/packages/stack/README.md | 2 +- .../auth-failure-propagation.test.ts | 2 +- .../stack/__tests__/cjs-require.test.ts | 4 +- .../stack/__tests__/diagnostics-entry.test.ts | 4 +- .../stack/__tests__/encrypt-query.test.ts | 4 +- .../__tests__/helpers/process-free-realm.mjs | 2 +- .../__tests__/logger-edge-safety.test.ts | 8 +- .../stack/__tests__/readme-sync.test.ts | 4 +- .../wasm-inline-bundle-isolation.test.ts | 2 +- ...sm-inline-core-credential-contract.test.ts | 4 +- .../stack/__tests__/wasm-inline-v3.test.ts | 2 +- .../dist-types/wasm-inline-type-identity.ts | 6 +- .../stack/integration/vitest.config.ts | 2 +- .../stack/integration/wasm/adapter.ts | 2 +- .../typescript/packages/stack/package.json | 2 +- .../packages/stack/scripts/install-eql-v3.ts | 2 +- .../packages/stack/src/adapter-kit.ts | 2 +- .../typescript/packages/stack/tsconfig.json | 2 +- .../packages/stack/vitest.config.ts | 2 +- .../packages/stack/vitest.wasm-core.config.ts | 6 +- .../packages/test-kit/src/install.ts | 7 +- .../packages/test-kit/tsconfig.json | 2 +- .../typescript/packages/wizard/package.json | 2 +- .../src/__tests__/install-skills.test.ts | 2 +- .../wizard/src/__tests__/post-agent.test.ts | 2 +- .../src/__tests__/rewrite-migrations.test.ts | 2 +- .../packages/wizard/src/agent/interface.ts | 2 +- .../packages/wizard/src/lib/post-agent.ts | 2 +- .../wizard/src/lib/rewrite-migrations.ts | 6 +- .../typescript/packages/wizard/tsconfig.json | 4 +- package.json | 8 +- packages/eql/AGENTS.md | 2 +- pnpm-lock.yaml | 86 +++++++++---------- pnpm-workspace.yaml | 20 ++--- .../bench-index-expressions.test.mjs | 6 +- .../__tests__/cargo-lock-freshness.test.mjs | 8 +- .../__tests__/cargo-publish-opt-out.test.mjs | 6 +- scripts/__tests__/cli-vitest-alias.test.mjs | 8 +- .../eql-sql-asset-freshness.test.mjs | 2 +- scripts/__tests__/eql-suite-ci.test.mjs | 8 +- scripts/__tests__/ffi-binding-action.test.mjs | 16 ++-- .../__tests__/ffi-binding-step-order.test.mjs | 10 +-- scripts/__tests__/ffi-release-matrix.test.mjs | 6 +- .../__tests__/ffi-repository-urls.test.mjs | 6 +- .../frozen-publisher-runtime-pins.test.mjs | 4 +- .../integration-workflow-paths.test.mjs | 18 ++-- scripts/__tests__/lib/package-readmes.mjs | 6 +- scripts/__tests__/lib/workflows.mjs | 2 +- .../lint-no-dead-package-paths.test.mjs | 8 +- .../lint-no-eql-registry-pins.test.mjs | 30 ++++--- .../__tests__/neon-dist-crate-name.test.mjs | 5 +- .../__tests__/no-parked-changesets.test.mjs | 2 +- .../no-removed-drizzle-surface.test.mjs | 14 +-- .../no-removed-eql-version-flag.test.mjs | 8 +- scripts/__tests__/release-gate.test.mjs | 18 ++-- .../rewriter-copies-in-sync.test.mjs | 8 +- .../skills-retired-package-scopes.test.mjs | 2 +- ...s-select-star-not-a-read-backstop.test.mjs | 14 +-- .../supabase-runtime-claims.test.mjs | 20 ++--- .../__tests__/sync-lockstep-versions.test.mjs | 16 ++-- .../__tests__/turbo-skills-inputs.test.mjs | 2 +- .../wasm-build-inputs-paths-filter.test.mjs | 16 ++-- .../__tests__/wasm-core-contract-ci.test.mjs | 46 ++++++---- .../__tests__/workflow-mise-setup.test.mjs | 2 +- .../workflow-trigger-comments.test.mjs | 12 +-- scripts/ffi-release-matrix.mjs | 5 +- scripts/lint-no-dead-package-paths.mjs | 10 +-- scripts/lint-no-eql-registry-pins.mjs | 18 ++-- scripts/lint-no-hardcoded-runners.mjs | 8 +- scripts/lint-no-workflow-caching.mjs | 4 +- scripts/lint-typecheck-scope.mjs | 12 +-- scripts/release-gate.mjs | 8 +- scripts/sync-lockstep-versions.mjs | 8 +- skills/stash-edge/SKILL.md | 4 +- skills/stash-supply-chain-security/SKILL.md | 4 +- turbo.json | 8 +- vitest.shared.ts | 54 ++++++------ 177 files changed, 852 insertions(+), 796 deletions(-) diff --git a/.github/actions/build-ffi-binding/action.yml b/.github/actions/build-ffi-binding/action.yml index bee2c7228..02e3be6d3 100644 --- a/.github/actions/build-ffi-binding/action.yml +++ b/.github/actions/build-ffi-binding/action.yml @@ -1,6 +1,6 @@ name: Build the protect-ffi binding description: >- - Compile `packages/protect-ffi` into the artifacts its JS consumers load at + Compile `languages/typescript/packages/protect-ffi` into the artifacts its JS consumers load at runtime — `lib/` (tsc), `index.node` (cargo), and optionally `dist/wasm/**` (wasm-pack) — then prove they load. @@ -47,7 +47,7 @@ runs: id: cache-native uses: actions/cache@v4 with: - path: packages/protect-ffi/index.node + path: languages/typescript/packages/protect-ffi/index.node # package.json and mise.toml are in the key because they are build # INPUTS, not just metadata: `build:native` is `cargo-build` plus a # `postcargo-build` hook (`neon dist < cargo.log`), both defined in @@ -82,11 +82,11 @@ runs: # that way) would make it a compile input with no other trace. key: >- ffi-native-${{ runner.os }}-${{ runner.arch }}-${{ - hashFiles('packages/protect-ffi/crates/**', - 'packages/protect-ffi/Cargo.toml', - 'packages/protect-ffi/Cargo.lock', - 'packages/protect-ffi/package.json', - 'packages/protect-ffi/mise.toml', + hashFiles('languages/typescript/packages/protect-ffi/crates/**', + 'languages/typescript/packages/protect-ffi/Cargo.toml', + 'languages/typescript/packages/protect-ffi/Cargo.lock', + 'languages/typescript/packages/protect-ffi/package.json', + 'languages/typescript/packages/protect-ffi/mise.toml', 'packages/eql/crates/**', 'packages/eql/Cargo.toml') }} @@ -109,7 +109,7 @@ runs: # Unlike index.node, this path is NOT purely generated. `dist/wasm` holds # wasm-pack's output alongside three declaration files that are tracked in - # git — see packages/protect-ffi/.gitignore for why they have to be. A + # git — see languages/typescript/packages/protect-ffi/.gitignore for why they have to be. A # restore untars over the checkout, so with a key hashed from the Rust # inputs alone, an entry saved before a `.d.ts` edit silently reverts that # edit: no diff, no log line, and the next `tsc` against wasm-inline @@ -139,7 +139,7 @@ runs: id: cache-wasm uses: actions/cache@v4 with: - path: packages/protect-ffi/dist/wasm + path: languages/typescript/packages/protect-ffi/dist/wasm # The last five are the same build-input argument as on the native key, # and `build:wasm` is the longer pipeline of the two: wasm-pack, then # `tsc -p tsconfig.wasm-errors.json`, then a `postbuild:wasm` hook @@ -173,19 +173,19 @@ runs: # same missing input. key: >- ffi-wasm-${{ runner.os }}-${{ - hashFiles('packages/protect-ffi/crates/**', - 'packages/protect-ffi/Cargo.toml', - 'packages/protect-ffi/Cargo.lock', + hashFiles('languages/typescript/packages/protect-ffi/crates/**', + 'languages/typescript/packages/protect-ffi/Cargo.toml', + 'languages/typescript/packages/protect-ffi/Cargo.lock', 'packages/eql/crates/**', 'packages/eql/Cargo.toml', - 'packages/protect-ffi/dist/wasm/*.d.ts', - 'packages/protect-ffi/src/errors.ts', - 'packages/protect-ffi/package.json', - 'packages/protect-ffi/mise.toml', - 'packages/protect-ffi/tsconfig.wasm-errors.json', - 'packages/protect-ffi/scripts/inline-wasm.mjs') }} + 'languages/typescript/packages/protect-ffi/dist/wasm/*.d.ts', + 'languages/typescript/packages/protect-ffi/src/errors.ts', + 'languages/typescript/packages/protect-ffi/package.json', + 'languages/typescript/packages/protect-ffi/mise.toml', + 'languages/typescript/packages/protect-ffi/tsconfig.wasm-errors.json', + 'languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs') }} - # mise carries the pinned wasm-pack (see packages/protect-ffi/mise.toml) + # mise carries the pinned wasm-pack (see languages/typescript/packages/protect-ffi/mise.toml) # and, run from that directory, trusts the nested config — a bare `mise` # call elsewhere refuses it with "Config files are not trusted", which # reads as a toolchain problem rather than a trust one. @@ -210,7 +210,7 @@ runs: with: install: true install_args: aqua:wasm-bindgen/wasm-pack - working_directory: packages/protect-ffi + working_directory: languages/typescript/packages/protect-ffi # `--all-targets` in the Rust lint means all target KINDS, not platforms; # wasm32 has to be installed explicitly before anything can build for it. @@ -230,7 +230,7 @@ runs: # deep in a credentialed suite. Fail here instead, naming the artifact. - name: Verify the binding loads shell: bash - working-directory: packages/protect-ffi + working-directory: languages/typescript/packages/protect-ffi env: WANT_WASM: ${{ inputs.wasm }} run: | diff --git a/.github/dependabot.yml b/.github/dependabot.yml index a4bdb9370..395548f66 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -62,7 +62,7 @@ updates: update-types: - version-update:semver-major - # ── Cargo (packages/protect-ffi — one of two Rust workspaces) ─── + # ── Cargo (languages/typescript/packages/protect-ffi — one of two Rust workspaces) ─── # Absorbing protect-ffi brought a 494-crate Cargo.lock in-tree. osv-scanner # already sees it — `--recursive ./` walks the tree and extracts every # lockfile it recognises — so known advisories were visible from day one, but @@ -76,7 +76,7 @@ updates: # A misaimed directory fails silently: Dependabot records "no manifest # found" on a log page nobody visits, and the symptom is simply that no PR # ever arrives. The e2e test asserts this path holds a Cargo.toml. - directory: /packages/protect-ffi + directory: /languages/typescript/packages/protect-ffi # Monthly, where npm and actions are weekly. The deviation is about # validation cost, not risk appetite: a Cargo.lock bump is checked by # tests-rust.yml — one Blacksmith job, 45-minute timeout, cargo test + @@ -190,7 +190,7 @@ updates: - patch ignore: # `cipherstash-client = "=0.42.0"` in tests/sqlx/Cargo.toml — the SAME - # exact pin, at the SAME version, as packages/protect-ffi. That is not a + # exact pin, at the SAME version, as languages/typescript/packages/protect-ffi. That is not a # coincidence and it is the reason the subtree was imported: the two now # share one release train, and a Dependabot PR that moved one workspace # and not the other would reintroduce precisely the skew the absorption diff --git a/.github/workflows/_build-ffi-artifacts.yml b/.github/workflows/_build-ffi-artifacts.yml index 802932629..b11178ba4 100644 --- a/.github/workflows/_build-ffi-artifacts.yml +++ b/.github/workflows/_build-ffi-artifacts.yml @@ -151,7 +151,7 @@ jobs: - name: Install node-gyp run: npm install -g node-gyp - # zig + cargo-zigbuild, pinned in packages/protect-ffi/mise.toml. Only the + # zig + cargo-zigbuild, pinned in languages/typescript/packages/protect-ffi/mise.toml. Only the # gnu platforms use them, so the four others skip this rather than # compiling cargo-zigbuild from source on runners that never call it. # @@ -175,14 +175,14 @@ jobs: with: install: true install_args: zig cargo:cargo-zigbuild - working_directory: packages/protect-ffi + working_directory: languages/typescript/packages/protect-ffi cache: false - name: Install dependencies run: pnpm install --frozen-lockfile - name: Build binding - working-directory: packages/protect-ffi + working-directory: languages/typescript/packages/protect-ffi env: CARGO_BUILD_TARGET: ${{ matrix.cfg.target }} NEON_BUILD_PLATFORM: ${{ matrix.cfg.platform }} @@ -247,7 +247,7 @@ jobs: fi - name: Place the binding in its platform package - working-directory: packages/protect-ffi + working-directory: languages/typescript/packages/protect-ffi env: PLATFORM: ${{ matrix.cfg.platform }} BUILD_LOG: ${{ matrix.cfg.log }} @@ -280,8 +280,8 @@ jobs: run: | set -euo pipefail mkdir -p ffi-dist - pnpm --dir "packages/protect-ffi/platforms/${PLATFORM}" pack - mv "packages/protect-ffi/platforms/${PLATFORM}"/*.tgz ffi-dist/ + pnpm --dir "languages/typescript/packages/protect-ffi/platforms/${PLATFORM}" pack + mv "languages/typescript/packages/protect-ffi/platforms/${PLATFORM}"/*.tgz ffi-dist/ ls ffi-dist - name: Verify the tarball is the platform package, not the wrapper @@ -348,7 +348,7 @@ jobs: - name: Install node-gyp run: npm install -g node-gyp - # wasm-pack, pinned in packages/protect-ffi/mise.toml — `build:wasm` + # wasm-pack, pinned in languages/typescript/packages/protect-ffi/mise.toml — `build:wasm` # shells out to it and nothing else supplies it. `install_args` narrows # this to wasm-pack alone: a bare `mise install` would also build # cargo-zigbuild from source, which this job never calls. The argument is @@ -359,7 +359,7 @@ jobs: with: install: true install_args: aqua:wasm-bindgen/wasm-pack - working_directory: packages/protect-ffi + working_directory: languages/typescript/packages/protect-ffi cache: false # `--all-targets` in the Rust lint means all target KINDS, not platforms; @@ -374,15 +374,15 @@ jobs: # tracked; the runtime .js and .wasm are generated here. Without this the # published `./wasm` and `./wasm-inline` entries resolve to nothing. - name: Build WASM - working-directory: packages/protect-ffi + working-directory: languages/typescript/packages/protect-ffi run: pnpm run build:wasm - name: Pack the wrapper run: | set -euo pipefail mkdir -p ffi-dist - pnpm --dir packages/protect-ffi pack - mv packages/protect-ffi/*.tgz ffi-dist/ + pnpm --dir languages/typescript/packages/protect-ffi pack + mv languages/typescript/packages/protect-ffi/*.tgz ffi-dist/ - name: Verify the wrapper tarball run: | diff --git a/.github/workflows/fta-v3.yml b/.github/workflows/fta-v3.yml index e5228686d..258e3e941 100644 --- a/.github/workflows/fta-v3.yml +++ b/.github/workflows/fta-v3.yml @@ -12,24 +12,24 @@ on: branches: - 'main' paths: - - 'packages/stack/src/eql/v3/**' - - 'packages/stack-drizzle/**' - - 'packages/stack-supabase/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/stack-drizzle/**' + - 'languages/typescript/packages/stack-supabase/**' # Shared match-index defaults live outside src/eql/v3 but shape every # emitted v3 match block (load-bearing `k`/`m` ciphertext params), so edits # here must trigger the v3 gate too. - - 'packages/stack/src/schema/match-defaults.ts' - - 'packages/stack/package.json' + - 'languages/typescript/packages/stack/src/schema/match-defaults.ts' + - 'languages/typescript/packages/stack/package.json' - '.github/workflows/fta-v3.yml' pull_request: branches: - "**" paths: - - 'packages/stack/src/eql/v3/**' - - 'packages/stack-drizzle/**' - - 'packages/stack-supabase/**' - - 'packages/stack/src/schema/match-defaults.ts' - - 'packages/stack/package.json' + - 'languages/typescript/packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/stack-drizzle/**' + - 'languages/typescript/packages/stack-supabase/**' + - 'languages/typescript/packages/stack/src/schema/match-defaults.ts' + - 'languages/typescript/packages/stack/package.json' - '.github/workflows/fta-v3.yml' permissions: diff --git a/.github/workflows/integration-drizzle.yml b/.github/workflows/integration-drizzle.yml index d931ebc89..02a726790 100644 --- a/.github/workflows/integration-drizzle.yml +++ b/.github/workflows/integration-drizzle.yml @@ -16,25 +16,25 @@ on: push: branches: [main] paths: - - 'packages/stack/src/eql/v3/**' - - 'packages/stack-drizzle/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/stack-drizzle/**' # Source layers the adapter's encoding/round-trip rests on: a break here # (not just under src/eql/v3) can produce wrong rows, so trigger the live # suite that would catch it. - - 'packages/stack/src/encryption/**' - - 'packages/stack/src/schema/**' - - 'packages/stack/integration/**' + - 'languages/typescript/packages/stack/src/encryption/**' + - 'languages/typescript/packages/stack/src/schema/**' + - 'languages/typescript/packages/stack/integration/**' # The WASM family suite (integration/wasm/**) exercises this entry: - - 'packages/stack/src/wasm-inline.ts' + - 'languages/typescript/packages/stack/src/wasm-inline.ts' # The DynamoDB adapter, and the entry/type modules the suites import # directly. `integration/shared/v2-decrypt-compat` and its # `integration/wasm/` twin (both selected below) are the repo's only live # EQL v2 read coverage, and they exercise the DynamoDB legacy path, so a # change here must run them. Pinned by # scripts/__tests__/integration-workflow-paths.test.mjs. - - 'packages/stack/src/dynamodb/**' - - 'packages/stack/src/index.ts' - - 'packages/stack/src/types.ts' + - 'languages/typescript/packages/stack/src/dynamodb/**' + - 'languages/typescript/packages/stack/src/index.ts' + - 'languages/typescript/packages/stack/src/types.ts' # Those same v2 suites mint their fixtures by importing # `@cipherstash/protect-ffi` directly. A native-module bump is the change # most able to break v2 payload deserialization and it touches NO source @@ -49,10 +49,10 @@ on: # and these are credentialed, database-backed jobs. Nothing is lost: a # protect-ffi or auth version change cannot reach the lockfile without # editing one of the two manifests below first. - - 'packages/stack/package.json' + - 'languages/typescript/packages/stack/package.json' - 'pnpm-workspace.yaml' - - 'packages/test-kit/**' - - 'packages/cli/src/installer/**' + - 'languages/typescript/packages/test-kit/**' + - 'languages/typescript/packages/cli/src/installer/**' - 'local/docker-compose.postgres.yml' - 'local/docker-compose.supabase.yml' - 'local/supabase-init.sql' @@ -69,12 +69,12 @@ on: # without touching a .rs file, and package.json / mise.toml carry the # build scripts and the toolchain pin. Matching the filter in # tests-rust.yml, which already covers all four. - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # The non-cargo half of `build:wasm`, and the reason this job passes # `wasm: 'true'`: `tsc -p tsconfig.wasm-errors.json`, then a # `postbuild:wasm` hook running `scripts/inline-wasm.mjs`, which is what @@ -85,8 +85,8 @@ on: # two entries the workflow does not trigger at all, so neither the rebuild # nor the only suite that loads it ever runs. # Pinned by scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs. - - 'packages/protect-ffi/tsconfig.wasm-errors.json' - - 'packages/protect-ffi/scripts/inline-wasm.mjs' + - 'languages/typescript/packages/protect-ffi/tsconfig.wasm-errors.json' + - 'languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs' # Out of that package, and compiled into the same two artifacts: the # cdylib crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the @@ -101,25 +101,25 @@ on: branches: ['**'] # Repeated verbatim: GitHub Actions does not support YAML anchors/aliases. paths: - - 'packages/stack/src/eql/v3/**' - - 'packages/stack-drizzle/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/stack-drizzle/**' # Source layers the adapter's encoding/round-trip rests on: a break here # (not just under src/eql/v3) can produce wrong rows, so trigger the live # suite that would catch it. - - 'packages/stack/src/encryption/**' - - 'packages/stack/src/schema/**' - - 'packages/stack/integration/**' + - 'languages/typescript/packages/stack/src/encryption/**' + - 'languages/typescript/packages/stack/src/schema/**' + - 'languages/typescript/packages/stack/integration/**' # The WASM family suite (integration/wasm/**) exercises this entry: - - 'packages/stack/src/wasm-inline.ts' + - 'languages/typescript/packages/stack/src/wasm-inline.ts' # The DynamoDB adapter, and the entry/type modules the suites import # directly. `integration/shared/v2-decrypt-compat` and its # `integration/wasm/` twin (both selected below) are the repo's only live # EQL v2 read coverage, and they exercise the DynamoDB legacy path, so a # change here must run them. Pinned by # scripts/__tests__/integration-workflow-paths.test.mjs. - - 'packages/stack/src/dynamodb/**' - - 'packages/stack/src/index.ts' - - 'packages/stack/src/types.ts' + - 'languages/typescript/packages/stack/src/dynamodb/**' + - 'languages/typescript/packages/stack/src/index.ts' + - 'languages/typescript/packages/stack/src/types.ts' # Those same v2 suites mint their fixtures by importing # `@cipherstash/protect-ffi` directly. A native-module bump is the change # most able to break v2 payload deserialization and it touches NO source @@ -134,10 +134,10 @@ on: # and these are credentialed, database-backed jobs. Nothing is lost: a # protect-ffi or auth version change cannot reach the lockfile without # editing one of the two manifests below first. - - 'packages/stack/package.json' + - 'languages/typescript/packages/stack/package.json' - 'pnpm-workspace.yaml' - - 'packages/test-kit/**' - - 'packages/cli/src/installer/**' + - 'languages/typescript/packages/test-kit/**' + - 'languages/typescript/packages/cli/src/installer/**' - 'local/docker-compose.postgres.yml' - 'local/docker-compose.supabase.yml' - 'local/supabase-init.sql' @@ -154,12 +154,12 @@ on: # without touching a .rs file, and package.json / mise.toml carry the # build scripts and the toolchain pin. Matching the filter in # tests-rust.yml, which already covers all four. - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # The non-cargo half of `build:wasm`, and the reason this job passes # `wasm: 'true'`: `tsc -p tsconfig.wasm-errors.json`, then a # `postbuild:wasm` hook running `scripts/inline-wasm.mjs`, which is what @@ -170,8 +170,8 @@ on: # two entries the workflow does not trigger at all, so neither the rebuild # nor the only suite that loads it ever runs. # Pinned by scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs. - - 'packages/protect-ffi/tsconfig.wasm-errors.json' - - 'packages/protect-ffi/scripts/inline-wasm.mjs' + - 'languages/typescript/packages/protect-ffi/tsconfig.wasm-errors.json' + - 'languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs' # Out of that package, and compiled into the same two artifacts: the # cdylib crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the diff --git a/.github/workflows/integration-prisma-next.yml b/.github/workflows/integration-prisma-next.yml index 9f94acda2..8ad8faf9c 100644 --- a/.github/workflows/integration-prisma-next.yml +++ b/.github/workflows/integration-prisma-next.yml @@ -18,15 +18,15 @@ on: push: branches: [main] paths: - - 'packages/stack/src/eql/v3/**' - - 'packages/stack-prisma/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/stack-prisma/**' # Source layers the adapter's encoding/round-trip rests on: a break here # (not just under src/eql/v3) can produce wrong rows, so trigger the live # suite that would catch it. - - 'packages/stack/src/encryption/**' - - 'packages/stack/src/schema/**' - - 'packages/test-kit/**' - - 'packages/cli/src/installer/**' + - 'languages/typescript/packages/stack/src/encryption/**' + - 'languages/typescript/packages/stack/src/schema/**' + - 'languages/typescript/packages/test-kit/**' + - 'languages/typescript/packages/cli/src/installer/**' - 'local/docker-compose.postgres.yml' - 'local/docker-compose.supabase.yml' - 'local/supabase-init.sql' @@ -43,12 +43,12 @@ on: # without touching a .rs file, and package.json / mise.toml carry the # build scripts and the toolchain pin. Matching the filter in # tests-rust.yml, which already covers all four. - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the @@ -65,15 +65,15 @@ on: branches: ['**'] # Repeated verbatim: GitHub Actions does not support YAML anchors/aliases. paths: - - 'packages/stack/src/eql/v3/**' - - 'packages/stack-prisma/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/stack-prisma/**' # Source layers the adapter's encoding/round-trip rests on: a break here # (not just under src/eql/v3) can produce wrong rows, so trigger the live # suite that would catch it. - - 'packages/stack/src/encryption/**' - - 'packages/stack/src/schema/**' - - 'packages/test-kit/**' - - 'packages/cli/src/installer/**' + - 'languages/typescript/packages/stack/src/encryption/**' + - 'languages/typescript/packages/stack/src/schema/**' + - 'languages/typescript/packages/test-kit/**' + - 'languages/typescript/packages/cli/src/installer/**' - 'local/docker-compose.postgres.yml' - 'local/docker-compose.supabase.yml' - 'local/supabase-init.sql' @@ -90,12 +90,12 @@ on: # without touching a .rs file, and package.json / mise.toml carry the # build scripts and the toolchain pin. Matching the filter in # tests-rust.yml, which already covers all four. - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the diff --git a/.github/workflows/integration-protect-ffi.yml b/.github/workflows/integration-protect-ffi.yml index 2cc9d13ba..05cea407b 100644 --- a/.github/workflows/integration-protect-ffi.yml +++ b/.github/workflows/integration-protect-ffi.yml @@ -1,17 +1,17 @@ name: Integration — protect-ffi (native + WASM) -# The `packages/protect-ffi/integration-tests/` suite: 19 files of live +# The `languages/typescript/packages/protect-ffi/integration-tests/` suite: 19 files of live # encrypt / decrypt / lock-context / keyset / JSON-SteVec / Postgres / # WASM-round-trip coverage against real ZeroKMS and a real Postgres. # # WHY THIS EXISTS: upstream (`cipherstash/protectjs-ffi`) ran this suite on # EVERY pull request from `.github/workflows/test.yml` — `mise setup`, then # `mise run test:integration:all`. The absorption copied the suite in intact and -# left that workflow behind under `packages/protect-ffi/.github/`, where GitHub +# left that workflow behind under `languages/typescript/packages/protect-ffi/.github/`, where GitHub # never looks: it reads workflows from the repository root alone. So from the # day protect-ffi landed here, none of it ran, and a suite that never starts # reads exactly like a suite that passes. -# `packages/protect-ffi/src/integrationSuiteCi.test.ts` asserts this file (or a +# `languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts` asserts this file (or a # successor) still invokes it. # # WHERE THE SUITE'S DEPENDENCIES COME FROM. `integration-tests/` is a pnpm @@ -37,7 +37,7 @@ on: paths: # The suite itself: tests, fixtures, its compose file, its `tasks.toml` # and its manifest. - - 'packages/protect-ffi/integration-tests/**' + - 'languages/typescript/packages/protect-ffi/integration-tests/**' # The suite's dependency versions, now that it is a pnpm workspace member: # `@cipherstash/auth`, `vitest` and `typescript` reach it through # `catalog:repo`, so a catalog bump changes what this job runs while @@ -57,26 +57,26 @@ on: # The Rust the suite round-trips every payload through, and the manifests # that change what cargo builds without touching a .rs file. Matching the # filter in tests-rust.yml. - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' # `src/**` is `lib/`, which is the module every test imports, plus # `load.cts` — the loader that finds `index.node`. - - 'packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/src/**' # `scripts/inline-wasm.mjs` emits `dist/wasm/protect_ffi_inline.js`, which # `tests/wasm-round-trip.test.ts` loads at module-graph time. An edit # there breaks that suite while touching no Rust and no `src/`. - - 'packages/protect-ffi/scripts/**' + - 'languages/typescript/packages/protect-ffi/scripts/**' # The other half of the same build: `build:wasm` ends in `tsc -p # tsconfig.wasm-errors.json`, and the inliner re-exports what it emits. # `scripts/**` above does not reach a root tsconfig, so without this an # edit to it rebuilds the bundle that suite loads and starts no job. - - 'packages/protect-ffi/tsconfig.wasm-errors.json' + - 'languages/typescript/packages/protect-ffi/tsconfig.wasm-errors.json' # package.json carries the build scripts and the exports map the suite # resolves through; mise.toml carries the `tasks.toml` include, the # toolchain pins, and the PG* connection env. - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of this package, and a real compile input: the cdylib crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the # EQL wire types are linked into `index.node` AND into the wasm32 build @@ -96,17 +96,17 @@ on: # A one-sided edit disables the job on pull requests while leaving it green # on `main` — the exact inversion of what you want. paths: - - 'packages/protect-ffi/integration-tests/**' + - 'languages/typescript/packages/protect-ffi/integration-tests/**' - 'pnpm-workspace.yaml' - 'packages/eql/packages/eql/**' - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/scripts/**' - - 'packages/protect-ffi/tsconfig.wasm-errors.json' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/scripts/**' + - 'languages/typescript/packages/protect-ffi/tsconfig.wasm-errors.json' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of this package, and a real compile input: the cdylib crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the # EQL wire types are linked into `index.node` AND into the wasm32 build @@ -188,7 +188,7 @@ jobs: # `5436:5432`, so 5436 is the only port that reaches the container from # the runner. Upstream's workflow said 5432 and worked anyway because # every invocation went through mise, and `[env]` in - # packages/protect-ffi/mise.toml (which says 5436) overrides an inherited + # languages/typescript/packages/protect-ffi/mise.toml (which says 5436) overrides an inherited # value — verified, not assumed. The suite step below runs vitest # directly, outside mise, so that safety net is gone and this block has to # be right. The values here are identical to mise.toml's, which makes the @@ -249,7 +249,7 @@ jobs: # this tree. It is also required before the binding build — # `build-ffi-binding` runs `pnpm --filter @cipherstash/protect-ffi run # build` — and is what puts `@neon-rs/load` in - # packages/protect-ffi/node_modules. + # languages/typescript/packages/protect-ffi/node_modules. # # `mise run setup` below runs the same command again, deliberately: the # task has to stand on its own for a contributor running it locally. On @@ -294,7 +294,7 @@ jobs: # `working_directory` is load-bearing, not tidiness. mise reads config # from the current directory and its PARENTS, so an action running at the - # repo root never sees packages/protect-ffi/mise.toml — it would install + # repo root never sees languages/typescript/packages/protect-ffi/mise.toml — it would install # nothing and leave the config untrusted, and the later `mise run` fails # with "Config files ... are not trusted", which reads as a toolchain # problem rather than a trust one. @@ -314,7 +314,7 @@ jobs: - uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3.6.3 with: install: true - working_directory: packages/protect-ffi + working_directory: languages/typescript/packages/protect-ffi # One task, four things the suite cannot run without (see # integration-tests/tasks.toml): `pnpm install --frozen-lockfile` (a @@ -337,7 +337,7 @@ jobs: # The fixed host port (5436) that comes with it cannot collide with the # shared stacks, which publish on ephemeral ports. - name: Provision the suite (Postgres, EQL v2 + v3) - working-directory: packages/protect-ffi + working-directory: languages/typescript/packages/protect-ffi run: mise run setup # vitest directly rather than `mise run test:integration:all`, because @@ -352,7 +352,7 @@ jobs: # put in this package's `node_modules/.bin`. It was `npx` against the # suite's own `package-lock.json` until CIP-3744 retired that lockfile. - name: Integration suite (live ZeroKMS + Postgres, native and WASM) - working-directory: packages/protect-ffi/integration-tests + working-directory: languages/typescript/packages/protect-ffi/integration-tests run: pnpm exec vitest run # `-v` drops the volume too. The runner is ephemeral, so this is not about @@ -362,5 +362,5 @@ jobs: # what `mise run start-db` brought the stack up under. - name: Stop Postgres if: always() - working-directory: packages/protect-ffi/integration-tests + working-directory: languages/typescript/packages/protect-ffi/integration-tests run: docker compose down -v diff --git a/.github/workflows/integration-supabase.yml b/.github/workflows/integration-supabase.yml index 61f1f4ad6..d1a2a3b65 100644 --- a/.github/workflows/integration-supabase.yml +++ b/.github/workflows/integration-supabase.yml @@ -12,23 +12,23 @@ on: push: branches: [main] paths: - - 'packages/stack-supabase/**' - - 'packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/stack-supabase/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' # Source layers the adapter's encoding/round-trip rests on: a break here # (not just under src/supabase) can produce wrong wire output or rows, so # trigger the live suite that would catch it. - - 'packages/stack/src/encryption/**' - - 'packages/stack/src/schema/**' - - 'packages/stack/integration/**' + - 'languages/typescript/packages/stack/src/encryption/**' + - 'languages/typescript/packages/stack/src/schema/**' + - 'languages/typescript/packages/stack/integration/**' # The DynamoDB adapter, and the entry/type modules the suites import # directly. `integration/shared/v2-decrypt-compat` is the repo's only live # EQL v2 read coverage for the native entry (the `integration/wasm/` twin # runs on the Drizzle job) and it exercises the DynamoDB legacy path, so a # change here must run it. Pinned by # scripts/__tests__/integration-workflow-paths.test.mjs. - - 'packages/stack/src/dynamodb/**' - - 'packages/stack/src/index.ts' - - 'packages/stack/src/types.ts' + - 'languages/typescript/packages/stack/src/dynamodb/**' + - 'languages/typescript/packages/stack/src/index.ts' + - 'languages/typescript/packages/stack/src/types.ts' # That v2 suite mints its fixtures by importing `@cipherstash/protect-ffi` # directly. A native-module bump is the change most able to break v2 # payload deserialization and it touches NO source directory, so without @@ -42,10 +42,10 @@ on: # and these are credentialed, database-backed jobs. Nothing is lost: a # protect-ffi or auth version change cannot reach the lockfile without # editing one of the two manifests below first. - - 'packages/stack/package.json' + - 'languages/typescript/packages/stack/package.json' - 'pnpm-workspace.yaml' - - 'packages/test-kit/**' - - 'packages/cli/src/installer/**' + - 'languages/typescript/packages/test-kit/**' + - 'languages/typescript/packages/cli/src/installer/**' - 'local/docker-compose.supabase.yml' - 'local/supabase-init.sql' - '.github/workflows/integration-supabase.yml' @@ -61,12 +61,12 @@ on: # without touching a .rs file, and package.json / mise.toml carry the # build scripts and the toolchain pin. Matching the filter in # tests-rust.yml, which already covers all four. - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the @@ -82,23 +82,23 @@ on: pull_request: branches: ['**'] paths: - - 'packages/stack-supabase/**' - - 'packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/stack-supabase/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' # Source layers the adapter's encoding/round-trip rests on: a break here # (not just under src/supabase) can produce wrong wire output or rows, so # trigger the live suite that would catch it. - - 'packages/stack/src/encryption/**' - - 'packages/stack/src/schema/**' - - 'packages/stack/integration/**' + - 'languages/typescript/packages/stack/src/encryption/**' + - 'languages/typescript/packages/stack/src/schema/**' + - 'languages/typescript/packages/stack/integration/**' # The DynamoDB adapter, and the entry/type modules the suites import # directly. `integration/shared/v2-decrypt-compat` is the repo's only live # EQL v2 read coverage for the native entry (the `integration/wasm/` twin # runs on the Drizzle job) and it exercises the DynamoDB legacy path, so a # change here must run it. Pinned by # scripts/__tests__/integration-workflow-paths.test.mjs. - - 'packages/stack/src/dynamodb/**' - - 'packages/stack/src/index.ts' - - 'packages/stack/src/types.ts' + - 'languages/typescript/packages/stack/src/dynamodb/**' + - 'languages/typescript/packages/stack/src/index.ts' + - 'languages/typescript/packages/stack/src/types.ts' # That v2 suite mints its fixtures by importing `@cipherstash/protect-ffi` # directly. A native-module bump is the change most able to break v2 # payload deserialization and it touches NO source directory, so without @@ -112,10 +112,10 @@ on: # and these are credentialed, database-backed jobs. Nothing is lost: a # protect-ffi or auth version change cannot reach the lockfile without # editing one of the two manifests below first. - - 'packages/stack/package.json' + - 'languages/typescript/packages/stack/package.json' - 'pnpm-workspace.yaml' - - 'packages/test-kit/**' - - 'packages/cli/src/installer/**' + - 'languages/typescript/packages/test-kit/**' + - 'languages/typescript/packages/cli/src/installer/**' - 'local/docker-compose.supabase.yml' - 'local/supabase-init.sql' - '.github/workflows/integration-supabase.yml' @@ -131,12 +131,12 @@ on: # without touching a .rs file, and package.json / mise.toml carry the # build scripts and the toolchain pin. Matching the filter in # tests-rust.yml, which already covers all four. - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the diff --git a/.github/workflows/prisma-example-readme-e2e.yml b/.github/workflows/prisma-example-readme-e2e.yml index 667350968..f46a9d67b 100644 --- a/.github/workflows/prisma-example-readme-e2e.yml +++ b/.github/workflows/prisma-example-readme-e2e.yml @@ -1,6 +1,6 @@ name: Prisma Example README E2E -# Outside-in walkthrough of `examples/prisma/README.md`'s "Run it" +# Outside-in walkthrough of `languages/typescript/examples/prisma/README.md`'s "Run it" # section: copies .env.example, brings up the bundled Postgres, runs # `pnpm install`, `pnpm emit`, `pnpm migration:plan --name initial`, # `pnpm migration:apply`, then `pnpm start`, asserting each command @@ -16,7 +16,7 @@ on: branches: - main paths: - - 'examples/prisma/**' + - 'languages/typescript/examples/prisma/**' - '.github/workflows/prisma-example-readme-e2e.yml' # The walkthrough encrypts against the live service, so the native # binding and the action that builds it are inputs to this suite. Added @@ -26,12 +26,12 @@ on: # report — a PR touching any of these runs the walkthrough before the # change lands, not after. - '.github/actions/build-ffi-binding/**' - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the @@ -48,7 +48,7 @@ on: branches: - '**' paths: - - 'examples/prisma/**' + - 'languages/typescript/examples/prisma/**' - '.github/workflows/prisma-example-readme-e2e.yml' # The same entries as under `push` above, and the copy that does the # work: a PR touching the native binding or the action that builds it @@ -58,12 +58,12 @@ on: # scripts/__tests__/workflow-paths-filter-parity.test.mjs compares the # two copies.) - '.github/actions/build-ffi-binding/**' - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the @@ -135,7 +135,7 @@ jobs: client-access-key: ${{ secrets.CS_CLIENT_ACCESS_KEY }} # The walkthrough encrypts against the live service, so it needs the - # native binding — `packages/protect-ffi` is a workspace package now, so + # native binding — `languages/typescript/packages/protect-ffi` is a workspace package now, so # `index.node` is a build output rather than tarball contents. This step # runs on push to main and on any PR whose diff matches the paths filter # above, the absorption PR that introduced the need included: that PR @@ -147,7 +147,7 @@ jobs: # Build via turbo so `^build` on `@cipherstash/stack-prisma` and # its `@cipherstash/stack` peer is honoured. The test's - # `pnpm install` subprocess inside `examples/prisma/` is a no-op + # `pnpm install` subprocess inside `languages/typescript/examples/prisma/` is a no-op # given the lockfile is already in steady state from this step. - name: Build @cipherstash/stack-prisma run: pnpm exec turbo run build --filter @cipherstash/stack-prisma @@ -157,5 +157,5 @@ jobs: - name: Tear down bundled Postgres (best-effort) if: always() - working-directory: examples/prisma + working-directory: languages/typescript/examples/prisma run: docker compose down -v || true diff --git a/.github/workflows/prisma-next-e2e.yml b/.github/workflows/prisma-next-e2e.yml index 6ef2b9a60..23061ae7b 100644 --- a/.github/workflows/prisma-next-e2e.yml +++ b/.github/workflows/prisma-next-e2e.yml @@ -3,7 +3,7 @@ name: Prisma Next E2E # End-to-end tests for `@cipherstash/stack-prisma`: spins up a real # Postgres container, applies the cipherstash baseline migration # (EQL bundle install) + the example app's schema, then runs the -# suite at `examples/prisma/test/e2e/` against a live ZeroKMS +# suite at `languages/typescript/examples/prisma/test/e2e/` against a live ZeroKMS # workspace. # # Triggers only on changes that affect the package or the example @@ -15,8 +15,8 @@ on: branches: - main paths: - - 'packages/stack-prisma/**' - - 'examples/prisma/**' + - 'languages/typescript/packages/stack-prisma/**' + - 'languages/typescript/examples/prisma/**' - '.github/workflows/prisma-next-e2e.yml' # This suite encrypts against the live service, so the native binding and # the action that builds it are inputs to it. Added with that build step: @@ -25,12 +25,12 @@ on: # what makes that a gate rather than a report — a PR touching any of these # runs the suite before the change lands, not after. - '.github/actions/build-ffi-binding/**' - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the @@ -47,8 +47,8 @@ on: branches: - '**' paths: - - 'packages/stack-prisma/**' - - 'examples/prisma/**' + - 'languages/typescript/packages/stack-prisma/**' + - 'languages/typescript/examples/prisma/**' - '.github/workflows/prisma-next-e2e.yml' # The same entries as under `push` above, and the copy that does the # work: a PR touching the native binding or the action that builds it @@ -58,12 +58,12 @@ on: # scripts/__tests__/workflow-paths-filter-parity.test.mjs compares the # two copies.) - '.github/actions/build-ffi-binding/**' - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/src/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/package.json' - - 'packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/src/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the @@ -137,7 +137,7 @@ jobs: client-access-key: ${{ secrets.CS_CLIENT_ACCESS_KEY }} # This suite encrypts against the live service, so it needs the native - # binding — `packages/protect-ffi` is a workspace package now, so + # binding — `languages/typescript/packages/protect-ffi` is a workspace package now, so # `index.node` is a build output rather than tarball contents. This step # runs on push to main and on any PR whose diff matches the paths filter # above, the absorption PR that introduced the need included: that PR @@ -154,14 +154,14 @@ jobs: # the container, but the migration:apply subprocess relies on # prisma-next.config.ts → process.env['DATABASE_URL'] being set # before the test runner spawns it. - - name: Create .env file in examples/prisma + - name: Create .env file in languages/typescript/examples/prisma run: | - touch ./examples/prisma/.env - echo "DATABASE_URL=postgres://cipherstash:cipherstash@localhost:54329/cipherstash_e2e" >> ./examples/prisma/.env - echo "CS_WORKSPACE_CRN=${{ vars.CS_WORKSPACE_CRN }}" >> ./examples/prisma/.env - echo "CS_CLIENT_ID=${{ vars.CS_CLIENT_ID }}" >> ./examples/prisma/.env - echo "CS_CLIENT_KEY=${{ secrets.CS_CLIENT_KEY }}" >> ./examples/prisma/.env - echo "CS_CLIENT_ACCESS_KEY=${{ secrets.CS_CLIENT_ACCESS_KEY }}" >> ./examples/prisma/.env + touch ./languages/typescript/examples/prisma/.env + echo "DATABASE_URL=postgres://cipherstash:cipherstash@localhost:54329/cipherstash_e2e" >> ./languages/typescript/examples/prisma/.env + echo "CS_WORKSPACE_CRN=${{ vars.CS_WORKSPACE_CRN }}" >> ./languages/typescript/examples/prisma/.env + echo "CS_CLIENT_ID=${{ vars.CS_CLIENT_ID }}" >> ./languages/typescript/examples/prisma/.env + echo "CS_CLIENT_KEY=${{ secrets.CS_CLIENT_KEY }}" >> ./languages/typescript/examples/prisma/.env + echo "CS_CLIENT_ACCESS_KEY=${{ secrets.CS_CLIENT_ACCESS_KEY }}" >> ./languages/typescript/examples/prisma/.env # Build via turbo so the `^build` dependency on # `@cipherstash/stack` (which `@cipherstash/stack-prisma` imports @@ -176,7 +176,7 @@ jobs: run: pnpm exec turbo run emit --filter @cipherstash/prisma-example - name: Start E2E Postgres container - working-directory: examples/prisma + working-directory: languages/typescript/examples/prisma run: | docker compose -f test/e2e/docker-compose.yml up -d # Wait for pg_isready before handing off to the suite — the @@ -194,5 +194,5 @@ jobs: - name: Stop E2E Postgres container if: always() - working-directory: examples/prisma + working-directory: languages/typescript/examples/prisma run: docker compose -f test/e2e/docker-compose.yml down -v diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 1d9b675e7..989954bb1 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -494,7 +494,7 @@ jobs: # every publish fails with E404 (see npm/cli#8976). GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Embeds the CLI's PostHog project key at build time (see - # packages/cli/tsup.config.ts). A repo *variable*, not a secret: the + # languages/typescript/packages/cli/tsup.config.ts). A repo *variable*, not a secret: the # key is public and write-only (like a web SDK key). Unset until GA, so # every release before it is flipped ships telemetry-dormant. This is # the single go-live switch — set it with: diff --git a/.github/workflows/test-eql.yml b/.github/workflows/test-eql.yml index 5cbaa6608..88b50abdc 100644 --- a/.github/workflows/test-eql.yml +++ b/.github/workflows/test-eql.yml @@ -159,7 +159,7 @@ jobs: # Every path except the workflow itself gained the `packages/eql/` # prefix with the subtree. dorny/paths-filter matches against # repo-root-relative paths, so the unprefixed globs would match - # `packages/stack/src/**` and friends instead — firing the whole + # `languages/typescript/packages/stack/src/**` and friends instead — firing the whole # matrix on changes that cannot affect EQL, and (worse) NOT firing on # EQL's own `src/`, since nothing at the repo root is called that. # diff --git a/.github/workflows/tests-bench.yml b/.github/workflows/tests-bench.yml index 488b03ba4..c373c5788 100644 --- a/.github/workflows/tests-bench.yml +++ b/.github/workflows/tests-bench.yml @@ -11,15 +11,15 @@ on: branches: - 'main' paths: - - 'packages/bench/**' - - 'packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/bench/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' # The bench drives the typed v3 CLIENT, which lives in `encryption/`, not # `eql/v3/` (that is the authoring DSL). Without this the job stayed green # by never running for the changes most likely to break it. - - 'packages/stack/src/encryption/**' - - 'packages/stack-drizzle/**' - - 'packages/test-kit/**' - - 'packages/cli/src/installer/**' + - 'languages/typescript/packages/stack/src/encryption/**' + - 'languages/typescript/packages/stack-drizzle/**' + - 'languages/typescript/packages/test-kit/**' + - 'languages/typescript/packages/cli/src/installer/**' - 'local/**' - '.github/workflows/tests-bench.yml' - '.github/actions/integration-setup/**' @@ -28,15 +28,15 @@ on: - "**" # Repeated verbatim: GitHub Actions does not support YAML anchors/aliases. paths: - - 'packages/bench/**' - - 'packages/stack/src/eql/v3/**' + - 'languages/typescript/packages/bench/**' + - 'languages/typescript/packages/stack/src/eql/v3/**' # The bench drives the typed v3 CLIENT, which lives in `encryption/`, not # `eql/v3/` (that is the authoring DSL). Without this the job stayed green # by never running for the changes most likely to break it. - - 'packages/stack/src/encryption/**' - - 'packages/stack-drizzle/**' - - 'packages/test-kit/**' - - 'packages/cli/src/installer/**' + - 'languages/typescript/packages/stack/src/encryption/**' + - 'languages/typescript/packages/stack-drizzle/**' + - 'languages/typescript/packages/test-kit/**' + - 'languages/typescript/packages/cli/src/installer/**' - 'local/**' - '.github/workflows/tests-bench.yml' - '.github/actions/integration-setup/**' @@ -77,7 +77,7 @@ jobs: # credentials, and `tsc --noEmit` passes on a hand-written row type that # agrees with itself (#772 review, finding 12). - name: Run bench unit checks (no database, no credentials) - working-directory: packages/bench + working-directory: languages/typescript/packages/bench run: pnpm test:unit # Service-scoped `postgres`: local/docker-compose.yml also defines a @@ -98,5 +98,5 @@ jobs: # option-terminator and ignore the filter, running all 3 test files # — including ones that need CipherStash credentials. - name: Run bench smoke tests - working-directory: packages/bench + working-directory: languages/typescript/packages/bench run: pnpm test:local db-only diff --git a/.github/workflows/tests-rust.yml b/.github/workflows/tests-rust.yml index 93567dec2..b3e0961c9 100644 --- a/.github/workflows/tests-rust.yml +++ b/.github/workflows/tests-rust.yml @@ -1,13 +1,13 @@ name: Tests (Rust) -# The Rust half of packages/protect-ffi. Path-filtered and separate from +# The Rust half of languages/typescript/packages/protect-ffi. Path-filtered and separate from # tests.yml because it is the only Rust in the repo. # # Since the absorption these checks ran NOWHERE. Phase 1 deliberately moved # `cargo test` + `cargo fmt --check` behind `test:cargo` and clippy behind # `mise run lint:rust`, to keep cargo off every contributor's default # `pnpm test` — but no root workflow picked them back up. -# `packages/protect-ffi/src/lintWiring.test.ts` asserts the split from the +# `languages/typescript/packages/protect-ffi/src/lintWiring.test.ts` asserts the split from the # manifest side; this is the other half, and that test now reads this file. # # The filter is broader than `crates/**`: dependency, feature and toolchain @@ -16,17 +16,17 @@ name: Tests (Rust) on: pull_request: paths: - - 'packages/protect-ffi/crates/**' - - 'packages/protect-ffi/Cargo.toml' - - 'packages/protect-ffi/Cargo.lock' - - 'packages/protect-ffi/mise.toml' - - 'packages/protect-ffi/package.json' + - 'languages/typescript/packages/protect-ffi/crates/**' + - 'languages/typescript/packages/protect-ffi/Cargo.toml' + - 'languages/typescript/packages/protect-ffi/Cargo.lock' + - 'languages/typescript/packages/protect-ffi/mise.toml' + - 'languages/typescript/packages/protect-ffi/package.json' # Out of that package, and compiled by every check below all the same: # `crates/protect-ffi/Cargo.toml` carries # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so # `cargo test`, `cargo fmt --check` and both clippy passes build that # tree. A change there can break this job in a PR touching no file under - # packages/protect-ffi at all. The workspace root manifest comes with it: + # languages/typescript/packages/protect-ffi at all. The workspace root manifest comes with it: # cargo reads it for the crate's workspace context, so a # `.workspace = true` added to eql-bindings becomes a compile input # with no other trace. Same two entries as the native cache key in @@ -67,7 +67,7 @@ jobs: # `working_directory` is load-bearing, not tidiness. mise reads config # from the current directory and its PARENTS, so an action running at the - # repo root never sees packages/protect-ffi/mise.toml — it would install + # repo root never sees languages/typescript/packages/protect-ffi/mise.toml — it would install # nothing and leave the config untrusted. A later `mise run` then fails # with "Config files ... are not trusted", which reads as a toolchain # problem rather than a trust one. @@ -84,7 +84,7 @@ jobs: - uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3.6.3 with: install: true - working_directory: packages/protect-ffi + working_directory: languages/typescript/packages/protect-ffi # `--all-targets` in the clippy invocation means all target KINDS (lib, # bins, tests, benches), not all platform targets — it lints the host and @@ -128,5 +128,5 @@ jobs: # nobody runs (#145). lintWiring.test.ts asserts every `lint:rust:*` task # is in its `depends` list. - name: clippy (host + wasm32) - working-directory: packages/protect-ffi + working-directory: languages/typescript/packages/protect-ffi run: mise run lint:rust diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 8cc57b877..1e311098f 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -117,12 +117,12 @@ jobs: client-key: ${{ secrets.CS_CLIENT_KEY }} client-access-key: ${{ secrets.CS_CLIENT_ACCESS_KEY }} - # `pnpm run test` below runs the `packages/stack` suites, and only 8 of + # `pnpm run test` below runs the `languages/typescript/packages/stack` suites, and only 8 of # those 120 files mock `@cipherstash/protect-ffi` — the rest load # `index.node`, which nothing else in this job produces. # # NOT for protect-ffi's own suite, though vendoring it did add - # `@cipherstash/protect-ffi#test` to `turbo test --filter './packages/*'`. + # `@cipherstash/protect-ffi#test` to `turbo test --filter './languages/typescript/packages/*'`. # That suite must pass with no binding at all (its `build` is `tsc` and # its `test` is deliberately cargo-free), and `src/lintWiring.test.ts` # re-runs it here with the artifact hidden to keep that true — this job @@ -176,7 +176,7 @@ jobs: - name: Typecheck (prisma-next — enforces v3 operator-capability gating) run: pnpm exec turbo run typecheck --filter @cipherstash/stack-prisma - # `packages/bench` is a live importer of `@cipherstash/stack` and + # `languages/typescript/packages/bench` is a live importer of `@cipherstash/stack` and # `@cipherstash/stack-drizzle`, but it has no `test` script (its suites # need a database), so `pnpm run test` never reaches it and an adapter # rename could break it unnoticed. Its `build` is `tsc --noEmit`, and @@ -192,12 +192,12 @@ jobs: - name: Typecheck (wizard) run: pnpm exec turbo run typecheck --filter @cipherstash/wizard - # `examples/*` are standalone apps outside the `./packages/*` filter that - # root `build`/`test` use, so nothing in CI compiled them. `examples/basic` + # `languages/typescript/examples/*` are standalone apps outside the `./languages/typescript/packages/*` filter that + # root `build`/`test` use, so nothing in CI compiled them. `languages/typescript/examples/basic` # had been broken since the v2 removal deleted `encryptedType` and the v2 # `encryptedSupabase` — on a fully green board. Gate it through turbo so # `^build` builds stack/stack-drizzle/stash first. - - name: Typecheck (examples/basic — guards the v3 stack/stack-drizzle importers) + - name: Typecheck (languages/typescript/examples/basic — guards the v3 stack/stack-drizzle importers) run: pnpm exec turbo run typecheck --filter @cipherstash/basic-example # The rest of the surfaces that were compiling nowhere. Each of these has @@ -220,7 +220,7 @@ jobs: - name: Typecheck (nextjs) run: pnpm exec turbo run typecheck --filter @cipherstash/nextjs - - name: Typecheck (examples/prisma — guards the prisma-next importers) + - name: Typecheck (languages/typescript/examples/prisma — guards the prisma-next importers) run: pnpm exec turbo run typecheck --filter @cipherstash/prisma-example - name: Typecheck (e2e) @@ -300,8 +300,8 @@ jobs: # siblings that depend on it. A merge can therefore ARM a release that # cannot succeed, and this repository has done it. `@cipherstash/eql` is # published from cipherstash/encrypt-query-language, so a version bumped - # in this workspace cannot be published from here — while `packages/cli` - # and `packages/stack-prisma` carry it in RUNTIME dependencies, so pnpm + # in this workspace cannot be published from here — while `languages/typescript/packages/cli` + # and `languages/typescript/packages/stack-prisma` carry it in RUNTIME dependencies, so pnpm # packs whatever version this tree holds into both tarballs. Bump it past # what the registry carries and both ship a range no published version # satisfies, in tarballs that publish fine. That is what the hand-applied @@ -324,26 +324,26 @@ jobs: - name: Test — lint script self-tests run: pnpm run test:scripts - - name: Create .env file in ./packages/stack/ + - name: Create .env file in ./languages/typescript/packages/stack/ run: | - touch ./packages/stack/.env - echo "CS_WORKSPACE_CRN=${{ vars.CS_WORKSPACE_CRN }}" >> ./packages/stack/.env - echo "CS_CLIENT_ID=${{ vars.CS_CLIENT_ID }}" >> ./packages/stack/.env - echo "CS_CLIENT_KEY=${{ secrets.CS_CLIENT_KEY }}" >> ./packages/stack/.env - echo "CS_CLIENT_ACCESS_KEY=${{ secrets.CS_CLIENT_ACCESS_KEY }}" >> ./packages/stack/.env - echo "DATABASE_URL=postgres://cipherstash:password@localhost:5432/cipherstash" >> ./packages/stack/.env + touch ./languages/typescript/packages/stack/.env + echo "CS_WORKSPACE_CRN=${{ vars.CS_WORKSPACE_CRN }}" >> ./languages/typescript/packages/stack/.env + echo "CS_CLIENT_ID=${{ vars.CS_CLIENT_ID }}" >> ./languages/typescript/packages/stack/.env + echo "CS_CLIENT_KEY=${{ secrets.CS_CLIENT_KEY }}" >> ./languages/typescript/packages/stack/.env + echo "CS_CLIENT_ACCESS_KEY=${{ secrets.CS_CLIENT_ACCESS_KEY }}" >> ./languages/typescript/packages/stack/.env + echo "DATABASE_URL=postgres://cipherstash:password@localhost:5432/cipherstash" >> ./languages/typescript/packages/stack/.env # Run TurboRepo tests # # STASH_TEST_DATABASE_URL points the CLI's live-Postgres suites - # (`packages/cli/src/**/__tests__/**.live.test.ts`) at this job's + # (`languages/typescript/packages/cli/src/**/__tests__/**.live.test.ts`) at this job's # service container — without it they self-skip, and the only guard on # the `stash eql verify` parser↔catalog spelling seam # (`installer/__tests__/verify.live.test.ts`) would run in no CI # workflow at all: a routine `@cipherstash/eql` bump could then make # every `stash eql install` fail with phantom damage, on green CI. # Most suites need Postgres only. The encrypted-index upgrade suite also - # loads this job's CipherStash credentials from packages/stack/.env and + # loads this job's CipherStash credentials from languages/typescript/packages/stack/.env and # uses the binding built above to create genuine ciphertext. The verify # suite installs EQL v3 into its own schemas, which coexists # with the image's pre-installed EQL v2 that the stack tests use. @@ -432,7 +432,7 @@ jobs: # Run the standalone `e2e/` workspace via turbo so the `^build` # dep on the `test:e2e` task builds cli + wizard first. CLI's own - # E2E (`packages/cli/tests/e2e/**`) is covered by the `run-tests` + # E2E (`languages/typescript/packages/cli/tests/e2e/**`) is covered by the `run-tests` # job above; we filter to the new workspace here to avoid duplication. - name: Run E2E tests run: pnpm exec turbo run test:e2e --filter @cipherstash/e2e @@ -528,7 +528,7 @@ jobs: # src/lintWiring.test.ts asserts this step exists, because between the # absorption and this line the check ran nowhere at all: the jobs its # exemption named were the upstream copies under - # packages/protect-ffi/.github/, which GitHub never executes. + # languages/typescript/packages/protect-ffi/.github/, which GitHub never executes. - name: Typecheck the generated WASM declarations run: pnpm --filter @cipherstash/protect-ffi run test:typecheck:wasm @@ -541,13 +541,13 @@ jobs: # # Not the only suite that loads the real core, and this is not the only # job that builds it for one — `integration-drizzle.yml` runs - # `packages/stack`'s `integration/wasm/**` the same way. It is here + # `languages/typescript/packages/stack`'s `integration/wasm/**` the same way. It is here # because it needs NOTHING else: no credentials, no database. Those # suites' `globalSetup` requires both unconditionally and throws rather # than skipping, and that job is path-filtered and fork-skipped besides, # so hosting a core contract there would leave it unchecked on every diff # those paths do not select. See - # `packages/stack/vitest.wasm-core.config.ts` for the long form. + # `languages/typescript/packages/stack/vitest.wasm-core.config.ts` for the long form. # # Before `Build stack` deliberately — it reads protect-ffi's output # directly and none of stack's, so a core that changed its credential @@ -636,7 +636,7 @@ jobs: client-key: ${{ secrets.CS_CLIENT_KEY }} client-access-key: ${{ secrets.CS_CLIENT_ACCESS_KEY }} - # The `packages/stack` suites below are the live ones — 120 files, of + # The `languages/typescript/packages/stack` suites below are the live ones — 120 files, of # which only 8 mock `@cipherstash/protect-ffi` — so they load # `index.node`, and the `Build packages` step below does not produce it # (protect-ffi's `build` is `tsc`, deliberately cargo-free). No @@ -648,22 +648,22 @@ jobs: - name: Build the protect-ffi binding uses: ./.github/actions/build-ffi-binding - - name: Create .env file in ./packages/stack/ + - name: Create .env file in ./languages/typescript/packages/stack/ run: | - touch ./packages/stack/.env - echo "CS_WORKSPACE_CRN=${{ vars.CS_WORKSPACE_CRN }}" >> ./packages/stack/.env - echo "CS_CLIENT_ID=${{ vars.CS_CLIENT_ID }}" >> ./packages/stack/.env - echo "CS_CLIENT_KEY=${{ secrets.CS_CLIENT_KEY }}" >> ./packages/stack/.env - echo "CS_CLIENT_ACCESS_KEY=${{ secrets.CS_CLIENT_ACCESS_KEY }}" >> ./packages/stack/.env - echo "DATABASE_URL=postgres://cipherstash:password@localhost:5432/cipherstash" >> ./packages/stack/.env + touch ./languages/typescript/packages/stack/.env + echo "CS_WORKSPACE_CRN=${{ vars.CS_WORKSPACE_CRN }}" >> ./languages/typescript/packages/stack/.env + echo "CS_CLIENT_ID=${{ vars.CS_CLIENT_ID }}" >> ./languages/typescript/packages/stack/.env + echo "CS_CLIENT_KEY=${{ secrets.CS_CLIENT_KEY }}" >> ./languages/typescript/packages/stack/.env + echo "CS_CLIENT_ACCESS_KEY=${{ secrets.CS_CLIENT_ACCESS_KEY }}" >> ./languages/typescript/packages/stack/.env + echo "DATABASE_URL=postgres://cipherstash:password@localhost:5432/cipherstash" >> ./languages/typescript/packages/stack/.env # Build with Node (turbo/tsup need Node), then run tests with Bun - name: Build packages - run: pnpm turbo build --filter './packages/*' + run: pnpm turbo build --filter './languages/typescript/packages/*' - name: Run tests with Bun run: | - for dir in packages/stack; do + for dir in languages/typescript/packages/stack; do if [ -f "$dir/vitest.config.ts" ] || [ -f "$dir/package.json" ]; then echo "--- Testing $dir ---" (cd "$dir" && bunx --bun vitest run) || true diff --git a/.gitignore b/.gitignore index 00af2bf73..9a2898f58 100644 --- a/.gitignore +++ b/.gitignore @@ -7,9 +7,9 @@ mise.local.toml # Three generated WASM declaration files are tracked deliberately. They have to # be re-included from HERE: git cannot re-include a file whose parent directory # is excluded, and the bare `dist` above excludes the directory itself, so a -# negation in packages/protect-ffi/.gitignore has no effect on its own. +# negation in languages/typescript/packages/protect-ffi/.gitignore has no effect on its own. # -# Why they are tracked at all: `packages/stack` value-imports +# Why they are tracked at all: `languages/typescript/packages/stack` value-imports # `@cipherstash/protect-ffi/wasm-inline`, so its declaration build cannot # resolve the module unless these exist. Generating them needs Rust, the wasm32 # target and wasm-pack — which would land on every contributor and every PR job @@ -17,14 +17,14 @@ mise.local.toml # so declarations alone suffice; verified by deleting every `.js` and `.wasm` # under dist/wasm and running stack's build, test:types:dist, test:types and # unit suite green. The runtime output (7.4MB, regenerated each release) is -# still ignored. See packages/protect-ffi/.gitignore for the sibling rules. -!packages/protect-ffi/dist/ -packages/protect-ffi/dist/* -!packages/protect-ffi/dist/wasm/ -packages/protect-ffi/dist/wasm/* -!packages/protect-ffi/dist/wasm/protect_ffi.d.ts -!packages/protect-ffi/dist/wasm/protect_ffi_bg.wasm.d.ts -!packages/protect-ffi/dist/wasm/errors.d.ts +# still ignored. See languages/typescript/packages/protect-ffi/.gitignore for the sibling rules. +!languages/typescript/packages/protect-ffi/dist/ +languages/typescript/packages/protect-ffi/dist/* +!languages/typescript/packages/protect-ffi/dist/wasm/ +languages/typescript/packages/protect-ffi/dist/wasm/* +!languages/typescript/packages/protect-ffi/dist/wasm/protect_ffi.d.ts +!languages/typescript/packages/protect-ffi/dist/wasm/protect_ffi_bg.wasm.d.ts +!languages/typescript/packages/protect-ffi/dist/wasm/errors.d.ts # dependencies /node_modules diff --git a/AGENTS.md b/AGENTS.md index 413ad054e..2f918b550 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -24,7 +24,7 @@ pnpm run build pnpm run build:js ``` -Under the hood this uses Turborepo to build `./packages/*` with each package's `tsup` configuration. +Under the hood this uses Turborepo to build `./languages/typescript/packages/*` with each package's `tsup` configuration. ### Dev/watch @@ -71,36 +71,36 @@ If these variables are missing, tests that require live encryption will fail or ## Repository Layout -- `packages/stack`: Main package (`@cipherstash/stack`) containing the encryption client and all integrations +- `languages/typescript/packages/stack`: Main package (`@cipherstash/stack`) containing the encryption client and all integrations - Subpath exports: `@cipherstash/stack`, `@cipherstash/stack/identity`, `@cipherstash/stack/schema`, `@cipherstash/stack/eql/v3`, `@cipherstash/stack/v3`, `@cipherstash/stack/types`, `@cipherstash/stack/dynamodb`, `@cipherstash/stack/encryption`, `@cipherstash/stack/errors`, `@cipherstash/stack/adapter-kit`, `@cipherstash/stack/wasm-inline`, `@cipherstash/stack/diagnostics` (the Drizzle and Supabase integrations moved to their own packages — see below) -- `packages/cli`: The `stash` CLI — auth, init, encryption schema, and database setup (`stash eql install`). Has its own `AGENTS.md`. -- `packages/wizard`: AI-powered encryption setup (`@cipherstash/wizard`) -- `packages/migrate`: Plaintext-to-encrypted column migration (`@cipherstash/migrate`) — resumable backfill, per-column state -- `packages/stack-prisma`: Prisma Next integration (`@cipherstash/stack-prisma`) — searchable field-level encryption for Postgres. **EQL v3 only**: per-domain constructors (`cipherstash.TextSearch()` / `text()` / `bigIntOrd()` / …) and `cipherstashFromStack` (the `./v3` and `./stack` entries). The EQL v2 surface was removed — the adapter's baseline migration installs the EQL v3 bundle only (works on Supabase as a non-superuser) -- `packages/stack-drizzle`: Drizzle ORM integration (`@cipherstash/stack-drizzle`), depends on `@cipherstash/stack` — **EQL v3 only**, on the package root (the v2 surface was removed and the old `./v3` subpath collapsed into `.`). Split out of `@cipherstash/stack`. -- `packages/stack-supabase`: Supabase integration (`@cipherstash/stack-supabase`), depends on `@cipherstash/stack` — **EQL v3 only**: `encryptedSupabase` is the v3 factory (`encryptedSupabaseV3` remains as a `@deprecated` alias). Split out of `@cipherstash/stack`. Two entries: the package root (native engine, Node) and `./wasm-inline` (WASM engine, edge — ESM-only, and declared-`schemas` only since it carries no Postgres driver). -- `packages/nextjs`: Next.js helpers and Clerk integration (`./clerk` export) -- `packages/utils`: Shared config (`utils/config`) and logger (`utils/logger`) -- `packages/bench`: Performance / index-engagement benchmarks (private, not published) -- `packages/protect-ffi`: Native FFI bindings to the CipherStash Client SDK (`@cipherstash/protect-ffi`) — the Rust core that `packages/stack` encrypts and decrypts through, absorbed from `cipherstash/protectjs-ffi`. Contains a **nested Cargo workspace** (`crates/`) and six per-platform binary packages under `platforms/*`, each published as `@cipherstash/protect-ffi-` and linked here via `workspace:*`. Also holds the repo's live FFI integration suite at `integration-tests/` — a private workspace member (`@cipherstash/ffi-integration-tests`) enrolled by its own literal entry in `pnpm-workspace.yaml`, needing Docker and credentials, and deliberately carrying **no `test` script** so `pnpm test` cannot reach it. See the "Working on protect-ffi" notes below before touching it — its default `test` and `build` are deliberately Rust-free. -- `packages/eql`: The Encrypt Query Language subtree — the SQL bundle that stores and queries encrypted payloads — absorbed from `cipherstash/encrypt-query-language`. **The directory is the subtree root, not the package.** It was imported at a *verbatim prefix* so its repo-root-relative paths (mise tasks, `Doxyfile`, `sync-generated.mjs`) keep resolving, which puts the npm package `@cipherstash/eql` two levels down at `packages/eql/packages/eql` — the same shape as `packages/protect-ffi/platforms/*`, and enrolled the same way, by an explicit `packages/eql/packages/*` glob in `pnpm-workspace.yaml`. The subtree root deliberately carries no `package.json`. Also contains a **nested Cargo workspace** at `packages/eql/crates/` (`eql-bindings`, published in lockstep with the npm package, plus `eql-domains` / `eql-codegen` / `eql-tests-macros`, which are not), a SQLx test crate at `packages/eql/tests/sqlx`, an ~900-line `mise.toml` task surface, its own `AGENTS.md`, and `docs/`. See the "Working on EQL" notes below before touching it. +- `languages/typescript/packages/cli`: The `stash` CLI — auth, init, encryption schema, and database setup (`stash eql install`). Has its own `AGENTS.md`. +- `languages/typescript/packages/wizard`: AI-powered encryption setup (`@cipherstash/wizard`) +- `languages/typescript/packages/migrate`: Plaintext-to-encrypted column migration (`@cipherstash/migrate`) — resumable backfill, per-column state +- `languages/typescript/packages/stack-prisma`: Prisma Next integration (`@cipherstash/stack-prisma`) — searchable field-level encryption for Postgres. **EQL v3 only**: per-domain constructors (`cipherstash.TextSearch()` / `text()` / `bigIntOrd()` / …) and `cipherstashFromStack` (the `./v3` and `./stack` entries). The EQL v2 surface was removed — the adapter's baseline migration installs the EQL v3 bundle only (works on Supabase as a non-superuser) +- `languages/typescript/packages/stack-drizzle`: Drizzle ORM integration (`@cipherstash/stack-drizzle`), depends on `@cipherstash/stack` — **EQL v3 only**, on the package root (the v2 surface was removed and the old `./v3` subpath collapsed into `.`). Split out of `@cipherstash/stack`. +- `languages/typescript/packages/stack-supabase`: Supabase integration (`@cipherstash/stack-supabase`), depends on `@cipherstash/stack` — **EQL v3 only**: `encryptedSupabase` is the v3 factory (`encryptedSupabaseV3` remains as a `@deprecated` alias). Split out of `@cipherstash/stack`. Two entries: the package root (native engine, Node) and `./wasm-inline` (WASM engine, edge — ESM-only, and declared-`schemas` only since it carries no Postgres driver). +- `languages/typescript/packages/nextjs`: Next.js helpers and Clerk integration (`./clerk` export) +- `languages/typescript/packages/utils`: Shared config (`utils/config`) and logger (`utils/logger`) +- `languages/typescript/packages/bench`: Performance / index-engagement benchmarks (private, not published) +- `languages/typescript/packages/protect-ffi`: Native FFI bindings to the CipherStash Client SDK (`@cipherstash/protect-ffi`) — the Rust core that `languages/typescript/packages/stack` encrypts and decrypts through, absorbed from `cipherstash/protectjs-ffi`. Contains a **nested Cargo workspace** (`crates/`) and six per-platform binary packages under `platforms/*`, each published as `@cipherstash/protect-ffi-` and linked here via `workspace:*`. Also holds the repo's live FFI integration suite at `integration-tests/` — a private workspace member (`@cipherstash/ffi-integration-tests`) enrolled by its own literal entry in `pnpm-workspace.yaml`, needing Docker and credentials, and deliberately carrying **no `test` script** so `pnpm test` cannot reach it. See the "Working on protect-ffi" notes below before touching it — its default `test` and `build` are deliberately Rust-free. +- `packages/eql`: The Encrypt Query Language subtree — the SQL bundle that stores and queries encrypted payloads — absorbed from `cipherstash/encrypt-query-language`. **The directory is the subtree root, not the package.** It was imported at a *verbatim prefix* so its repo-root-relative paths (mise tasks, `Doxyfile`, `sync-generated.mjs`) keep resolving, which puts the npm package `@cipherstash/eql` two levels down at `packages/eql/packages/eql` — the same shape as `languages/typescript/packages/protect-ffi/platforms/*`, and enrolled the same way, by an explicit `packages/eql/packages/*` glob in `pnpm-workspace.yaml`. The subtree root deliberately carries no `package.json`. Also contains a **nested Cargo workspace** at `packages/eql/crates/` (`eql-bindings`, published in lockstep with the npm package, plus `eql-domains` / `eql-codegen` / `eql-tests-macros`, which are not), a SQLx test crate at `packages/eql/tests/sqlx`, an ~900-line `mise.toml` task surface, its own `AGENTS.md`, and `docs/`. See the "Working on EQL" notes below before touching it. **Repository ownership:** EQL now lives in `cipherstash/stack`. File and update EQL issues in this repository, never in the historical `cipherstash/encrypt-query-language` repository. Old upstream issue and PR links are provenance only. - `e2e/*`: Cross-package end-to-end tests (package managers, supply chain, Prisma example README) -- `examples/*`: Working apps (basic, prisma, supabase-worker) +- `languages/typescript/examples/*`: Working apps (basic, prisma, supabase-worker) - `docs/plans/*`: Internal design plans. User-facing documentation lives at https://cipherstash.com/docs (not in this repo). - `skills/*`: Agent skills (`stash-cli`, `stash-encryption`, `stash-indexing`, `stash-deployment`, `stash-zerokms`, `stash-auth`, `stash-postgres`, `stash-edge`, `stash-drizzle`, `stash-dynamodb`, `stash-supabase`, `stash-prisma`, `stash-managed-platforms`, `stash-supply-chain-security`) ## Working on protect-ffi -`packages/protect-ffi` carries one of this repo's two Cargo workspaces (the +`languages/typescript/packages/protect-ffi` carries one of this repo's two Cargo workspaces (the other is `packages/eql/crates`), and its scripts are split so a Rust toolchain stays optional for everyone else. - **The default `test` and `build` never invoke cargo.** Root `pnpm test` runs - `turbo test --filter './packages/**'`, which reaches this package — so a cargo + `turbo test --filter './languages/typescript/packages/**'`, which reaches this package — so a cargo process on that path is a Rust toolchain on every contributor's machine. `test` is the JS chain; `build` is `tsc`. - **CI does build the binding, in the jobs that need it.** That is the limit of @@ -125,7 +125,7 @@ stays optional for everyone else. **`--locked` is on the CHECK and deliberately not on the builds.** Nothing in this repo passed it at all until the #915 follow-up, and the bill came due through `sync-lockstep-versions.mjs`: it rewrites `eql-bindings`'s crate - version on every lockstep bump, `packages/protect-ffi` depends on that crate + version on every lockstep bump, `languages/typescript/packages/protect-ffi` depends on that crate by path, so its `Cargo.lock` records the version — and nothing updated it. After the 3.0.5 bump `cargo metadata --locked` exited 101 while every cargo command in CI regenerated the lock in memory, built against the regenerated @@ -210,7 +210,7 @@ stays optional for everyone else. ### The `integration-tests/` suite -`packages/protect-ffi/integration-tests/` is 19 files of **live** coverage — +`languages/typescript/packages/protect-ffi/integration-tests/` is 19 files of **live** coverage — encrypt/decrypt, lock context, keysets, JS auth strategies, JSON SteVec, Postgres (EQL v2 *and* v3), and a WASM round trip — and it is the only place several of those paths are exercised at all. It needs three things a normal @@ -218,7 +218,7 @@ several of those paths are exercised at all. It needs three things a normal EQL versions installed** in the database. - **It is a pnpm workspace member, and `pnpm test` must never reach it.** Named - literally in `pnpm-workspace.yaml` (the `packages/*` glob is one level deep and + literally in `pnpm-workspace.yaml` (the `languages/typescript/packages/*` glob is one level deep and stops short of it), so its dependencies come from the repo lockfile: `@cipherstash/eql` at `workspace:^`, `@cipherstash/protect-ffi` at `workspace:*`, `@cipherstash/auth` / `vitest` / `typescript` from @@ -228,7 +228,7 @@ EQL versions installed** in the database. EMITS it — and it would have disagreed in a database, not in CI. The cost of membership: root `pnpm test` is `turbo test --filter - './packages/**'`, which now reaches this package. It is kept out by **naming no + './languages/typescript/packages/**'`, which now reaches this package. It is kept out by **naming no live script after a turbo task** — the suite's runners are `vitest:live` and `vitest:live:coverage`, which `turbo.json` knows nothing about. `test` is the obvious trap and `test:integration` is the less obvious one (a real turbo task, @@ -243,7 +243,7 @@ EQL versions installed** in the database. fixtures are compiled too — one of them is a real `AccessKeyStrategy` call site, and a `tests/**/*.ts` scope would leave it checked by nothing but the path-filtered credentialed job. -- **Run it locally** from `packages/protect-ffi`: +- **Run it locally** from `languages/typescript/packages/protect-ffi`: ```bash mise run setup # pnpm install, docker compose up, EQL v2 + v3 @@ -284,7 +284,7 @@ EQL versions installed** in the database. - **`src/integrationSuiteCi.test.ts` asserts a root workflow still runs it.** The suite ran on every upstream PR and then ran *nowhere* for the whole absorption, because the workflow that drove it was deposited under - `packages/protect-ffi/.github/` — a directory GitHub never reads. That test is + `languages/typescript/packages/protect-ffi/.github/` — a directory GitHub never reads. That test is what stops it going quiet again, and it deliberately scans only the repo-root workflow directory. @@ -300,11 +300,11 @@ monorepo, which is where the silent failures are. subtree root has no `package.json` by design, so a tool that globs one level under `packages/` selects the root — a directory with no manifest and no scripts — and not the package. That is why root `pnpm test` is - `turbo test --filter './packages/**'` and not `'./packages/*'`: under the + `turbo test --filter './languages/typescript/packages/**'` and not `'./languages/typescript/packages/*'`: under the one-level filter the task graph contained `@cipherstash/eql#build` (pulled in transitively by its consumers) and **no `#test` at all**, so its Vitest suite ran nowhere while CI stayed green. `build` can stay one-level because - consumers pull it through `^build`. Anything else that walks `packages/*` needs + consumers pull it through `^build`. Anything else that walks `languages/typescript/packages/*` needs the same treatment — `scripts/lint-typecheck-scope.mjs` already carries the two nested roots explicitly. - **Anything invoking a mise task must run with `working_directory: @@ -476,7 +476,7 @@ monorepo, which is where the silent failures are. changes what the whole EQL CI surface compiles against, and with the skip in place the release-stopper is closed without it. If wanted, the pin belongs upstream and arrives by subtree pull. -- **`eql-bindings` resolves by path from `packages/protect-ffi`, never from +- **`eql-bindings` resolves by path from `languages/typescript/packages/protect-ffi`, never from crates.io**, and `scripts/lint-no-eql-registry-pins.mjs` (`pnpm run lint:eql-pins`) is what keeps it that way. The two halves of EQL are the Rust that EMITS a payload and the SQL that STORES and queries one; a registry pin @@ -488,7 +488,7 @@ monorepo, which is where the silent failures are. effect). It exits **2**, not 0, when its own configuration has gone stale — a source it could not read, a declaration it expected and no longer sees, or an exemption excusing nothing. There are **no exemptions today**: the only one - there had ever been (`packages/protect-ffi/integration-tests`, which installed + there had ever been (`languages/typescript/packages/protect-ffi/integration-tests`, which installed with `npm ci` and could not take a `workspace:` specifier) was retired when that directory joined the pnpm workspace, and the guard's own staleness rule — keyed on "excuses nothing", not "names nothing" — is what forced it out in the @@ -572,7 +572,7 @@ monorepo, which is where the silent failures are. functions the version it reports does not define. The CLI now refuses a bundle whose bytes do not hash to its own release - manifest (`packages/cli/src/installer/bundle-digest.ts`), but that catches a + manifest (`languages/typescript/packages/cli/src/installer/bundle-digest.ts`), but that catches a corrupt or tampered `node_modules`, **not** this — a frozen-package skew regenerates the manifest alongside the SQL, so the two agree locally. The release gate is still the only thing that notices. It `npm pack`s the frozen @@ -602,9 +602,9 @@ monorepo, which is where the silent failures are. `skills/*/SKILL.md` are **published artifacts, not internal notes.** Treat a wrong sentence in one of them the way you'd treat a wrong line of code: -- `packages/cli/tsup.config.ts` copies `skills/` into `dist/skills/`, so they ship +- `languages/typescript/packages/cli/tsup.config.ts` copies `skills/` into `dist/skills/`, so they ship inside the `stash` npm tarball (and the `@cipherstash/wizard` one). -- `installSkills()` (`packages/cli/src/commands/init/lib/install-skills.ts`) copies the +- `installSkills()` (`languages/typescript/packages/cli/src/commands/init/lib/install-skills.ts`) copies the per-integration set into the user's `.claude/skills/` or `.codex/skills/` at handoff time. - `readBundledSkill()` inlines a skill's body into the user's `AGENTS.md` for editor agents (Cursor / Windsurf / Cline), and as the Codex fallback for skills that could @@ -618,26 +618,26 @@ nothing type-checks them, and the damage lands in a customer's repo, not ours. | If you change… | Check | |---|---| -| `packages/cli` commands, flags, or prompts | `skills/stash-cli` | -| `packages/stack` encryption API, schema builders, subpath exports | `skills/stash-encryption` | +| `languages/typescript/packages/cli` commands, flags, or prompts | `skills/stash-cli` | +| `languages/typescript/packages/stack` encryption API, schema builders, subpath exports | `skills/stash-encryption` | | Drizzle / Supabase / Prisma Next / DynamoDB integrations | `skills/stash-drizzle`, `skills/stash-supabase`, `skills/stash-prisma`, `skills/stash-dynamodb` | -| The rollout/cutover lifecycle (`packages/migrate`, `stash encrypt *`) | `skills/stash-encryption` and `skills/stash-cli` | +| The rollout/cutover lifecycle (`languages/typescript/packages/migrate`, `stash encrypt *`) | `skills/stash-encryption` and `skills/stash-cli` | | The deploy sequencing / deploy-gate story, `stash env`, or platform-specific deployment guidance | `skills/stash-deployment` | | The managed AI platform path (Lovable, v0, Bolt, Replit) — headless auth, non-`postgres` roles, PostgREST limits | `skills/stash-managed-platforms` | | The `@cipherstash/eql` pin, `eql install`/`eql migration` behaviour, or index-related SQL guidance | `skills/stash-indexing` | | The EQL operator/domain surface (`eql_v3.query_*` casts, predicate forms) | `skills/stash-postgres` | | The keyset/client model (`config.keyset`, grants, the ZeroKMS access story) | `skills/stash-zerokms` — the canonical source; other skills should point here rather than restate it | | Auth strategies (`config.authStrategy`), the `CS_*` variables, lock context, `stash env` / `auth login` behaviour | `skills/stash-auth` — the canonical source; other skills should point here rather than restate it | -| `packages/stack/src/wasm-inline.ts`, the WASM entry's exports, or `stash env` | `skills/stash-edge` | +| `languages/typescript/packages/stack/src/wasm-inline.ts`, the WASM entry's exports, or `stash env` | `skills/stash-edge` | | pnpm config, CI workflows, dependency policy | `skills/stash-supply-chain-security` | -| The durable agent rules themselves | `packages/cli/src/commands/init/doctrine/AGENTS-doctrine.md` | +| The durable agent rules themselves | `languages/typescript/packages/cli/src/commands/init/doctrine/AGENTS-doctrine.md` | For CLI changes there is a mechanical check — the command registry is the source of truth, so diff the skill against it rather than proofreading: ```bash pnpm --filter stash build -node packages/cli/dist/bin/stash.js manifest --json +node languages/typescript/packages/cli/dist/bin/stash.js manifest --json ``` Every command and flag named in `skills/stash-cli/SKILL.md` must resolve against that @@ -719,9 +719,9 @@ pnpm changeset:publish - Import `dotenv/config` at the top when tests need environment variables. - Prefer testing via the public API. Avoid reaching into private internals. - Some tests have larger timeouts (e.g., 30s) to accommodate network calls. -- `packages/cli` has a second suite — pty-driven E2E tests under - `packages/cli/tests/e2e/**` run via `pnpm --filter stash - test:e2e` (requires a build). See `packages/cli/AGENTS.md` for when to +- `languages/typescript/packages/cli` has a second suite — pty-driven E2E tests under + `languages/typescript/packages/cli/tests/e2e/**` run via `pnpm --filter stash + test:e2e` (requires a build). See `languages/typescript/packages/cli/AGENTS.md` for when to add or update them. ## Bundling and Deployment Notes @@ -733,12 +733,12 @@ pnpm changeset:publish ## Adding Features Safely (LLM checklist) -1. Identify the target package(s) in `packages/*` and confirm whether changes affect public APIs or payload shapes. -2. If modifying `packages/stack` encryption operations or `EncryptionClient`, ensure: +1. Identify the target package(s) in `languages/typescript/packages/*` and confirm whether changes affect public APIs or payload shapes. +2. If modifying `languages/typescript/packages/stack` encryption operations or `EncryptionClient`, ensure: - The Result contract and error type strings remain stable. - `.withLockContext()` remains available for affected operations. - ESM/CJS exports continue to work (don't break `require`). -3. If changing schema behavior (`packages/stack` schema builders, `@cipherstash/stack/schema`), update type definitions and ensure validation still works in `EncryptionClient.init`. +3. If changing schema behavior (`languages/typescript/packages/stack` schema builders, `@cipherstash/stack/schema`), update type definitions and ensure validation still works in `EncryptionClient.init`. 4. Add/extend tests in the same package. For features that require live credentials, guard with env checks or provide mock-friendly paths. 5. Run: - `pnpm run code:fix` @@ -786,7 +786,7 @@ pnpm changeset:publish ## Useful Links - `README.md` for quickstart and feature overview -- `packages/cli/AGENTS.md` for CLI-specific guidance +- `languages/typescript/packages/cli/AGENTS.md` for CLI-specific guidance - `e2e/README.md` for the cross-package E2E suite - `skills/*/SKILL.md` for per-integration agent guides - User-facing docs (concepts, reference, how-to) live on the docs site: diff --git a/CLAUDE.md b/CLAUDE.md index cd3c0c688..0f5849965 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -38,7 +38,7 @@ because both fail silently — nothing in CI catches either: ## Package-specific notes -`packages/cli` has its own `AGENTS.md` covering the two Vitest configs (unit vs. +`languages/typescript/packages/cli` has its own `AGENTS.md` covering the two Vitest configs (unit vs. the pty-driven e2e suite) and when each needs to run. Read it before touching -`packages/cli/src/bin/main.ts`, `packages/cli/src/messages.ts`, or the command -registry at `packages/cli/src/cli/registry.ts`. +`languages/typescript/packages/cli/src/bin/main.ts`, `languages/typescript/packages/cli/src/messages.ts`, or the command +registry at `languages/typescript/packages/cli/src/cli/registry.ts`. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index c08c7e95f..94634880f 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -27,7 +27,7 @@ This is a [Turborepo](https://turbo.build/) monorepo managed with [pnpm](https:/ See [AGENTS.md](./AGENTS.md) for a detailed layout, key APIs, environment variables, and gotchas — it's written for coding agents but is the most complete developer reference in the repo. -### `packages/stack` +### `languages/typescript/packages/stack` **@cipherstash/stack** is the main package published to npm. It contains the encryption client and all integrations (Drizzle, Supabase, DynamoDB, secrets, identity). This is likely where you'll spend most of your time. @@ -62,7 +62,7 @@ pnpm install pnpm run build ``` -This triggers Turborepo's build pipeline, compiling each package in `packages/*` and linking them locally so the examples can reference them. +This triggers Turborepo's build pipeline, compiling each package in `languages/typescript/packages/*` and linking them locally so the examples can reference them. ### 4. Run an Example App diff --git a/README.md b/README.md index 060776f47..d3d693220 100644 --- a/README.md +++ b/README.md @@ -383,7 +383,7 @@ disclosure, see [SECURITY.md][security-policy]. [MIT licensed][license]. [benches]: https://github.com/cipherstash/benches [eql]: https://github.com/cipherstash/encrypt-query-language [discord]: https://discord.gg/5qwXUFb6PB -[examples]: https://github.com/cipherstash/stack/tree/main/examples +[examples]: https://github.com/cipherstash/stack/tree/main/languages/typescript/examples [contribute]: https://github.com/cipherstash/stack/blob/main/CONTRIBUTING.md [security-policy]: https://github.com/cipherstash/stack/blob/main/SECURITY.md [license]: https://github.com/cipherstash/stack/blob/main/LICENSE.md diff --git a/biome.json b/biome.json index 4e94394bc..f20e4bb71 100644 --- a/biome.json +++ b/biome.json @@ -7,9 +7,9 @@ "!**/.turbo/", "!**/dist", "!**/nix/store", - "!packages/protect-ffi/lib", - "!packages/protect-ffi/target", - "!packages/protect-ffi/src/eql-v3-types", + "!languages/typescript/packages/protect-ffi/lib", + "!languages/typescript/packages/protect-ffi/target", + "!languages/typescript/packages/protect-ffi/src/eql-v3-types", "!packages/eql/crates/eql-bindings/bindings", "!packages/eql/crates/eql-bindings/schema", "!packages/eql/packages/eql/src/generated", @@ -53,7 +53,7 @@ { "includes": [ "**/src/**", - "examples/**", + "languages/typescript/examples/**", "!**/__tests__/**", "!**/*.test.ts", "!**/*.test-d.ts", diff --git a/docs/agents/issue-tracker.md b/docs/agents/issue-tracker.md index c2acf9dfb..4bd5ecdae 100644 --- a/docs/agents/issue-tracker.md +++ b/docs/agents/issue-tracker.md @@ -7,7 +7,7 @@ operations. All work present in this monorepo is tracked in `cipherstash/stack`, including the absorbed EQL source under `packages/eql` and protect-ffi under -`packages/protect-ffi`. Their former upstream repositories are historical +`languages/typescript/packages/protect-ffi`. Their former upstream repositories are historical sources, not active issue trackers. Never create, move, or update an issue in `cipherstash/encrypt-query-language` or `cipherstash/protectjs-ffi` for work in this tree. Create it in `cipherstash/stack` and link historical upstream issues diff --git a/docs/eql-v3-ord-term-ordering-defect.md b/docs/eql-v3-ord-term-ordering-defect.md index 0c63425e4..d0e524927 100644 --- a/docs/eql-v3-ord-term-ordering-defect.md +++ b/docs/eql-v3-ord-term-ordering-defect.md @@ -124,7 +124,7 @@ separate design spec plus the re-vendored OPE bundle, not as part of this change ## What we changed in this repo -- `packages/stack/__tests__/schema-v3-pg.test.ts`: corrected the misleading +- `languages/typescript/packages/stack/__tests__/schema-v3-pg.test.ts`: corrected the misleading comment on the range test and added an explicit ORE-total-order proof using pairwise `eql_v3.lt` (the only ORE-correct path on the current bundle), so the guarantee is asserted positively rather than merely avoided. These assertions diff --git a/docs/query-api-walkthrough.md b/docs/query-api-walkthrough.md index ac44297f9..1c7419f90 100644 --- a/docs/query-api-walkthrough.md +++ b/docs/query-api-walkthrough.md @@ -73,5 +73,5 @@ flowchart LR - **Client init:** `EncryptionClient.init()` (`encryption/index.ts:81`) calls FFI `newClient()` once; the returned `Client` handle is passed into every `encryptQuery` call. - **`cipherstashclient`** = the CipherStash Client **Rust SDK**, compiled via Neon into the platform `.node` binary inside `@cipherstash/protect-ffi`. It performs the actual crypto and talks to ZeroKMS. - **Result shape:** `EncryptedQueryResult` (`types.ts:175`); shaped by `formatEncryptedResult(..., returnType)` (`eql` vs raw). -- **Version:** `packages/stack/package.json` pins `@cipherstash/protect-ffi@0.30.0` (`stack-drizzle` and `stack-supabase` pin the same version — they must move in lockstep). -- **Paths:** rows 1–3 and the notes above are relative to `packages/stack/src/`; row 1a is rooted at `packages/`; rows 4–5 are inside the installed `@cipherstash/protect-ffi`. Line numbers drift — search the symbol, don't trust the offset. +- **Version:** `languages/typescript/packages/stack/package.json` pins `@cipherstash/protect-ffi@0.30.0` (`stack-drizzle` and `stack-supabase` pin the same version — they must move in lockstep). +- **Paths:** rows 1–3 and the notes above are relative to `languages/typescript/packages/stack/src/`; row 1a is rooted at `packages/`; rows 4–5 are inside the installed `@cipherstash/protect-ffi`. Line numbers drift — search the symbol, don't trust the offset. diff --git a/e2e/README.md b/e2e/README.md index c3ee77197..1565158d4 100644 --- a/e2e/README.md +++ b/e2e/README.md @@ -24,7 +24,7 @@ pnpm --filter @cipherstash/e2e exec vitest run tests/package-managers.e2e.test.t | --- | --- | | `tests/package-managers.e2e.test.ts` | The `init` providers and the wizard binary render `bunx`/`pnpm dlx`/`yarn dlx`/`npx` based on detected package manager. | | `tests/supply-chain.e2e.test.ts` | Lockfile/registry/CODEOWNERS controls from `skills/stash-supply-chain-security` are still enforced. | -| `tests/prisma-example-readme.e2e.test.ts` | Parses `examples/prisma/README.md`'s "Run it" section and asserts every command (skipping `stash auth login`) exits 0. | +| `tests/prisma-example-readme.e2e.test.ts` | Parses `languages/typescript/examples/prisma/README.md`'s "Run it" section and asserts every command (skipping `stash auth login`) exits 0. | | `tests/skill-map-parity.e2e.test.ts` | The CLI's and the wizard's `SKILL_MAP` install the same skills for each equivalent integration. Lives here because this is the only workspace declaring both packages. | ## Auth-dependent suites diff --git a/e2e/tests/package-managers.e2e.test.ts b/e2e/tests/package-managers.e2e.test.ts index 830fcf753..5c72e810d 100644 --- a/e2e/tests/package-managers.e2e.test.ts +++ b/e2e/tests/package-managers.e2e.test.ts @@ -12,7 +12,10 @@ import type { PackageManager } from '../../packages/cli/src/commands/init/utils. const __dirname = dirname(fileURLToPath(import.meta.url)) const REPO_ROOT = resolve(__dirname, '../..') -const WIZARD_BIN = resolve(REPO_ROOT, 'packages/wizard/dist/bin/wizard.js') +const WIZARD_BIN = resolve( + REPO_ROOT, + 'languages/typescript/packages/wizard/dist/bin/wizard.js', +) const PMS: PackageManager[] = ['npm', 'bun', 'pnpm', 'yarn'] const RUNNER: Record = { @@ -23,8 +26,14 @@ const RUNNER: Record = { } const BIN = { - cli: resolve(REPO_ROOT, 'packages/cli/dist/bin/stash.js'), - wizard: resolve(REPO_ROOT, 'packages/wizard/dist/bin/wizard.js'), + cli: resolve( + REPO_ROOT, + 'languages/typescript/packages/cli/dist/bin/stash.js', + ), + wizard: resolve( + REPO_ROOT, + 'languages/typescript/packages/wizard/dist/bin/wizard.js', + ), // The legacy @cipherstash/protect `stash` bin and the @cipherstash/drizzle // `generate-eql-migration` bin are both gone with their packages // (@cipherstash/stack and @cipherstash/stack-drizzle are the successors). diff --git a/e2e/tests/prisma-example-readme.e2e.test.ts b/e2e/tests/prisma-example-readme.e2e.test.ts index 119422bda..7070a4b23 100644 --- a/e2e/tests/prisma-example-readme.e2e.test.ts +++ b/e2e/tests/prisma-example-readme.e2e.test.ts @@ -14,7 +14,7 @@ import { afterAll, beforeAll, describe, expect, it } from 'vitest' const __dirname = dirname(fileURLToPath(import.meta.url)) const REPO_ROOT = resolve(__dirname, '../..') -const EXAMPLE_DIR = resolve(REPO_ROOT, 'examples/prisma') +const EXAMPLE_DIR = resolve(REPO_ROOT, 'languages/typescript/examples/prisma') const authConfigured = (() => { if (process.env.CS_CLIENT_ID && process.env.CS_CLIENT_KEY) return true @@ -119,7 +119,7 @@ function parseRunItCommands(readme: string): string[] { if (!match) { throw new Error( 'parseRunItCommands: could not locate the bash code fence under `## Run it` in the README. ' + - 'Check examples/prisma/README.md structure (expected `## Run it` heading followed by a ```bash fenced block).', + 'Check languages/typescript/examples/prisma/README.md structure (expected `## Run it` heading followed by a ```bash fenced block).', ) } return match[1]! @@ -160,7 +160,7 @@ const outcomes = new Map() let snapDir: string describe.skipIf(!authConfigured)( - 'examples/prisma README "Run it" walkthrough', + 'languages/typescript/examples/prisma README "Run it" walkthrough', () => { beforeAll(async () => { snapDir = await snapshotTransientOutputs() diff --git a/e2e/tests/supply-chain.e2e.test.ts b/e2e/tests/supply-chain.e2e.test.ts index c9b92d278..5e3b6abcc 100644 --- a/e2e/tests/supply-chain.e2e.test.ts +++ b/e2e/tests/supply-chain.e2e.test.ts @@ -274,7 +274,7 @@ describe('supply chain — pnpm-lock.yaml integrity', () => { }) it('@anthropic-ai/sdk resolves to the peer-pinned patched version (≥ 0.106.0)', () => { - // Not an override but a peer-resolution pin: packages/wizard depends on + // Not an override but a peer-resolution pin: languages/typescript/packages/wizard depends on // @anthropic-ai/sdk@^0.106.0 to force the auto-installed peer of // @anthropic-ai/claude-agent-sdk past the advisory-vulnerable 0.81.0 // (GHSA-p7fg-763f-g4gf). The override-effect test cannot cover a peer @@ -658,7 +658,7 @@ const ignoresAllSemverMajor = (entry: DependabotUpdate): boolean => // // A glob is satisfied by matching AT LEAST ONE directory holding the manifest, // not all of them. `/packages/*` under the npm entry would fail an every-match -// rule against this very tree today: packages/utils/ holds only config/ and +// rule against this very tree today: languages/typescript/packages/utils/ holds only config/ and // logger/, with no package.json of its own. // // Expanded with node:fs `globSync` (Node 22, which package.json engines already @@ -755,7 +755,7 @@ describe('supply chain — automated dependency updates (Dependabot)', () => { // Derived from the filesystem, not from a list of ecosystems we expect — // so the NEXT lockfile someone adds (a new language, a nested manifest) // fails here instead of quietly going unmonitored. Absorbing - // packages/protect-ffi is precisely that event: it brought a 494-crate + // languages/typescript/packages/protect-ffi is precisely that event: it brought a 494-crate // Cargo.lock in-tree, which osv-scanner already scans for known // advisories (`--recursive ./` reaches it) while nothing proposed the // routine version bumps. @@ -763,7 +763,7 @@ describe('supply chain — automated dependency updates (Dependabot)', () => { // Coverage is asserted per ECOSYSTEM, not per directory. Dependabot's npm // entry at `/` follows the pnpm workspace, so it reaches every member's // manifest through the single root `pnpm-lock.yaml`. The one lockfile that - // sat outside that — packages/protect-ffi/integration-tests's own + // sat outside that — languages/typescript/packages/protect-ffi/integration-tests's own // `package-lock.json`, a standalone `npm ci` harness — is gone as of // CIP-3744, and the suite now resolves from the repo lockfile like // everything else. @@ -805,7 +805,7 @@ describe('supply chain — automated dependency updates (Dependabot)', () => { // wrong directory monitors nothing, and fails silently — Dependabot logs // "no manifest found" on a page nobody visits, and the symptom is just an // absence of PRs. Load-bearing for cargo, whose workspace root is - // packages/protect-ffi, not the repo root. + // languages/typescript/packages/protect-ffi, not the repo root. for (const entry of db.updates) { const ecosystem = entry['package-ecosystem'] const manifest = MANIFEST_BY_ECOSYSTEM[ecosystem] diff --git a/e2e/wasm/deno.json b/e2e/wasm/deno.json index 6aabb5f91..262d51fcc 100644 --- a/e2e/wasm/deno.json +++ b/e2e/wasm/deno.json @@ -1,7 +1,7 @@ { "//1": "Deno smoke tests for @cipherstash/stack/wasm-inline and @cipherstash/stack-supabase/wasm-inline. Run `pnpm exec turbo run build --filter @cipherstash/stack --filter @cipherstash/stack-supabase` first so both dist/ trees are fresh.", - "//2": "Everything resolves to files pnpm already installed in the workspace — no `npm:` specifiers, so Deno never re-resolves against the registry. stack is its locally-built dist; auth and protect-ffi are the WASM-inline entries of the exact versions the catalog pinned, reached via stack's own node_modules symlink (`packages/stack/node_modules/@cipherstash/*`). Both entries import only their own relative wasm bindings, so there are no transitive npm deps to resolve. This keeps the versions in lockstep with the catalog automatically (a bump to pnpm-workspace.yaml needs no edit here) and sidesteps Deno 2.9's default 24h npm freshness cooldown, which would otherwise reject a just-published first-party version and block lockstep bumps for a day. The real supply-chain gate is pnpm's `minimumReleaseAge` (see skills/stash-supply-chain-security/), which already exempts first-party @cipherstash packages.", - "//4": "The stack-supabase edge entry imports three of stack's native-free subpaths (adapter-kit, eql/v3, errors) — mapped here because Deno resolves the bare specifiers in the emitted bundle, not because the entry needs anything extra. It imports NO Postgres driver, which packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts asserts against the emitted file; if that ever regressed, this Deno run would fail on an unmapped `pg` specifier.", + "//2": "Everything resolves to files pnpm already installed in the workspace — no `npm:` specifiers, so Deno never re-resolves against the registry. stack is its locally-built dist; auth and protect-ffi are the WASM-inline entries of the exact versions the catalog pinned, reached via stack's own node_modules symlink (`languages/typescript/packages/stack/node_modules/@cipherstash/*`). Both entries import only their own relative wasm bindings, so there are no transitive npm deps to resolve. This keeps the versions in lockstep with the catalog automatically (a bump to pnpm-workspace.yaml needs no edit here) and sidesteps Deno 2.9's default 24h npm freshness cooldown, which would otherwise reject a just-published first-party version and block lockstep bumps for a day. The real supply-chain gate is pnpm's `minimumReleaseAge` (see skills/stash-supply-chain-security/), which already exempts first-party @cipherstash packages.", + "//4": "The stack-supabase edge entry imports three of stack's native-free subpaths (adapter-kit, eql/v3, errors) — mapped here because Deno resolves the bare specifiers in the emitted bundle, not because the entry needs anything extra. It imports NO Postgres driver, which languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts asserts against the emitted file; if that ever regressed, this Deno run would fail on an unmapped `pg` specifier.", "//3": "No --allow-ffi grant. If protect-ffi ever silently fell back to a native binding under Deno, the test would fail on missing FFI permission — this is the WASM guarantee.", "nodeModulesDir": "auto", "tasks": { diff --git a/languages/typescript/examples/basic/README.md b/languages/typescript/examples/basic/README.md index 5704c7912..48a8a9940 100644 --- a/languages/typescript/examples/basic/README.md +++ b/languages/typescript/examples/basic/README.md @@ -22,7 +22,7 @@ pnpm add @cipherstash/stack dotenv > [!NOTE] > `dotenv` is only needed if you are loading credentials from a `.env` file. It is not a dependency of `@cipherstash/stack`. -You can also clone this repo and run the example as-is from `examples/basic` (after `pnpm install` in the repo root and in `examples/basic`). +You can also clone this repo and run the example as-is from `languages/typescript/examples/basic` (after `pnpm install` in the repo root and in `languages/typescript/examples/basic`). ## Configuring the basic example diff --git a/languages/typescript/examples/prisma/test/e2e/README.md b/languages/typescript/examples/prisma/test/e2e/README.md index 2e129ff7d..64a609989 100644 --- a/languages/typescript/examples/prisma/test/e2e/README.md +++ b/languages/typescript/examples/prisma/test/e2e/README.md @@ -13,7 +13,7 @@ This directory hosts the live-Postgres + EQL v3 bundle + ZeroKMS end-to-end harn ## Local setup ```bash -docker compose -f test/e2e/docker-compose.yml up -d # from examples/prisma +docker compose -f test/e2e/docker-compose.yml up -d # from languages/typescript/examples/prisma pnpm --filter @cipherstash/prisma-example test:e2e ``` diff --git a/languages/typescript/examples/prisma/test/e2e/global-setup.ts b/languages/typescript/examples/prisma/test/e2e/global-setup.ts index 9bbd9937b..c42c06513 100644 --- a/languages/typescript/examples/prisma/test/e2e/global-setup.ts +++ b/languages/typescript/examples/prisma/test/e2e/global-setup.ts @@ -23,7 +23,7 @@ * between full-run iterations of the suite. * * No teardown — the container lifecycle is owned by the developer - * (`docker compose down` from `examples/prisma` + * (`docker compose down` from `languages/typescript/examples/prisma` * tears it down explicitly). */ @@ -110,7 +110,7 @@ export default async function setup(): Promise<() => Promise> { pgIsReady, 'Bring it up with:\n' + ' docker compose -f test/e2e/docker-compose.yml up -d\n' + - '(from `examples/prisma`).', + '(from `languages/typescript/examples/prisma`).', ), ) } diff --git a/languages/typescript/packages/bench/__tests__/drizzle/operators.explain.test.ts b/languages/typescript/packages/bench/__tests__/drizzle/operators.explain.test.ts index 546f4fb2c..fc09b4497 100644 --- a/languages/typescript/packages/bench/__tests__/drizzle/operators.explain.test.ts +++ b/languages/typescript/packages/bench/__tests__/drizzle/operators.explain.test.ts @@ -122,7 +122,7 @@ async function tryExplainWhere(name: string, where: SQL): Promise { // even with the hmac index available the planner correctly chooses a seq // scan because it would re-touch nearly every row. We record their plans for // the investigation log but don't assert — the SQL shape is what matters, -// and that's covered by the unit tests under packages/stack. +// and that's covered by the unit tests under languages/typescript/packages/stack. describe('#421: equality and array operators', () => { it('eq engages the hmac functional index', async () => { const plan = await explainWhere( diff --git a/languages/typescript/packages/bench/vitest.config.ts b/languages/typescript/packages/bench/vitest.config.ts index 28c1fc983..2a6fd347c 100644 --- a/languages/typescript/packages/bench/vitest.config.ts +++ b/languages/typescript/packages/bench/vitest.config.ts @@ -9,7 +9,7 @@ export default defineConfig({ globalSetup: ['./src/harness/global-setup.ts'], // `@cipherstash/test-kit` is consumed as unbuilt TypeScript source, so it // must not be externalized — same reason the integration suites carry this - // (`packages/test-kit/src/integration/config.ts`). + // (`languages/typescript/packages/test-kit/src/integration/config.ts`). server: { deps: { inline: [/packages\/test-kit/] } }, testTimeout: 300_000, hookTimeout: 300_000, diff --git a/languages/typescript/packages/cli/AGENTS.md b/languages/typescript/packages/cli/AGENTS.md index 1208997ad..7a222c60a 100644 --- a/languages/typescript/packages/cli/AGENTS.md +++ b/languages/typescript/packages/cli/AGENTS.md @@ -35,11 +35,11 @@ modules import workspace packages that publish `./dist` only, so an unbuilt workspace fails at collection with `Failed to resolve entry for package …` rather than at an assertion. `vitest.config.ts` aliases `@cipherstash/migrate` to its source to remove one such coupling; `@cipherstash/stack` remains, reached -via `packages/migrate/src/backfill.ts` and a direct import in -`init/lib/__tests__/introspect.test.ts`. Deleting `packages/stack/dist` fails 10 +via `languages/typescript/packages/migrate/src/backfill.ts` and a direct import in +`init/lib/__tests__/introspect.test.ts`. Deleting `languages/typescript/packages/stack/dist` fails 10 files. Closing it needs `vitest.shared.ts`'s `stackSourceAlias`, which cannot be -spread into this config: its `'@/'` points at `packages/stack/src` while this -package's points at `packages/cli/src`, and a flat alias map admits only one — +spread into this config: its `'@/'` points at `languages/typescript/packages/stack/src` while this +package's points at `languages/typescript/packages/cli/src`, and a flat alias map admits only one — spread it after and stack's entry clobbers the CLI's, spread it before and the CLI's breaks stack's own source imports (#787 review). @@ -98,7 +98,7 @@ exercise the same code paths. encryption row and exit 1, and `doctor` offers the recovery it has for an npm user — reinstall `node_modules` — which does not fix this. **That is a missing binding, not a broken checkout.** Build one (needs a Rust toolchain), - from `packages/protect-ffi`: + from `languages/typescript/packages/protect-ffi`: ```bash mise run build:debug # or: pnpm --filter @cipherstash/protect-ffi build:native diff --git a/languages/typescript/packages/cli/package.json b/languages/typescript/packages/cli/package.json index 6ee7a3cda..57d4ece66 100644 --- a/languages/typescript/packages/cli/package.json +++ b/languages/typescript/packages/cli/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/cli" + "directory": "languages/typescript/packages/cli" }, "license": "MIT", "author": "CipherStash ", diff --git a/languages/typescript/packages/cli/scripts/e2e-encrypt.sh b/languages/typescript/packages/cli/scripts/e2e-encrypt.sh index 0e027a80b..893f51ee4 100755 --- a/languages/typescript/packages/cli/scripts/e2e-encrypt.sh +++ b/languages/typescript/packages/cli/scripts/e2e-encrypt.sh @@ -5,7 +5,7 @@ # `stash_e2e_test`. Requires CipherStash credentials in the environment # for the actual encryption step (CS_CLIENT_ACCESS_KEY etc). # -# Usage: bash packages/cli/scripts/e2e-encrypt.sh +# Usage: bash languages/typescript/packages/cli/scripts/e2e-encrypt.sh set -euo pipefail diff --git a/languages/typescript/packages/cli/src/__tests__/installer.test.ts b/languages/typescript/packages/cli/src/__tests__/installer.test.ts index 81507a4bb..9bb3a31c5 100644 --- a/languages/typescript/packages/cli/src/__tests__/installer.test.ts +++ b/languages/typescript/packages/cli/src/__tests__/installer.test.ts @@ -819,7 +819,7 @@ describe('Supabase grants split', () => { '@/installer/grants.ts' ) // The exact string the CLI shipped before the immediate/owner-scoped - // split. `packages/stack-supabase/integration/grants.integration.test.ts` + // split. `languages/typescript/packages/stack-supabase/integration/grants.integration.test.ts` // live-proves this block, so it must not drift. expect( SUPABASE_PERMISSIONS_SQL_V3, diff --git a/languages/typescript/packages/cli/src/__tests__/module-error-classification.test.ts b/languages/typescript/packages/cli/src/__tests__/module-error-classification.test.ts index 78ece773d..41debfc65 100644 --- a/languages/typescript/packages/cli/src/__tests__/module-error-classification.test.ts +++ b/languages/typescript/packages/cli/src/__tests__/module-error-classification.test.ts @@ -119,10 +119,10 @@ describe('isPackageMissing', () => { // interrupted install, a partially built workspace) as one the user has // simply not installed yet: a green row, and no reason to look further. // - // The path the CLI's own resolution produces — `packages/cli/node_modules/ + // The path the CLI's own resolution produces — `languages/typescript/packages/cli/node_modules/ // @cipherstash/stack/…`, the workspace's stand-in for a user's install. // Not `require.resolve('@cipherstash/stack/package.json')`: that returns - // the symlink's REAL path (`packages/stack/…`), which drops the scoped + // the symlink's REAL path (`languages/typescript/packages/stack/…`), which drops the scoped // name the bug turns on. Node raises the error either way; only the path // handed to it is composed here. // diff --git a/languages/typescript/packages/cli/src/__tests__/rewrite-migrations.test.ts b/languages/typescript/packages/cli/src/__tests__/rewrite-migrations.test.ts index 0eda4a28d..5e44dc5eb 100644 --- a/languages/typescript/packages/cli/src/__tests__/rewrite-migrations.test.ts +++ b/languages/typescript/packages/cli/src/__tests__/rewrite-migrations.test.ts @@ -184,7 +184,7 @@ describe('rewriteEncryptedAlterColumns', () => { }) // Every concrete `eql_v3_*` domain shipped by `@cipherstash/stack/eql/v3` - // (see `packages/stack/src/eql/v3/columns.ts`). Eight scalar bases carry the + // (see `languages/typescript/packages/stack/src/eql/v3/columns.ts`). Eight scalar bases carry the // four storage/eq/ord flavours; text adds `_match`/`_search`; boolean and json // stand alone. const V3_SCALAR_BASES = [ diff --git a/languages/typescript/packages/cli/src/bin/main.ts b/languages/typescript/packages/cli/src/bin/main.ts index b4398625d..a74b99a0e 100644 --- a/languages/typescript/packages/cli/src/bin/main.ts +++ b/languages/typescript/packages/cli/src/bin/main.ts @@ -355,7 +355,7 @@ async function runDbCommand( values: Record, ) { // Plumbed through every db subcommand so the URL resolver can use it as - // an explicit override. See packages/cli/src/config/database-url.ts. + // an explicit override. See languages/typescript/packages/cli/src/config/database-url.ts. const databaseUrl = values['database-url'] switch (sub) { diff --git a/languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts b/languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts index adac6487f..7ba11d5b6 100644 --- a/languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts +++ b/languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts @@ -1248,7 +1248,7 @@ function renderSafeAlter( // the TABLE's schema (from a pgSchema() table) and says nothing about where // the domain lives. If EQL ever supports installing into a non-`public` // schema, this needs the install schema threaded in, here and in the - // sibling `packages/wizard/src/lib/rewrite-migrations.ts`. + // sibling `languages/typescript/packages/wizard/src/lib/rewrite-migrations.ts`. `ALTER TABLE ${qualifiedTable} ADD COLUMN "${encrypted}" "public"."${domain}";`, ].join('\n') } diff --git a/languages/typescript/packages/cli/src/commands/eql/__tests__/validate.test.ts b/languages/typescript/packages/cli/src/commands/eql/__tests__/validate.test.ts index 1c7a1487d..01dc98503 100644 --- a/languages/typescript/packages/cli/src/commands/eql/__tests__/validate.test.ts +++ b/languages/typescript/packages/cli/src/commands/eql/__tests__/validate.test.ts @@ -592,7 +592,7 @@ describe('database rules', () => { /** * `@cipherstash/migrate` accepts `schema.table` (`splitTableName` in - * `packages/migrate/src/version.ts`), so the spelling reaches validate — but + * `languages/typescript/packages/migrate/src/version.ts`), so the spelling reaches validate — but * the literal `'app.users'` is compared whole against a bare * `information_schema.columns.table_name`, matches nothing, and was reported * as a missing table. Saying nothing could be checked is honest; saying the diff --git a/languages/typescript/packages/cli/src/commands/eql/validate.ts b/languages/typescript/packages/cli/src/commands/eql/validate.ts index 33d58c717..34347ce8e 100644 --- a/languages/typescript/packages/cli/src/commands/eql/validate.ts +++ b/languages/typescript/packages/cli/src/commands/eql/validate.ts @@ -422,7 +422,7 @@ function unreachableTableIssue( // reads compare it whole against a bare `relname` / `table_name` — so it // matches nothing anywhere and was reported as an unapplied migration. // `@cipherstash/migrate` does accept the spelling (`splitTableName` in - // `packages/migrate/src/version.ts`, first dot wins), so the toolchain + // `languages/typescript/packages/migrate/src/version.ts`, first dot wins), so the toolchain // disagrees with itself. Resolving it properly needs a schema-aware column // read, which is `fetchPhysicalColumns` — shared with `encrypt status` and // scoped to `current_schema()` by construction. Splitting the name here and diff --git a/languages/typescript/packages/cli/src/commands/init/__tests__/utils-codegen.test.ts b/languages/typescript/packages/cli/src/commands/init/__tests__/utils-codegen.test.ts index 68e134514..11bb1c04c 100644 --- a/languages/typescript/packages/cli/src/commands/init/__tests__/utils-codegen.test.ts +++ b/languages/typescript/packages/cli/src/commands/init/__tests__/utils-codegen.test.ts @@ -77,7 +77,7 @@ describe('generateClientFromSchemas', () => { // above only exercise 3 of 13 domains, so every domain is proven to emit // verbatim through both generators. `V3Domain` and `DataType` are finite closed // unions, so enumeration is complete — a fast-check property would sample the -// same finite set and add nothing (and `packages/cli` has no fast-check dep). +// same finite set and add nothing (and `languages/typescript/packages/cli` has no fast-check dep). const ALL_DOMAINS: import('../types.js').V3Domain[] = [ 'Text', 'TextEq', diff --git a/languages/typescript/packages/cli/src/commands/init/lib/__tests__/introspect.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/introspect.test.ts index 1efca50e3..ca5d0a076 100644 --- a/languages/typescript/packages/cli/src/commands/init/lib/__tests__/introspect.test.ts +++ b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/introspect.test.ts @@ -107,7 +107,7 @@ describe('defaultDomain', () => { // The marker used to be `udt_name === 'eql_v2_encrypted'` alone. v3 is the // default generation and its columns carry `eql_v3_*` domains, so on the // default path an already-encrypted column was reported as plaintext: shown -// with its `dataType` hint and left unticked. `packages/wizard` already made +// with its `dataType` hint and left unticked. `languages/typescript/packages/wizard` already made // this call, and its comment names the consequence — misreporting encrypted // columns as plaintext lets an agent clobber real ciphertext. describe('isEqlEncryptedDomain', () => { @@ -318,7 +318,7 @@ describe('v3 domain drift guard', () => { // This asserts every offered domain resolves to a real factory, so a rename // or removal in stack fails here (in CI) rather than silently. It is the // enforced counterpart to the reviewer's "avoid drift" concern; a plain type - // alias is not enough because `packages/cli` has no `tsc --noEmit` step (its + // alias is not enough because `languages/typescript/packages/cli` has no `tsc --noEmit` step (its // build is tsup + Biome + vitest, none of which check an unused type). it('every domain the picker can offer is a real @cipherstash/stack/eql/v3 factory', () => { const dataTypes: DataType[] = [ diff --git a/languages/typescript/packages/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts index 85281d147..5e1759e76 100644 --- a/languages/typescript/packages/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts +++ b/languages/typescript/packages/cli/src/commands/init/lib/__tests__/setup-prompt.test.ts @@ -160,7 +160,7 @@ describe('renderSetupPrompt — orient + route (implement mode)', () => { expect(out).not.toContain('{ table, column, queryType }') }) - // `packages/cli` builds with tsup, which transpiles without type-checking, + // `languages/typescript/packages/cli` builds with tsup, which transpiles without type-checking, // and has no `typecheck` script — so `Record` buys nothing // at build time here. An if-chain ending in a bare Drizzle `return` hands a // future fifth integration the exact string this helper exists to stop it diff --git a/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts b/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts index 559df6171..68a6af7a5 100644 --- a/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts +++ b/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts @@ -27,7 +27,7 @@ export function findBundledDir(name: string): string | undefined { join(here, '..', '..', name), join(here, '..', '..', '..', name), join(here, '..', '..', '..', '..', name), - // Dev fallback: running from `packages/cli/src/commands/init/lib/`, + // Dev fallback: running from `languages/typescript/packages/cli/src/commands/init/lib/`, // the monorepo `/` is six levels up. join(here, '..', '..', '..', '..', '..', '..', name), ] diff --git a/languages/typescript/packages/cli/src/commands/init/lib/introspect.ts b/languages/typescript/packages/cli/src/commands/init/lib/introspect.ts index 37cef7049..de43a9761 100644 --- a/languages/typescript/packages/cli/src/commands/init/lib/introspect.ts +++ b/languages/typescript/packages/cli/src/commands/init/lib/introspect.ts @@ -51,7 +51,7 @@ export function pgTypeToDataType(udtName: string): DataType { * so keying on the v2 name alone, as this did, reported every column on the * default path as plaintext. That is the dangerous direction to be wrong in: * an encrypted column shown as plaintext invites the caller to encrypt it a - * second time. `packages/wizard` already carries this predicate; the two + * second time. `languages/typescript/packages/wizard` already carries this predicate; the two * should agree. * * Deliberately not `classifyEqlDomain` from `@cipherstash/migrate`, despite diff --git a/languages/typescript/packages/cli/src/commands/init/lib/setup-prompt.ts b/languages/typescript/packages/cli/src/commands/init/lib/setup-prompt.ts index 6db238329..003d9eb0d 100644 --- a/languages/typescript/packages/cli/src/commands/init/lib/setup-prompt.ts +++ b/languages/typescript/packages/cli/src/commands/init/lib/setup-prompt.ts @@ -118,7 +118,7 @@ function schemaAuthoringGuidance(integration: Integration): string { * or Prisma project sends the agent after a package that is not installed. * * A `switch` with a neutral `default`, not an if-chain ending in the Drizzle - * string: `packages/cli` is built by tsup, which transpiles without + * string: `languages/typescript/packages/cli` is built by tsup, which transpiles without * type-checking, and the package has no `typecheck` script — so nothing would * catch a fifth `Integration` variant silently inheriting Drizzle's answer. * `skillsFor()` in `install-skills.ts` degrades the same way, for the same diff --git a/languages/typescript/packages/cli/src/installer/__tests__/bundle-digest.test.ts b/languages/typescript/packages/cli/src/installer/__tests__/bundle-digest.test.ts index 430100699..1ed10d600 100644 --- a/languages/typescript/packages/cli/src/installer/__tests__/bundle-digest.test.ts +++ b/languages/typescript/packages/cli/src/installer/__tests__/bundle-digest.test.ts @@ -11,7 +11,7 @@ import { describe, expect, it, vi } from 'vitest' * `accde0030…`, because upstream restored the deprecated `ste_vec_contains` * aliases in the real release. `stash eql install` would have executed the * wrong one against a customer database and reported success — the whole - * failure is silent. `packages/stack-prisma` already refuses on this same + * failure is silent. `languages/typescript/packages/stack-prisma` already refuses on this same * digest (`readVerifiedInstallSql`); the CLI did not. */ diff --git a/languages/typescript/packages/cli/src/installer/bundle-digest.ts b/languages/typescript/packages/cli/src/installer/bundle-digest.ts index 4d3045682..ae12a675d 100644 --- a/languages/typescript/packages/cli/src/installer/bundle-digest.ts +++ b/languages/typescript/packages/cli/src/installer/bundle-digest.ts @@ -20,7 +20,7 @@ * `@cipherstash/eql` already ships the answer — `releaseManifest`'s * `installSqlSha256`, generated from the same tsup run that copies the SQL into * `dist/sql/`. It was imported by `verify.ts` for its `eqlVersion` alone. - * `packages/stack-prisma` has verified against it since the v3 migrations + * `languages/typescript/packages/stack-prisma` has verified against it since the v3 migrations * landed ({@link https://github.com/cipherstash/stack} — * `src/migration/eql-bundle-v3.ts`'s `readVerifiedInstallSql`); this is the * same check on the path that actually reaches customer databases. diff --git a/languages/typescript/packages/cli/src/installer/grants.ts b/languages/typescript/packages/cli/src/installer/grants.ts index 0594aab1d..edcb725d5 100644 --- a/languages/typescript/packages/cli/src/installer/grants.ts +++ b/languages/typescript/packages/cli/src/installer/grants.ts @@ -3,7 +3,7 @@ * * Deliberately import-free. `installer/index.ts` pulls in `pg` and the EQL SQL * bundle, which no other package depends on; keeping the grants here lets the - * live proof in `packages/stack/__tests__/supabase-v3-grants-pg.test.ts` assert + * live proof in `languages/typescript/packages/stack/__tests__/supabase-v3-grants-pg.test.ts` assert * against the EXACT SQL this package ships, without `@cipherstash/stack` taking * a dependency on `stash` (which would be a cycle — `stash` already depends on * `@cipherstash/stack`). Re-exported from `installer/index.ts`, which remains diff --git a/languages/typescript/packages/cli/src/messages.ts b/languages/typescript/packages/cli/src/messages.ts index ac1bd9623..2b0c653ea 100644 --- a/languages/typescript/packages/cli/src/messages.ts +++ b/languages/typescript/packages/cli/src/messages.ts @@ -7,7 +7,7 @@ * * Scope: only strings the E2E suite asserts on. Inline strings that no test * depends on stay inline — premature extraction is worse than copy-paste - * here. See `packages/cli/AGENTS.md` for guidance on what to add. + * here. See `languages/typescript/packages/cli/AGENTS.md` for guidance on what to add. */ export const messages = { cli: { diff --git a/languages/typescript/packages/cli/src/release-train.ts b/languages/typescript/packages/cli/src/release-train.ts index eb80083e1..db5f90618 100644 --- a/languages/typescript/packages/cli/src/release-train.ts +++ b/languages/typescript/packages/cli/src/release-train.ts @@ -13,7 +13,7 @@ * the build's tests instead of silently installing unpinned and being * exempt from the skew warning. * - * Values are manifest paths relative to `packages/cli/`. + * Values are manifest paths relative to `languages/typescript/packages/cli/`. */ export const RELEASE_TRAIN_MANIFESTS = { stash: './package.json', diff --git a/languages/typescript/packages/cli/tests/e2e/doctor-missing-binary.e2e.test.ts b/languages/typescript/packages/cli/tests/e2e/doctor-missing-binary.e2e.test.ts index ad7c3bd19..5b8784475 100644 --- a/languages/typescript/packages/cli/tests/e2e/doctor-missing-binary.e2e.test.ts +++ b/languages/typescript/packages/cli/tests/e2e/doctor-missing-binary.e2e.test.ts @@ -20,7 +20,7 @@ import { render } from '../helpers/pty.js' // Absent by patching the resolver in the spawned CLI, not by moving files: the // suite must not mutate the checkout it runs in, and this works whether or not // the developer has run `build:native`. Same technique as -// `packages/protect-ffi/src/lintWiring.test.ts`, which re-runs its own suite +// `languages/typescript/packages/protect-ffi/src/lintWiring.test.ts`, which re-runs its own suite // this way. interface Target { diff --git a/languages/typescript/packages/cli/tsconfig.scaffold.json b/languages/typescript/packages/cli/tsconfig.scaffold.json index 1a11f6286..226889b1d 100644 --- a/languages/typescript/packages/cli/tsconfig.scaffold.json +++ b/languages/typescript/packages/cli/tsconfig.scaffold.json @@ -1,7 +1,7 @@ { // Compiles the exact files `stash init` writes into a user's project. // - // Nothing else in the repo did. `packages/cli` has no typecheck script (21 + // Nothing else in the repo did. `languages/typescript/packages/cli` has no typecheck script (21 // pre-existing errors), the codegen tests only string-match the templates, // and `build-schema.test.ts` stubs the generator out entirely — so when // `Encryption` was tightened to require a non-empty schema set, both diff --git a/languages/typescript/packages/cli/tsup.config.ts b/languages/typescript/packages/cli/tsup.config.ts index feb085885..da02e4120 100644 --- a/languages/typescript/packages/cli/tsup.config.ts +++ b/languages/typescript/packages/cli/tsup.config.ts @@ -82,7 +82,7 @@ export default defineConfig([ // Skills live at the monorepo root and ship inside the CLI tarball so // `stash init` can copy them into the user's `.claude/skills/` or // `.codex/skills/` directory at handoff time. Mirror of - // packages/wizard/tsup.config.ts:24. + // languages/typescript/packages/wizard/tsup.config.ts:24. if (existsSync('../../skills')) { cpSync('../../skills', 'dist/skills', { recursive: true }) } diff --git a/languages/typescript/packages/cli/vitest.config.ts b/languages/typescript/packages/cli/vitest.config.ts index fdc0d98b2..20c772497 100644 --- a/languages/typescript/packages/cli/vitest.config.ts +++ b/languages/typescript/packages/cli/vitest.config.ts @@ -13,7 +13,7 @@ export default defineConfig({ // guarded-grants.live. Run in parallel forks they race; one fork lets each // suite see the database state its comments already assume. The unit // project keeps default file parallelism — serialising all ~1300 tests - // for the sake of four files is the `packages/migrate` fix at the wrong + // for the sake of four files is the `languages/typescript/packages/migrate` fix at the wrong // scale. projects: [ { @@ -55,15 +55,15 @@ export default defineConfig({ // before mocking runs. // // This removes the `@cipherstash/migrate` build coupling ONLY. The suite - // is still not self-contained: removing `packages/stack/dist` still + // is still not self-contained: removing `languages/typescript/packages/stack/dist` still // fails 10 files, via TWO independent routes — - // 1. `packages/migrate/src/backfill.ts` imports `@cipherstash/stack`, + // 1. `languages/typescript/packages/migrate/src/backfill.ts` imports `@cipherstash/stack`, // so this alias reaches it transitively; and // 2. `init/lib/__tests__/introspect.test.ts` imports // `@cipherstash/stack/eql/v3` directly, never touching migrate. // Route 2 means decoupling `backfill.ts` would NOT make the suite // standalone. Closing both needs `stackSourceAlias`, which cannot be - // spread here — its `'@/'` entry (pointing at `packages/stack/src`) + // spread here — its `'@/'` entry (pointing at `languages/typescript/packages/stack/src`) // would clobber this package's own `'@/'`. That is why // `vitest.shared.ts` is not imported by this config (#787 review). '@cipherstash/migrate': resolve(__dirname, '../migrate/src/index.ts'), diff --git a/languages/typescript/packages/migrate/package.json b/languages/typescript/packages/migrate/package.json index 0a3f6e11b..f362f8437 100644 --- a/languages/typescript/packages/migrate/package.json +++ b/languages/typescript/packages/migrate/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/migrate" + "directory": "languages/typescript/packages/migrate" }, "keywords": [ "cipherstash", diff --git a/languages/typescript/packages/nextjs/package.json b/languages/typescript/packages/nextjs/package.json index a23c3597a..344c2da0a 100644 --- a/languages/typescript/packages/nextjs/package.json +++ b/languages/typescript/packages/nextjs/package.json @@ -14,7 +14,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/nextjs" + "directory": "languages/typescript/packages/nextjs" }, "license": "MIT", "author": "CipherStash ", diff --git a/languages/typescript/packages/protect-ffi/.gitignore b/languages/typescript/packages/protect-ffi/.gitignore index 35fd9ccb1..72015789c 100644 --- a/languages/typescript/packages/protect-ffi/.gitignore +++ b/languages/typescript/packages/protect-ffi/.gitignore @@ -4,7 +4,7 @@ index.node # Generated output is not tracked — with three deliberate exceptions. # # `dist/wasm/**` comes from `wasm-pack` + `scripts/inline-wasm.mjs`, which need -# Rust, the wasm32 target and wasm-pack. But `packages/stack` value-imports +# Rust, the wasm32 target and wasm-pack. But `languages/typescript/packages/stack` value-imports # `@cipherstash/protect-ffi/wasm-inline`, so with the whole directory absent its # declaration build cannot resolve the module — which would put the Rust # toolchain on every contributor and every PR job, for a typecheck. diff --git a/languages/typescript/packages/protect-ffi/README.md b/languages/typescript/packages/protect-ffi/README.md index 892225a36..ba16b3c2c 100644 --- a/languages/typescript/packages/protect-ffi/README.md +++ b/languages/typescript/packages/protect-ffi/README.md @@ -224,7 +224,7 @@ is decided. In the project directory, you can run: -Since this package was absorbed into the `cipherstash/stack` monorepo, cargo is deliberately kept off the default `build` and `test` paths: the root `pnpm test` reaches every package, and a cargo process on that path would put a Rust toolchain on every contributor's machine. The Rust work lives behind its own scripts, listed below. `packages/protect-ffi/src/lintWiring.test.ts` enforces the split. +Since this package was absorbed into the `cipherstash/stack` monorepo, cargo is deliberately kept off the default `build` and `test` paths: the root `pnpm test` reaches every package, and a cargo process on that path would put a Rust toolchain on every contributor's machine. The Rust work lives behind its own scripts, listed below. `languages/typescript/packages/protect-ffi/src/lintWiring.test.ts` enforces the split. #### `pnpm run build` diff --git a/languages/typescript/packages/protect-ffi/mise.toml b/languages/typescript/packages/protect-ffi/mise.toml index 8e6c680e2..d775021fa 100644 --- a/languages/typescript/packages/protect-ffi/mise.toml +++ b/languages/typescript/packages/protect-ffi/mise.toml @@ -1,6 +1,6 @@ [tools] # No `node` entry. This file used to carry `node = "latest"`, which resolved to -# 25.x and meant `cd packages/protect-ffi` silently switched Node version +# 25.x and meant `cd languages/typescript/packages/protect-ffi` silently switched Node version # relative to the rest of the monorepo — whose lockfile, `@types/node` and # `@tsconfig/node22` are all resolved for 22, and whose only Node requirement # is the root `engines: { node: ">=22" }`. Leaving Node to the workspace keeps @@ -76,7 +76,7 @@ run = "cargo clippy --no-deps --tests --all-features --all-targets -- -D warning # Needs `rustup target add wasm32-unknown-unknown` once. CI does this in the # `Add wasm32 target` step of .github/workflows/tests-rust.yml — spelled from # the repository root because the bare filename this used to give resolved only -# to the dead upstream copy under packages/protect-ffi/.github/, which GitHub +# to the dead upstream copy under languages/typescript/packages/protect-ffi/.github/, which GitHub # never executes. So the comment described a step that ran nowhere, which is the # same defect as a check that runs nowhere. lintWiring.test.ts now fails on a # citation that resolves only in that directory. diff --git a/languages/typescript/packages/protect-ffi/platforms/darwin-arm64/package.json b/languages/typescript/packages/protect-ffi/platforms/darwin-arm64/package.json index 859494a49..0a4bf082f 100644 --- a/languages/typescript/packages/protect-ffi/platforms/darwin-arm64/package.json +++ b/languages/typescript/packages/protect-ffi/platforms/darwin-arm64/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/protect-ffi/platforms/darwin-arm64" + "directory": "languages/typescript/packages/protect-ffi/platforms/darwin-arm64" }, "os": [ "darwin" diff --git a/languages/typescript/packages/protect-ffi/platforms/darwin-x64/package.json b/languages/typescript/packages/protect-ffi/platforms/darwin-x64/package.json index 49ee91d06..eaffc5742 100644 --- a/languages/typescript/packages/protect-ffi/platforms/darwin-x64/package.json +++ b/languages/typescript/packages/protect-ffi/platforms/darwin-x64/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/protect-ffi/platforms/darwin-x64" + "directory": "languages/typescript/packages/protect-ffi/platforms/darwin-x64" }, "os": [ "darwin" diff --git a/languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/package.json b/languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/package.json index 3c2a9f10c..7d284be5f 100644 --- a/languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/package.json +++ b/languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/protect-ffi/platforms/linux-arm64-gnu" + "directory": "languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu" }, "os": [ "linux" diff --git a/languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/package.json b/languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/package.json index 231d1de2e..83e6266a1 100644 --- a/languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/package.json +++ b/languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/protect-ffi/platforms/linux-x64-gnu" + "directory": "languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu" }, "os": [ "linux" diff --git a/languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/package.json b/languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/package.json index 90ebc3350..53e72ad3e 100644 --- a/languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/package.json +++ b/languages/typescript/packages/protect-ffi/platforms/linux-x64-musl/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/protect-ffi/platforms/linux-x64-musl" + "directory": "languages/typescript/packages/protect-ffi/platforms/linux-x64-musl" }, "os": [ "linux" diff --git a/languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/package.json b/languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/package.json index 430e4e9e2..ebd8fdc96 100644 --- a/languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/package.json +++ b/languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/protect-ffi/platforms/win32-x64-msvc" + "directory": "languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc" }, "os": [ "win32" diff --git a/languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs b/languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs index 231a8722d..ab2d015f1 100644 --- a/languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs +++ b/languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs @@ -86,7 +86,7 @@ await writeFile(pkgPath, `${JSON.stringify({ type: 'module' }, null, 2)}\n`) // wasm-pack writes its own `dist/wasm/.gitignore` containing `*`, on the // assumption that everything it generates is disposable. Three files here are // not: `protect_ffi.d.ts`, `protect_ffi_bg.wasm.d.ts` and `errors.d.ts` are -// tracked so `packages/stack`'s declaration build resolves +// tracked so `languages/typescript/packages/stack`'s declaration build resolves // `@cipherstash/protect-ffi/wasm-inline` without a Rust toolchain (see the // repo root `.gitignore`). // diff --git a/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts b/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts index edca6218c..ae642742c 100644 --- a/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts +++ b/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts @@ -5,7 +5,7 @@ * request — `mise setup` then `mise run test:integration:all`, in * `.github/workflows/test.yml`. The absorption copied the suite into this * package intact and left that workflow behind under - * `packages/protect-ffi/.github/`, where GitHub never looks: it reads workflows + * `languages/typescript/packages/protect-ffi/.github/`, where GitHub never looks: it reads workflows * from the repository root alone. So the day protect-ffi landed in the * monorepo, every live encrypt / decrypt / lock-context / keyset / * JSON-SteVec / Postgres / WASM-round-trip assertion in it stopped executing — @@ -106,7 +106,7 @@ const rootWorkflows = readdirSync(workflowDir) * parsed YAML field so reindenting, renaming the step, or moving the * invocation between `run:` and a composite action does not break the check. */ -const SUITE_DIR = 'packages/protect-ffi/integration-tests' +const SUITE_DIR = 'languages/typescript/packages/protect-ffi/integration-tests' /** * Something that actually STARTS the tests. Either shape counts: @@ -133,7 +133,7 @@ describe('integration-tests suite runs in CI', () => { it('reads the root workflow directory', () => { // The guard on the scan. A discovery test that matches zero files passes // and proves nothing, so pin two workflows that live at the root and - // nowhere else: if this resolved to `packages/protect-ffi/.github/` (the + // nowhere else: if this resolved to `languages/typescript/packages/protect-ffi/.github/` (the // dead upstream deposit) or to a directory that no longer exists, every // assertion below would go vacuous instead of red. const names = rootWorkflows.map((workflow) => workflow.name) @@ -155,7 +155,7 @@ describe('integration-tests suite runs in CI', () => { it('names no script after a turbo task, so `pnpm test` stays credential-free', () => { // The cost of workspace membership, and it is not hypothetical. Root - // `pnpm test` is `turbo test --filter './packages/**'`, which now REACHES + // `pnpm test` is `turbo test --filter './languages/typescript/packages/**'`, which now REACHES // this package — turbo already lists `#test` in the graph and skips it only // because no script answers to that name. Give one that name and the repo's // ordinary unit-test command starts demanding Docker, a Postgres on 5436 @@ -246,7 +246,7 @@ describe('integration-tests suite runs in CI', () => { it('is invoked by at least one root workflow', () => { expect( suiteRunners.map((workflow) => workflow.name), - 'No workflow in .github/workflows/ both names packages/protect-ffi/integration-tests and starts vitest. That was silently true from the absorption until integration-protect-ffi.yml landed: the suite is 19 files of live coverage that nothing ran.', + 'No workflow in .github/workflows/ both names languages/typescript/packages/protect-ffi/integration-tests and starts vitest. That was silently true from the absorption until integration-protect-ffi.yml landed: the suite is 19 files of live coverage that nothing ran.', ).not.toEqual([]) }) diff --git a/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts b/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts index dc18b04bb..e44440759 100644 --- a/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts +++ b/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts @@ -65,7 +65,7 @@ const testWorkflow = withoutComments( // Every root workflow an exempted script may hang off, discovered by reading // the DIRECTORY rather than by listing filenames. Same rule as above: root // only — a script "run by CI" according to a file under -// packages/protect-ffi/.github/ is a script nothing runs. +// languages/typescript/packages/protect-ffi/.github/ is a script nothing runs. // // The scan is the point. A hardcoded list has to be maintained in step with a // set of files nothing forces it to track: move a job to a new workflow and @@ -196,7 +196,7 @@ function reachableFromAnyEntryPoint(): Set { * list is a way to launder an orphan into an intention: `test:typecheck:wasm` * sat here from the absorption onward reading "run by the wasm job", and the * only jobs that ran it were the upstream copies under - * packages/protect-ffi/.github/ — which GitHub, reading workflows from the + * languages/typescript/packages/protect-ffi/.github/ — which GitHub, reading workflows from the * repository root alone, never executed. */ const ENTRY_POINT_EXEMPT: Record = { @@ -258,7 +258,7 @@ fs.appendFileSync(${JSON.stringify(marker)}, process.pid + '\\n') const load = Module._load Module._load = function (request, parent, isMain) { if (BINDING.test(request)) { - // Shaped like the real thing: \`code\` is what packages/cli keys on. + // Shaped like the real thing: \`code\` is what languages/typescript/packages/cli keys on. const error = new Error("Cannot find module '" + request + "'") error.code = 'MODULE_NOT_FOUND' throw error @@ -364,7 +364,7 @@ describe('lint and format wiring', () => { }) it('keeps no .github directory inside this package', () => { - // `packages/protect-ffi/.github/` is gone: the release pipeline ported the + // `languages/typescript/packages/protect-ffi/.github/` is gone: the release pipeline ported the // last of what it held (`build.yml`'s per-platform CARGO_BUILD_TARGET // matrix, and `actions/setup`'s `neon list-platforms` step) into // `.github/workflows/_build-ffi-artifacts.yml`. @@ -396,7 +396,7 @@ describe('lint and format wiring', () => { it('keeps cargo off the default test path', () => { // The load-bearing half of the split. Root `pnpm test` runs - // `turbo test --filter './packages/*'`, which reaches this package's + // `turbo test --filter './languages/typescript/packages/*'`, which reaches this package's // `test` — so anything cargo on that path is cargo on every PR, in a repo // where one package out of eighteen is Rust. // @@ -424,7 +424,7 @@ describe('lint and format wiring', () => { // test then requires what cargo produces: `src/nativeLoading.test.ts` // asserted `assertNativeBindingAvailable()` does not throw, which needs // an `index.node` that only `build:native` writes. Root `pnpm test` - // reaches this package through `turbo test --filter './packages/*'`, so + // reaches this package through `turbo test --filter './languages/typescript/packages/*'`, so // that made a Rust build a prerequisite of the whole repo's default test // — the exact thing the entry-point split exists to prevent, arriving // through the tests instead of through the scripts. @@ -491,7 +491,7 @@ describe('lint and format wiring', () => { expect( child.status, - `The default test suite does not survive a checkout with no cargo build.\n\`packages/protect-ffi\`'s \`test\` is what root \`pnpm test\` runs through turbo, and it must pass with no \`index.node\` anywhere — the six \`platforms/*\` packages are empty until someone compiles one, and \`build\` is \`tsc\`, not cargo.\nGate the assertion on the artifact being present (see \`builtArtifacts\` in nativeLoading.test.ts) and give the artifact-free case its own contract, rather than making a Rust toolchain a prerequisite of the repo's default test.\nThe nested run said:\n${output}`, + `The default test suite does not survive a checkout with no cargo build.\n\`languages/typescript/packages/protect-ffi\`'s \`test\` is what root \`pnpm test\` runs through turbo, and it must pass with no \`index.node\` anywhere — the six \`platforms/*\` packages are empty until someone compiles one, and \`build\` is \`tsc\`, not cargo.\nGate the assertion on the artifact being present (see \`builtArtifacts\` in nativeLoading.test.ts) and give the artifact-free case its own contract, rather than making a Rust toolchain a prerequisite of the repo's default test.\nThe nested run said:\n${output}`, ).toBe(0) // Non-vacuity, in two parts. A child that ran nothing exits 0 on some @@ -552,7 +552,7 @@ describe('lint and format wiring', () => { // // Scoped to `test:cargo`, the Rust CHECK entry point, and deliberately not // to the build scripts. `cargo-build` is also `debug`, and `build:native` - // is a documented local command (README.md, packages/cli/AGENTS.md) — a + // is a documented local command (README.md, languages/typescript/packages/cli/AGENTS.md) — a // contributor who has just edited `Cargo.toml` regenerates the lock on // their next build, legitimately, and `--locked` would turn that into a // failure at the end of a compile. The check runs on the same commit and diff --git a/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts b/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts index 1cf770047..b047c53df 100644 --- a/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts +++ b/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts @@ -23,8 +23,8 @@ * under the emitted entry instead of substituting an installation. * * Nothing in this file may REQUIRE a binary, though, and that is a separate - * rule from the ones above. `packages/protect-ffi`'s `test` is the default task - * root `pnpm test` reaches through `turbo test --filter './packages/*'`, and it + * rule from the ones above. `languages/typescript/packages/protect-ffi`'s `test` is the default task + * root `pnpm test` reaches through `turbo test --filter './languages/typescript/packages/*'`, and it * is deliberately Rust-free: `index.node` stopped being tarball content when * this package was absorbed, so on a fresh checkout there is no binary * anywhere and the six `platforms/*` links are empty. `lintWiring.test.ts` @@ -146,8 +146,8 @@ const builtArtifacts = BINDING_ARTIFACTS.filter( ) /** - * The platform-package name in a loader failure, as `packages/cli` matches it - * (`PLATFORM_PKG` in `packages/cli/src/native.ts`). + * The platform-package name in a loader failure, as `languages/typescript/packages/cli` matches it + * (`PLATFORM_PKG` in `languages/typescript/packages/cli/src/native.ts`). * * Copied rather than imported — this package does not depend on the CLI, and * should not. The coupling is the point of the assertion: `index.cts`'s doc @@ -156,7 +156,7 @@ const builtArtifacts = BINDING_ARTIFACTS.filter( * the code doing that classification. Nothing checked the promise against a * real error until now: the CLI's own suite builds its inputs by hand * (`moduleError("Cannot find module '@cipherstash/protect-ffi-darwin-arm64'")` - * in `packages/cli/src/__tests__/native.test.ts`), so it proves the matcher + * in `languages/typescript/packages/cli/src/__tests__/native.test.ts`), so it proves the matcher * matches a string, not that the string is what the loader raises. */ const PLATFORM_PACKAGE = @@ -193,10 +193,10 @@ describe('assertNativeBindingAvailable', () => { // suite runs where a binary is installed". That premise died with the // absorption. `index.node` arrived prebuilt inside the npm tarball; as a // workspace package it is a cargo output, the six `platforms/*` links are - // empty until someone builds one, and `packages/protect-ffi`'s `test` is + // empty until someone builds one, and `languages/typescript/packages/protect-ffi`'s `test` is // deliberately Rust-free. So on every fresh checkout the assertion failed // — and it failed under root `pnpm test`, which reaches this package via - // `turbo test --filter './packages/*'`. + // `turbo test --filter './languages/typescript/packages/*'`. // // Both branches assert. A `skipIf` here would be the trade this repo keeps // refusing: it goes quiet on every contributor machine, and quiet is @@ -213,7 +213,7 @@ describe('assertNativeBindingAvailable', () => { expect( outcome.error, - `No index.node exists under packages/protect-ffi, so the loader cannot succeed and this call must throw. Looked at:\n${BINDING_ARTIFACTS.map((path) => ` ${path}`).join('\n')}\nA success here means the binding came from somewhere none of those paths covers, and the check above is then gated on a list that no longer describes reality.`, + `No index.node exists under languages/typescript/packages/protect-ffi, so the loader cannot succeed and this call must throw. Looked at:\n${BINDING_ARTIFACTS.map((path) => ` ${path}`).join('\n')}\nA success here means the binding came from somewhere none of those paths covers, and the check above is then gated on a list that no longer describes reality.`, ).toBeInstanceOf(Error) const error = outcome.error as NodeJS.ErrnoException & { @@ -222,11 +222,11 @@ describe('assertNativeBindingAvailable', () => { // The contract `index.cts` documents, verified against the real thing. expect( error.code, - `The loader failure must reach callers unwrapped as MODULE_NOT_FOUND. \`packages/cli\`'s \`isNativeBinaryMissing\` tests \`code\` first and returns false for anything else, so a wrapped or re-thrown error turns \`stash doctor\`'s actionable "native binary missing" note back into a raw stack trace. Got: ${errorDetail}`, + `The loader failure must reach callers unwrapped as MODULE_NOT_FOUND. \`languages/typescript/packages/cli\`'s \`isNativeBinaryMissing\` tests \`code\` first and returns false for anything else, so a wrapped or re-thrown error turns \`stash doctor\`'s actionable "native binary missing" note back into a raw stack trace. Got: ${errorDetail}`, ).toBe('MODULE_NOT_FOUND') expect( `${error.message}\n${(error.requireStack ?? []).join('\n')}`, - `The failure must name the platform package so \`packages/cli\` can tell a missing NATIVE binary from any other missing module. Got: ${errorDetail}`, + `The failure must name the platform package so \`languages/typescript/packages/cli\` can tell a missing NATIVE binary from any other missing module. Got: ${errorDetail}`, ).toMatch(PLATFORM_PACKAGE) }) diff --git a/languages/typescript/packages/stack-drizzle/__tests__/operators.test.ts b/languages/typescript/packages/stack-drizzle/__tests__/operators.test.ts index f9709b19e..626c71e25 100644 --- a/languages/typescript/packages/stack-drizzle/__tests__/operators.test.ts +++ b/languages/typescript/packages/stack-drizzle/__tests__/operators.test.ts @@ -59,7 +59,7 @@ function chainable(result: Promise) { // batch form applies it position-for-position so callers can pin ordering. function setup(termImpl: (value?: unknown) => unknown = () => TERM) { const encryptQuery = vi.fn((valueOrTerms: unknown, opts?: unknown) => { - // Route exactly as the real client does (packages/stack/src/encryption/ + // Route exactly as the real client does (languages/typescript/packages/stack/src/encryption/ // index.ts): batch ONLY when no opts are supplied AND the arg is a term // array. An array-valued single query WITH opts (e.g. a searchableJson // array needle) must take the single path here too, or the double would diff --git a/languages/typescript/packages/stack-drizzle/package.json b/languages/typescript/packages/stack-drizzle/package.json index 0ba93aa84..969b08fc6 100644 --- a/languages/typescript/packages/stack-drizzle/package.json +++ b/languages/typescript/packages/stack-drizzle/package.json @@ -19,7 +19,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/stack-drizzle" + "directory": "languages/typescript/packages/stack-drizzle" }, "license": "MIT", "author": "CipherStash ", diff --git a/languages/typescript/packages/stack-prisma/DEVELOPING.md b/languages/typescript/packages/stack-prisma/DEVELOPING.md index 588cee3f5..996a7ad3f 100644 --- a/languages/typescript/packages/stack-prisma/DEVELOPING.md +++ b/languages/typescript/packages/stack-prisma/DEVELOPING.md @@ -15,7 +15,7 @@ per-column search-mode flags. ## Source layout ```text -packages/stack-prisma/ +languages/typescript/packages/stack-prisma/ ├── src/ │ ├── contract.prisma PSL contract source (models NO storage — v3 │ │ declares none; the bundle creates the domains) @@ -378,7 +378,7 @@ directory: each `migration.ts` calls `readVerifiedInstallSql()`, so re-emitting a historical edge silently bakes the new release into it. `tsx` is not a dependency of this package; any workspace copy works (e.g. `../cli/node_modules/.bin/tsx`). Copy the new and re-emitted `migration.json` / -`ops.json` pairs into `examples/prisma/migrations/cipherstash/` and add the new +`ops.json` pairs into `languages/typescript/examples/prisma/migrations/cipherstash/` and add the new invariant to its single-line `refs/head.json` (`test/v3/vendored-space-parity.test.ts` enforces both). Between the two merges the live byte-identity check in `test/live/migration-apply-live-pg.test.ts` fails by construction (the diff --git a/languages/typescript/packages/stack-prisma/README.md b/languages/typescript/packages/stack-prisma/README.md index b326c4479..e0823754e 100644 --- a/languages/typescript/packages/stack-prisma/README.md +++ b/languages/typescript/packages/stack-prisma/README.md @@ -164,7 +164,7 @@ The four `CS_*` env vars (`CS_WORKSPACE_CRN`, `CS_CLIENT_ID`, `CS_CLIENT_KEY`, ` ## Example -A runnable end-to-end example lives at [`examples/prisma/`](https://github.com/cipherstash/stack/tree/main/examples/prisma) — bundles a docker-compose Postgres, a six-codec `User` schema, and a flow that exercises every operator category against a live ZeroKMS workspace. +A runnable end-to-end example lives at [`languages/typescript/examples/prisma/`](https://github.com/cipherstash/stack/tree/main/languages/typescript/examples/prisma) — bundles a docker-compose Postgres, a six-codec `User` schema, and a flow that exercises every operator category against a live ZeroKMS workspace. ## How it works @@ -185,7 +185,7 @@ plaintext and keys never reach CipherStash, and every decryption is logged for a ## Contributing -See [`DEVELOPING.md`](https://github.com/cipherstash/stack/blob/main/packages/stack-prisma/DEVELOPING.md) for the source layout, two-pass codec encode + middleware rewrite lifecycle, physical-column-name routing, the `bigint → Number` SDK boundary, and other runtime-side details. +See [`DEVELOPING.md`](https://github.com/cipherstash/stack/blob/main/languages/typescript/packages/stack-prisma/DEVELOPING.md) for the source layout, two-pass codec encode + middleware rewrite lifecycle, physical-column-name routing, the `bigint → Number` SDK boundary, and other runtime-side details. ## References diff --git a/languages/typescript/packages/stack-prisma/package.json b/languages/typescript/packages/stack-prisma/package.json index 703c38eab..cc91f1b82 100644 --- a/languages/typescript/packages/stack-prisma/package.json +++ b/languages/typescript/packages/stack-prisma/package.json @@ -19,7 +19,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/stack-prisma" + "directory": "languages/typescript/packages/stack-prisma" }, "type": "module", "sideEffects": false, diff --git a/languages/typescript/packages/stack-prisma/src/migration/eql-bundle-v3.ts b/languages/typescript/packages/stack-prisma/src/migration/eql-bundle-v3.ts index 4df232b89..9ab8126af 100644 --- a/languages/typescript/packages/stack-prisma/src/migration/eql-bundle-v3.ts +++ b/languages/typescript/packages/stack-prisma/src/migration/eql-bundle-v3.ts @@ -98,7 +98,7 @@ export function assertInstallSqlDigest(sql: string): string { * Turns a missing/broken package into an actionable error instead of a raw * `readFileSync` failure. The CLI does the same check on its own install * path — see `assertBundledEqlSqlDigest` in - * `packages/cli/src/installer/bundle-digest.ts`. (This comment named a + * `languages/typescript/packages/cli/src/installer/bundle-digest.ts`. (This comment named a * `readV3InstallSql` that never existed, back when the CLI verified nothing.) */ export function readVerifiedInstallSql(): string { diff --git a/languages/typescript/packages/stack-prisma/src/v3/operators-v3.ts b/languages/typescript/packages/stack-prisma/src/v3/operators-v3.ts index 08a18ef37..a82d799a6 100644 --- a/languages/typescript/packages/stack-prisma/src/v3/operators-v3.ts +++ b/languages/typescript/packages/stack-prisma/src/v3/operators-v3.ts @@ -1,7 +1,7 @@ /** * Cipherstash v3 query-operations registry — the EQL v3 twin of the v2 * `../execution/operators.ts`, lowering to the canonical v3 dialect - * (`packages/stack-drizzle/src/v3/{operators,sql-dialect}.ts` is the + * (`languages/typescript/packages/stack-drizzle/src/v3/{operators,sql-dialect}.ts` is the * byte-for-byte reference): * * eql_v3.eq(, $n::eql_v3.query_) -- equality (eqlEq) diff --git a/languages/typescript/packages/stack-prisma/test/live/helpers/live-gate.ts b/languages/typescript/packages/stack-prisma/test/live/helpers/live-gate.ts index 2a2ae28a3..207841bce 100644 --- a/languages/typescript/packages/stack-prisma/test/live/helpers/live-gate.ts +++ b/languages/typescript/packages/stack-prisma/test/live/helpers/live-gate.ts @@ -10,7 +10,7 @@ * at all. A PARTIAL `CS_*` environment counts as neither: it would * fail deep inside the client with "[encryption]: Not * authenticated", which names nothing — mirroring the rejection - * rationale in `packages/test-kit/src/env.ts`. + * rationale in `languages/typescript/packages/test-kit/src/env.ts`. * 2. **A Postgres to talk to** — `DATABASE_URL`. Locally: * * docker compose -f local/docker-compose.postgres.yml up -d --wait @@ -18,7 +18,7 @@ * * When either is missing the suites SKIP (describe.skip) so the default * `pnpm test` run stays green on machines without secrets — the posture - * the plan chose for this package (unlike `packages/stack/integration`, + * the plan chose for this package (unlike `languages/typescript/packages/stack/integration`, * whose suites run under a separate config and throw instead). */ diff --git a/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts index 04d9a9f77..f989466ee 100644 --- a/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts +++ b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-equality.test.ts @@ -3,7 +3,7 @@ * `eqlNeq`, `eqlIn`, `eqlNotIn`). * * The canonical v3 dialect (mirrors - * `packages/stack-drizzle/src/v3/{operators,sql-dialect}.ts`): + * `languages/typescript/packages/stack-drizzle/src/v3/{operators,sql-dialect}.ts`): * operands are QUERY TERMS cast to the column domain's * `eql_v3.query_` type — * diff --git a/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-json.test.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-json.test.ts index e5c2be090..eb0ff60ab 100644 --- a/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-json.test.ts +++ b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-json.test.ts @@ -3,7 +3,7 @@ * (`eqlJsonContains`, trait `cipherstash:searchable-json`). * * Canonical dialect (mirrors `v3Dialect.containsJson` in - * `packages/stack-drizzle/src/v3/sql-dialect.ts`): `eql_v3_json_search` has NO + * `languages/typescript/packages/stack-drizzle/src/v3/sql-dialect.ts`): `eql_v3_json_search` has NO * `eql_v3.matches` overload — containment is the `@>` operator, whose * `(eql_v3_json_search, eql_v3.query_json)` form takes a NARROWED query term * (searchableJson → no ciphertext) cast to the irregular diff --git a/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts index 82394449c..4004ade34 100644 --- a/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts +++ b/languages/typescript/packages/stack-prisma/test/v3/operator-lowering-v3-order-range.test.ts @@ -3,7 +3,7 @@ * `Lt` / `Lte` / `Between` / `NotBetween`) plus the free-standing * ordering helpers (`eqlAsc` / `eqlDesc`). * - * Canonical dialect (mirrors `packages/stack-drizzle/src/v3/sql-dialect.ts`): + * Canonical dialect (mirrors `languages/typescript/packages/stack-drizzle/src/v3/sql-dialect.ts`): * * eql_v3.gt(, $n::eql_v3.query_) * (eql_v3.gte(...) AND eql_v3.lte(...)) -- between, self-parenthesised diff --git a/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts b/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts index cfc89ce93..c98c771ee 100644 --- a/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts +++ b/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts @@ -657,7 +657,7 @@ describe('fresh database: both install paths must converge on eql-3.0.6', () => // driving `db init` in a repo upgraded from 1.0.0 hits this refusal with no // route out of it. Nothing type-checks either file; this assertion is the // only thing holding the pair to the planner's real message. - // `test/v3` -> `test` -> `packages/stack-prisma` -> `packages` -> root. + // `test/v3` -> `test` -> `languages/typescript/packages/stack-prisma` -> `packages` -> root. const repoRoot = join( dirname(fileURLToPath(import.meta.url)), '..', @@ -666,8 +666,8 @@ describe('fresh database: both install paths must converge on eql-3.0.6', () => '..', ) const shipped = { - 'packages/stack-prisma/README.md': await readFile( - join(repoRoot, 'packages/stack-prisma/README.md'), + 'languages/typescript/packages/stack-prisma/README.md': await readFile( + join(repoRoot, 'languages/typescript/packages/stack-prisma/README.md'), 'utf8', ), 'skills/stash-prisma/SKILL.md': await readFile( @@ -768,7 +768,7 @@ describe('no seed phase run: the 3.0.5 / 3.0.6 upgrades are silently invisible', /** * SHIPPED PROSE, pinned the same way the `db init` refusal above is pinned. * - * `skills/` is copied into the `stash` npm tarball by `packages/cli`'s build, + * `skills/` is copied into the `stash` npm tarball by `languages/typescript/packages/cli`'s build, * and `installSkills()` copies it from there into a customer's * `.claude/skills/` — so a wrong sentence in one is wrong guidance in someone * else's codebase. Nothing type-checks these files and no linter reads them; @@ -780,7 +780,7 @@ describe('no seed phase run: the 3.0.5 / 3.0.6 upgrades are silently invisible', * reaches the repo root to hold shipped docs to a fact. */ describe('shipped skills: claims verified false, which must not come back', () => { - // `test/v3` -> `test` -> `packages/stack-prisma` -> `packages` -> root. + // `test/v3` -> `test` -> `languages/typescript/packages/stack-prisma` -> `packages` -> root. const repoRoot = join( dirname(fileURLToPath(import.meta.url)), '..', @@ -811,7 +811,7 @@ describe('shipped skills: claims verified false, which must not come back', () = } it('no skill claims the CLI pins an exact `@cipherstash/eql` version', async () => { - // `packages/cli` depends on the workspace package, so what it packs is + // `languages/typescript/packages/cli` depends on the workspace package, so what it packs is // whatever specifier the release resolves — and the guarantee customers // actually have is narrower than "pinned": one `stash` RELEASE carries one // resolved bundle, but a DATABASE is on whatever bundle was last applied diff --git a/languages/typescript/packages/stack-prisma/test/v3/vendored-space-parity.test.ts b/languages/typescript/packages/stack-prisma/test/v3/vendored-space-parity.test.ts index 008cc7d2c..306993fc9 100644 --- a/languages/typescript/packages/stack-prisma/test/v3/vendored-space-parity.test.ts +++ b/languages/typescript/packages/stack-prisma/test/v3/vendored-space-parity.test.ts @@ -1,6 +1,6 @@ /** * Drift guard: the example app's vendored cipherstash contract space - * (`examples/prisma/migrations/cipherstash/`) must be byte-identical to + * (`languages/typescript/examples/prisma/migrations/cipherstash/`) must be byte-identical to * the artefacts this package ships. * * The CLI's seed phase copies the descriptor's migration packages into a @@ -18,7 +18,7 @@ * files. If this test fails after intentionally changing the package's * migrations, regenerate the example's copy: * - * cd examples/prisma && rm -rf migrations/cipherstash \ + * cd languages/typescript/examples/prisma && rm -rf migrations/cipherstash \ * && pnpm exec prisma-next migration plan --name sync # then delete * # the planned * # app-space dir diff --git a/languages/typescript/packages/stack-prisma/tsconfig.json b/languages/typescript/packages/stack-prisma/tsconfig.json index e79e9325c..6d5ff5f99 100644 --- a/languages/typescript/packages/stack-prisma/tsconfig.json +++ b/languages/typescript/packages/stack-prisma/tsconfig.json @@ -5,7 +5,7 @@ "module": "ESNext", "moduleDetection": "force", "moduleResolution": "bundler", - // Mirrors `packages/stack/tsconfig.json`: protect-ffi 0.24+ uses + // Mirrors `languages/typescript/packages/stack/tsconfig.json`: protect-ffi 0.24+ uses // conditional exports, and bundler resolution omits `node` by // default. Needed because the `@/*` mapping below pulls stack // SOURCE (which imports protect-ffi types) into this program. @@ -29,7 +29,7 @@ "baseUrl": ".", "paths": { // Resolve every consumed stack subpath to SOURCE, not `dist` - // (mirrors `packages/test-kit/tsconfig.json`). Without these, + // (mirrors `languages/typescript/packages/test-kit/tsconfig.json`). Without these, // `pnpm typecheck` only works after `pnpm build` — and on a // fresh/stale checkout the dist d.ts resolves partially, which // surfaces as implicit-`any` noise far from the real cause diff --git a/languages/typescript/packages/stack-supabase/__tests__/browser-export-condition.test.ts b/languages/typescript/packages/stack-supabase/__tests__/browser-export-condition.test.ts index 326d0b0b0..eb62d7ebc 100644 --- a/languages/typescript/packages/stack-supabase/__tests__/browser-export-condition.test.ts +++ b/languages/typescript/packages/stack-supabase/__tests__/browser-export-condition.test.ts @@ -1,7 +1,7 @@ /** * `@cipherstash/stack-supabase` declares no `browser` export condition (#804). * - * The sibling of `packages/stack/__tests__/browser-export-condition.test.ts`, + * The sibling of `languages/typescript/packages/stack/__tests__/browser-export-condition.test.ts`, * and it exists because this package has a `wasm-inline` entry of its own. * `./wasm-inline` binds the WASM engine from `@cipherstash/stack/wasm-inline`, * and that engine's core requires `clientKey` — a workspace secret — on every diff --git a/languages/typescript/packages/stack-supabase/__tests__/helpers/supabase-mock.ts b/languages/typescript/packages/stack-supabase/__tests__/helpers/supabase-mock.ts index 27b96c781..7e5555030 100644 --- a/languages/typescript/packages/stack-supabase/__tests__/helpers/supabase-mock.ts +++ b/languages/typescript/packages/stack-supabase/__tests__/helpers/supabase-mock.ts @@ -223,7 +223,7 @@ export function createMockSupabase(resultData: unknown = []) { * * Object literals, not the real classes: reproducing the split with the real * ones needs a built `dist/`, and `vitest.shared.ts:4-14` keeps `pnpm test` - * free of that. `packages/stack/dist-types/wasm-inline-type-identity.ts` covers + * free of that. `languages/typescript/packages/stack/dist-types/wasm-inline-type-identity.ts` covers * the dist-level TYPE half of the same hazard. */ export function wasmAuthoredV3Table(tableName: string, columnNames: string[]) { diff --git a/languages/typescript/packages/stack-supabase/__tests__/supabase-schema-builder.test.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-schema-builder.test.ts index 694426851..6a8db0691 100644 --- a/languages/typescript/packages/stack-supabase/__tests__/supabase-schema-builder.test.ts +++ b/languages/typescript/packages/stack-supabase/__tests__/supabase-schema-builder.test.ts @@ -272,7 +272,7 @@ describe('ColumnMap recognises v3 columns structurally, not by class identity', it('throws on a builder missing the v3 column surface', () => { // v2 columns have `build()` and `getName()` (`EncryptedColumn`, - // `packages/stack/src/schema/index.ts:442,449`) but neither `getEqlType()` + // `languages/typescript/packages/stack/src/schema/index.ts:442,449`) but neither `getEqlType()` // nor `getQueryCapabilities()` (`eql/v3/columns.ts:445,450`). Four probes, // not two, is what keeps the predicate honest. // diff --git a/languages/typescript/packages/stack-supabase/__tests__/supabase-wasm-config.test-d.ts b/languages/typescript/packages/stack-supabase/__tests__/supabase-wasm-config.test-d.ts index db3d76b9c..70d30e593 100644 --- a/languages/typescript/packages/stack-supabase/__tests__/supabase-wasm-config.test-d.ts +++ b/languages/typescript/packages/stack-supabase/__tests__/supabase-wasm-config.test-d.ts @@ -5,7 +5,7 @@ * `@cipherstash/stack-supabase/wasm-inline` "must carry all four `CS_*` * values", because there is no `~/.cipherstash` to discover credentials from * on an edge runtime. That is true of exactly ONE of the three arms - * `WasmClientConfig` accepts (`packages/stack/src/wasm-inline.ts`): the + * `WasmClientConfig` accepts (`languages/typescript/packages/stack/src/wasm-inline.ts`): the * access-key arm. On the `authStrategy` arm — the one an * `OidcFederationStrategy` takes, i.e. every identity-aware edge deployment — * `accessKey` is `never` and `workspaceCrn` is OPTIONAL, because a pre-built @@ -29,7 +29,7 @@ * Runs under `pnpm --filter @cipherstash/stack-supabase test:types`. * `@cipherstash/stack/wasm-inline` has no `paths` entry in * `tsconfig.json`, so it resolves through the workspace `exports` map to - * `packages/stack/dist/wasm-inline.d.ts` — build `@cipherstash/stack` first. + * `languages/typescript/packages/stack/dist/wasm-inline.d.ts` — build `@cipherstash/stack` first. */ import { encryptedTable, types } from '@cipherstash/stack/eql/v3' @@ -158,7 +158,7 @@ describe('the edge entry `config` accepts either auth arm', () => { * type checker enforced it. * * Same failure mode and same fix as `WasmClientConfig.eqlVersion?: never` in - * `packages/stack/src/wasm-inline.ts`, whose comment describes exactly this + * `languages/typescript/packages/stack/src/wasm-inline.ts`, whose comment describes exactly this * shared-config-const path; this is its sibling one package along. * * The runtime throw stays regardless — it is the backstop for plain JS, where diff --git a/languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts b/languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts index bf193ed41..b1107f2d8 100644 --- a/languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts +++ b/languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts @@ -142,10 +142,10 @@ describeBuilt('the wasm-inline entry, as emitted', () => { * things had been written down wrong there and both are settled here: * * - **Which package loads a binary at import.** Not `@cipherstash/protect-ffi`: - * `packages/protect-ffi/src/index.cts` writes `import native = + * `languages/typescript/packages/protect-ffi/src/index.cts` writes `import native = * require('./load.cjs')` specifically so `__importStar` cannot enumerate the * `@neon-rs/load` proxy into resolving the platform binary, and - * `packages/protect-ffi/src/nativeLoading.test.ts` guards that. It is + * `languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts` guards that. It is * `@cipherstash/auth`, whose Node entry evaluates its loader at module scope. * - **That none of it depends on introspection.** These are import-time * properties of the module graph. Declaring `schemas` skips introspection @@ -225,19 +225,19 @@ describeStackBuilt('the engine the native entry binds', () => { // may not exist when this suite runs. expect( readFileSync(resolve(ffi, 'load.cts'), 'utf-8'), - 'packages/protect-ffi/src/load.cts no longer wraps its platform requires in arrows. If protect-ffi now resolves a binary at module scope it becomes a second import-time load, and the correction this file grounds is only half right.', + 'languages/typescript/packages/protect-ffi/src/load.cts no longer wraps its platform requires in arrows. If protect-ffi now resolves a binary at module scope it becomes a second import-time load, and the correction this file grounds is only half right.', ).toMatch(DEFERRED_REQUIRE) expect( readFileSync(resolve(ffi, 'index.cts'), 'utf-8'), - 'packages/protect-ffi/src/index.cts no longer uses `import native = require(...)`. That form is the other half of why importing protect-ffi resolves no platform binary — `import * as` would emit `__importStar`, which enumerates the proxy and forces the load.', + 'languages/typescript/packages/protect-ffi/src/index.cts no longer uses `import native = require(...)`. That form is the other half of why importing protect-ffi resolves no platform binary — `import * as` would emit `__importStar`, which enumerates the proxy and forces the load.', ).toMatch(/import\s+native\s*=\s*require\(/) // The guard that owns this property in full. Duplicating its assertions // here would be a second, weaker copy of it. expect( existsSync(resolve(ffi, 'nativeLoading.test.ts')), - 'packages/protect-ffi/src/nativeLoading.test.ts is gone. It is what holds protect-ffi to deferred loading; without it the two checks above are the only thing left, and they read source rather than emit.', + 'languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts is gone. It is what holds protect-ffi to deferred loading; without it the two checks above are the only thing left, and they read source rather than emit.', ).toBe(true) }) }) diff --git a/languages/typescript/packages/stack-supabase/integration/grants.integration.test.ts b/languages/typescript/packages/stack-supabase/integration/grants.integration.test.ts index 43bfa13e0..e43455b49 100644 --- a/languages/typescript/packages/stack-supabase/integration/grants.integration.test.ts +++ b/languages/typescript/packages/stack-supabase/integration/grants.integration.test.ts @@ -11,7 +11,7 @@ * `permission denied for schema eql_v3_internal` on EVERY encrypted filter: * `=` (eq_term), `>=` (ord_term) and `@>`/`cs` (match_term) alike. * - * `packages/stack/__tests__/supabase-v3-builder.test.ts` cannot see this — it + * `languages/typescript/packages/stack/__tests__/supabase-v3-builder.test.ts` cannot see this — it * records wire strings against a mock. Only a real Postgres can. * * ## Why the grants SQL is imported from `stash` diff --git a/languages/typescript/packages/stack-supabase/package.json b/languages/typescript/packages/stack-supabase/package.json index 91c3d576b..b3f8a1ba5 100644 --- a/languages/typescript/packages/stack-supabase/package.json +++ b/languages/typescript/packages/stack-supabase/package.json @@ -18,7 +18,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/stack-supabase" + "directory": "languages/typescript/packages/stack-supabase" }, "license": "MIT", "author": "CipherStash ", diff --git a/languages/typescript/packages/stack-supabase/src/column-map.ts b/languages/typescript/packages/stack-supabase/src/column-map.ts index 5c8eff0bb..debeba4eb 100644 --- a/languages/typescript/packages/stack-supabase/src/column-map.ts +++ b/languages/typescript/packages/stack-supabase/src/column-map.ts @@ -35,7 +35,7 @@ export type V3ColumnLike = { * on ANY subpath, including `@cipherstash/stack/eql/v3`. * - **ESM does code-split**, so `dist/adapter-kit.js` and `dist/eql/v3/index.js` * share one chunk — but `dist/wasm-inline.js` is a separate esbuild run - * (`packages/stack/tsup.config.ts`) and carries its own copy, so an ESM + * (`languages/typescript/packages/stack/tsup.config.ts`) and carries its own copy, so an ESM * consumer authoring from `@cipherstash/stack/wasm-inline` hit it too. * * Whenever the adapter and the schema resolved different copies, `instanceof` @@ -45,17 +45,17 @@ export type V3ColumnLike = { * `buildColumnKeyMap()` and the encrypt config, not this map). * * The same hazard has a type-level half, fixed separately in - * `packages/stack/tsup.config.ts` and gated by - * `packages/stack/dist-types/wasm-inline-type-identity.ts`. + * `languages/typescript/packages/stack/tsup.config.ts` and gated by + * `languages/typescript/packages/stack/dist-types/wasm-inline-type-identity.ts`. * - * Mirrors `hasBuildColumnKeyMap` (`packages/stack/src/types.ts:276-283`), the + * Mirrors `hasBuildColumnKeyMap` (`languages/typescript/packages/stack/src/types.ts:276-283`), the * repo's canonical answer to the same problem, used identically at * `wasm-inline.ts:1361` — including its spelling: `'k' in obj && typeof (obj as * { k?: unknown }).k === 'function'`, one narrowed probe per member, rather * than one blanket `as Record` over the whole object. * * Four probes, not two: a v2 column builder has `build()` and `getName()` - * (`EncryptedColumn`, `packages/stack/src/schema/index.ts:442,449`) but neither + * (`EncryptedColumn`, `languages/typescript/packages/stack/src/schema/index.ts:442,449`) but neither * `getEqlType()` nor `getQueryCapabilities()` (`eql/v3/columns.ts:445,450`). * * Exported for `__tests__/column-map-predicate.test.ts` only — `column-map.ts` @@ -147,7 +147,7 @@ export class ColumnMap { ) { // FAIL CLOSED at the table level, for the same reason the column loop does // below. `buildColumnKeyMap()` is the canonical v2/v3 discriminator - // (`packages/stack/src/types.ts:276`), and it is also the very first thing + // (`languages/typescript/packages/stack/src/types.ts:276`), and it is also the very first thing // this constructor calls — so a v2 table died on the next line with // `table.buildColumnKeyMap is not a function`, naming an internal method // instead of the version mismatch. The column-level probe cannot cover diff --git a/languages/typescript/packages/stack-supabase/src/index.ts b/languages/typescript/packages/stack-supabase/src/index.ts index 87eac81fb..b320312d5 100644 --- a/languages/typescript/packages/stack-supabase/src/index.ts +++ b/languages/typescript/packages/stack-supabase/src/index.ts @@ -17,7 +17,7 @@ import { eqlRequiresQueryDomains, introspect } from './introspect' * * Not `@cipherstash/protect-ffi`, the graph's other Node-API package: it * deliberately resolves nothing until first use — see - * `packages/protect-ffi/src/index.cts` and the `nativeLoading.test.ts` beside + * `languages/typescript/packages/protect-ffi/src/index.cts` and the `nativeLoading.test.ts` beside * it. And the engine is not the only thing pinning this entry to Node: its own * emitted bundle carries an `import("pg")` specifier for introspection, which * a bundler resolves at build time. `__tests__/wasm-entry-edge-safety.test.ts` diff --git a/languages/typescript/packages/stack-supabase/src/introspect.ts b/languages/typescript/packages/stack-supabase/src/introspect.ts index dec26902e..54af2c1d3 100644 --- a/languages/typescript/packages/stack-supabase/src/introspect.ts +++ b/languages/typescript/packages/stack-supabase/src/introspect.ts @@ -95,7 +95,7 @@ export function groupIntrospectionRows( })) } -// DELIBERATE FORK of packages/cli/src/commands/init/lib/introspect.ts — keep the +// DELIBERATE FORK of languages/typescript/packages/cli/src/commands/init/lib/introspect.ts — keep the // two in sync. `stack` cannot depend on `cli`, and the projections differ: the // CLI detects v2 composites via `udt_name = 'eql_v2_encrypted'`; this reads v3 // domains via `domain_name`. `udt_name` is `jsonb` for a v3 domain column, so it diff --git a/languages/typescript/packages/stack-supabase/src/wasm-inline.ts b/languages/typescript/packages/stack-supabase/src/wasm-inline.ts index 2c8772d9d..55239cbfe 100644 --- a/languages/typescript/packages/stack-supabase/src/wasm-inline.ts +++ b/languages/typescript/packages/stack-supabase/src/wasm-inline.ts @@ -33,7 +33,7 @@ import { adaptWasmEncryption } from './wasm-client-adapter' * options object assembled as a `const` and passed by variable, which is what * a Node → edge port actually holds, type-checked clean and then hit the * runtime throw in `makeEncryptedSupabase`. Mirrors - * `WasmClientConfig.eqlVersion?: never` in `packages/stack/src/wasm-inline.ts` + * `WasmClientConfig.eqlVersion?: never` in `languages/typescript/packages/stack/src/wasm-inline.ts` * — same gap, same fix, one package along. */ export interface EncryptedSupabaseWasmOptions { diff --git a/languages/typescript/packages/stack-supabase/turbo.json b/languages/typescript/packages/stack-supabase/turbo.json index a9955b718..d9c1e75c3 100644 --- a/languages/typescript/packages/stack-supabase/turbo.json +++ b/languages/typescript/packages/stack-supabase/turbo.json @@ -13,7 +13,7 @@ // builds this package, the gate reports 4 skipped, and a regression that // put `@cipherstash/stack` back into the edge graph would ship green. // - // Same fix, same reason, as `packages/stack/turbo.json` — added there in + // Same fix, same reason, as `languages/typescript/packages/stack/turbo.json` — added there in // #799 for the adapter-kit process-free realm gate (#708 review, James). "test": { "dependsOn": ["^build", "build"] diff --git a/languages/typescript/packages/stack/README.md b/languages/typescript/packages/stack/README.md index 060776f47..d3d693220 100644 --- a/languages/typescript/packages/stack/README.md +++ b/languages/typescript/packages/stack/README.md @@ -383,7 +383,7 @@ disclosure, see [SECURITY.md][security-policy]. [MIT licensed][license]. [benches]: https://github.com/cipherstash/benches [eql]: https://github.com/cipherstash/encrypt-query-language [discord]: https://discord.gg/5qwXUFb6PB -[examples]: https://github.com/cipherstash/stack/tree/main/examples +[examples]: https://github.com/cipherstash/stack/tree/main/languages/typescript/examples [contribute]: https://github.com/cipherstash/stack/blob/main/CONTRIBUTING.md [security-policy]: https://github.com/cipherstash/stack/blob/main/SECURITY.md [license]: https://github.com/cipherstash/stack/blob/main/LICENSE.md diff --git a/languages/typescript/packages/stack/__tests__/auth-failure-propagation.test.ts b/languages/typescript/packages/stack/__tests__/auth-failure-propagation.test.ts index 07c4003d4..2eb6db8e9 100644 --- a/languages/typescript/packages/stack/__tests__/auth-failure-propagation.test.ts +++ b/languages/typescript/packages/stack/__tests__/auth-failure-propagation.test.ts @@ -6,7 +6,7 @@ * service token first, so CTS answering `402 USAGE_LIMIT_EXCEEDED` means no * ZeroKMS request is made at all. protect-ffi surfaces that as a thrown `Error` * with `authCode` and stack-auth's `help` (see `Error::auth_error` in - * `packages/protect-ffi/crates/protect-ffi/src/lib.rs`); this asserts the SDK + * `languages/typescript/packages/protect-ffi/crates/protect-ffi/src/lib.rs`); this asserts the SDK * folds the dashboard remedy into `message` and keeps the code for branching. * * Credential-free: protect-ffi is mocked, so there is no CTS round-trip. diff --git a/languages/typescript/packages/stack/__tests__/cjs-require.test.ts b/languages/typescript/packages/stack/__tests__/cjs-require.test.ts index 23be34a17..fcafdc0d2 100644 --- a/languages/typescript/packages/stack/__tests__/cjs-require.test.ts +++ b/languages/typescript/packages/stack/__tests__/cjs-require.test.ts @@ -8,7 +8,7 @@ import { describe, expect, it } from 'vitest' // `ERR_REQUIRE_ESM: Must use import to load ES Module: .../uuid/dist-node/index.js`. // This file proves the published CJS bundles (a) don't contain an // unresolved `require("uuid")` and (b) can be loaded from a real Node CJS -// process. See packages/stack/tsup.config.ts (noExternal: ['uuid']). +// process. See languages/typescript/packages/stack/tsup.config.ts (noExternal: ['uuid']). const packageRoot = path.resolve(__dirname, '..') const distDir = path.join(packageRoot, 'dist') @@ -124,7 +124,7 @@ describe('CJS consumers can require the built bundles', () => { for (const dep of ESM_ONLY_DEPENDENCIES) { expect( externalized.has(dep), - `${entry} externalizes "${dep}" via require(), which is ESM-only and will crash CJS consumers with ERR_REQUIRE_ESM. Add it to noExternal in packages/stack/tsup.config.ts.`, + `${entry} externalizes "${dep}" via require(), which is ESM-only and will crash CJS consumers with ERR_REQUIRE_ESM. Add it to noExternal in languages/typescript/packages/stack/tsup.config.ts.`, ).toBe(false) } }, diff --git a/languages/typescript/packages/stack/__tests__/diagnostics-entry.test.ts b/languages/typescript/packages/stack/__tests__/diagnostics-entry.test.ts index 22089701f..54aeeb9a5 100644 --- a/languages/typescript/packages/stack/__tests__/diagnostics-entry.test.ts +++ b/languages/typescript/packages/stack/__tests__/diagnostics-entry.test.ts @@ -98,7 +98,7 @@ function specifiersOf(bundlePath: string): string[] { * files keeps the checkout untouched and works whether or not the developer * has run `build:native`. * - * Adapted from `packages/protect-ffi/src/lintWiring.test.ts`, which runs its + * Adapted from `languages/typescript/packages/protect-ffi/src/lintWiring.test.ts`, which runs its * own suite under the same hook. `fs` is patched too: a loader that stats the * artifact before requiring it would otherwise see a file that `require` then * refuses to load. @@ -321,7 +321,7 @@ describe('@cipherstash/stack/diagnostics', () => { // execFileSync above. expect(output).toMatch(/^imported /) // Unwrapped: same `code` and the platform package by name, which is what - // `packages/cli/src/native.ts` classifies on. + // `languages/typescript/packages/cli/src/native.ts` classifies on. expect(output).toContain('MODULE_NOT_FOUND') expect(output).toMatch( /Cannot find module '@cipherstash\/protect-ffi-(darwin|linux|win32)-/, diff --git a/languages/typescript/packages/stack/__tests__/encrypt-query.test.ts b/languages/typescript/packages/stack/__tests__/encrypt-query.test.ts index 89008b7b3..1559f2386 100644 --- a/languages/typescript/packages/stack/__tests__/encrypt-query.test.ts +++ b/languages/typescript/packages/stack/__tests__/encrypt-query.test.ts @@ -707,8 +707,8 @@ describe.skipIf(skipWithoutLiveCredentials)('encryptQuery', () => { // // Real coverage lives where the claim can actually resolve, under // CLERK_MACHINE_TOKEN + OidcFederationStrategy: - // packages/stack/integration/identity/matrix-identity.integration.test.ts - // packages/stack-drizzle/integration/lock-context.integration.test.ts + // languages/typescript/packages/stack/integration/identity/matrix-identity.integration.test.ts + // languages/typescript/packages/stack-drizzle/integration/lock-context.integration.test.ts describe('LockContext support', () => { it('single query with a lock context builds an executable operation', async () => { const operation = protectClient.encryptQuery('test@example.com', { diff --git a/languages/typescript/packages/stack/__tests__/helpers/process-free-realm.mjs b/languages/typescript/packages/stack/__tests__/helpers/process-free-realm.mjs index cf1a8be8d..195ceed75 100644 --- a/languages/typescript/packages/stack/__tests__/helpers/process-free-realm.mjs +++ b/languages/typescript/packages/stack/__tests__/helpers/process-free-realm.mjs @@ -7,7 +7,7 @@ * realm (which would hand the module the host's `process` and prove nothing). * Bare specifiers are rejected. The graphs this is pointed at have none today * only because everything they reach is bundled (`noExternal` in - * `packages/stack/tsup.config.ts`) — a property of the build config, not of + * `languages/typescript/packages/stack/tsup.config.ts`) — a property of the build config, not of * module resolution. So a new one is a SIGNAL, not automatically a defect: if * it is a legitimate external the target runtime resolves, allow it here. * diff --git a/languages/typescript/packages/stack/__tests__/logger-edge-safety.test.ts b/languages/typescript/packages/stack/__tests__/logger-edge-safety.test.ts index 7b4b965b2..cb675d5f4 100644 --- a/languages/typescript/packages/stack/__tests__/logger-edge-safety.test.ts +++ b/languages/typescript/packages/stack/__tests__/logger-edge-safety.test.ts @@ -1,9 +1,9 @@ /** * `@cipherstash/stack/adapter-kit` re-exports this package's `logger` * (`src/adapter-kit.ts`), and three first-party adapters value-import - * adapter-kit: `packages/stack-supabase/src/column-map.ts:1`, - * `packages/stack-drizzle/src/column.ts:1`, - * `packages/stack-prisma/src/exports/column-types.ts:19`. A realm with no + * adapter-kit: `languages/typescript/packages/stack-supabase/src/column-map.ts:1`, + * `languages/typescript/packages/stack-drizzle/src/column.ts:1`, + * `languages/typescript/packages/stack-prisma/src/exports/column-types.ts:19`. A realm with no * `process` binding turns an unguarded module-scope `process.env` read in the * logger into a `ReferenceError` at import time on exactly the runtimes those * builds exist to serve. @@ -13,7 +13,7 @@ * * It reads `dist/`, so it SKIPS when the package has not been built — run * `pnpm --filter @cipherstash/stack build` first for it to mean anything. - * `packages/stack/turbo.json` wires `test` to `build`, and the root `build` task + * `languages/typescript/packages/stack/turbo.json` wires `test` to `build`, and the root `build` task * declares `outputs: ["dist/**"]` so a cache hit restores the artefact rather * than replaying logs over a missing one — without that, this gate reported * `1 skipped` while the suite stayed green. A bare `pnpm --filter … test` on an diff --git a/languages/typescript/packages/stack/__tests__/readme-sync.test.ts b/languages/typescript/packages/stack/__tests__/readme-sync.test.ts index 23047a723..0eb716eb8 100644 --- a/languages/typescript/packages/stack/__tests__/readme-sync.test.ts +++ b/languages/typescript/packages/stack/__tests__/readme-sync.test.ts @@ -1,7 +1,7 @@ /** * Guards the npm README against drifting from the root README. * - * `packages/stack/README.md` is a synced copy of the repo root `README.md` — + * `languages/typescript/packages/stack/README.md` is a synced copy of the repo root `README.md` — * the root file is the single source of truth, and the `prebuild` script * copies it into the package before every build (npm cannot publish a * symlink, so a real file must ship in the tarball). If someone edits the @@ -25,7 +25,7 @@ describe('package README', () => { ) expect( pkgReadme, - 'packages/stack/README.md has drifted from the root README — run `pnpm --filter @cipherstash/stack build` and commit the synced copy', + 'languages/typescript/packages/stack/README.md has drifted from the root README — run `pnpm --filter @cipherstash/stack build` and commit the synced copy', ).toBe(rootReadme) }) }) diff --git a/languages/typescript/packages/stack/__tests__/wasm-inline-bundle-isolation.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-bundle-isolation.test.ts index 38f6c5e64..7b680c493 100644 --- a/languages/typescript/packages/stack/__tests__/wasm-inline-bundle-isolation.test.ts +++ b/languages/typescript/packages/stack/__tests__/wasm-inline-bundle-isolation.test.ts @@ -23,7 +23,7 @@ import { describe, expect, it } from 'vitest' // see it — they mock the `/wasm-inline` subpath and run under Node, where the // native root resolves fine — so the assertion has to be on the built artifact. // -// Mirrors `packages/stack-prisma/test/bundling-isolation.test.ts`. +// Mirrors `languages/typescript/packages/stack-prisma/test/bundling-isolation.test.ts`. const packageRoot = path.resolve(fileURLToPath(import.meta.url), '../..') const distDir = path.join(packageRoot, 'dist') diff --git a/languages/typescript/packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts index ec3693e01..411e95f2b 100644 --- a/languages/typescript/packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts +++ b/languages/typescript/packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts @@ -49,7 +49,7 @@ * WHERE IT RUNS, and why not with the rest of the suite. Loading the real * module means loading `dist/wasm/protect_ffi_inline.js`, which wasm-pack * emits and `pnpm install` does not — only the three `.d.ts` beside it are - * tracked. So this file is excluded from `packages/stack/vitest.config.ts` and + * tracked. So this file is excluded from `languages/typescript/packages/stack/vitest.config.ts` and * collected by `vitest.wasm-core.config.ts` instead, run by `test:wasm-core` * from `tests.yml`'s `wasm-e2e-tests` job, the one job that builds it. Left in * the default config it does not skip — it fails to COLLECT, which is what it @@ -327,7 +327,7 @@ describe('protect-ffi WASM core: the strategy is read before the credentials (#8 // `@cipherstash/stack` nor `@cipherstash/stack-supabase` declares a `browser` // export condition — used to be asserted here. It has moved to // `__tests__/browser-export-condition.test.ts` (and its sibling in -// `packages/stack-supabase/__tests__/`), because it only reads a manifest: +// `languages/typescript/packages/stack-supabase/__tests__/`), because it only reads a manifest: // hosted in this file it inherited this file's exclusion from the default // config and so ran in one CI job and in nobody's local test run. Anyone // following #804 wants both files. diff --git a/languages/typescript/packages/stack/__tests__/wasm-inline-v3.test.ts b/languages/typescript/packages/stack/__tests__/wasm-inline-v3.test.ts index 5dd3b7184..fe440c59d 100644 --- a/languages/typescript/packages/stack/__tests__/wasm-inline-v3.test.ts +++ b/languages/typescript/packages/stack/__tests__/wasm-inline-v3.test.ts @@ -129,7 +129,7 @@ describe('wasm-inline is EQL v3 only (#614)', () => { }) // #815: native throws on the PRESENCE of `config.eqlVersion` - // (`Object.hasOwn`, packages/stack/src/encryption/index.ts). The WASM factory + // (`Object.hasOwn`, languages/typescript/packages/stack/src/encryption/index.ts). The WASM factory // had no equivalent, so a JS/JSON caller carrying `eqlVersion: 2` got a hard // error on one entry and silence on the other — the exact entry-disagreement // #815 exists to close. diff --git a/languages/typescript/packages/stack/dist-types/wasm-inline-type-identity.ts b/languages/typescript/packages/stack/dist-types/wasm-inline-type-identity.ts index feef593f1..4bb9fb529 100644 --- a/languages/typescript/packages/stack/dist-types/wasm-inline-type-identity.ts +++ b/languages/typescript/packages/stack/dist-types/wasm-inline-type-identity.ts @@ -1,6 +1,6 @@ /** * The TYPE-level half of the two-copies-of-a-class hazard that `isV3ColumnLike` - * (`packages/stack-supabase/src/column-map.ts`) fixed at runtime. + * (`languages/typescript/packages/stack-supabase/src/column-map.ts`) fixed at runtime. * * `EncryptedV3Column` carries `private readonly columnName`, and TypeScript * compares classes with private members by DECLARATION ORIGIN, not @@ -27,7 +27,7 @@ * * Lives here rather than in a `test-d`/vitest typecheck suite because those * resolve `@cipherstash/stack/*` to `../stack/src` (see - * `packages/stack-supabase/tsconfig.json`) — source against source, which never + * `languages/typescript/packages/stack-supabase/tsconfig.json`) — source against source, which never * sees how the subpaths resolve for an installed consumer. Only a gate that * reads `dist/` can. This one uses `moduleResolution: bundler` over relative * paths; `node16/wasm-inline.mts` asserts the same thing by package name through @@ -58,7 +58,7 @@ const wasmUsers = wasmEncryptedTable('users', { * * `@cipherstash/stack-supabase` is the concrete case, and this line is what * replaced a text-level guard over it. `V3Schemas = Record` - * (`packages/stack-supabase/src/schema-builder.ts:7`) imports `AnyV3Table` from + * (`languages/typescript/packages/stack-supabase/src/schema-builder.ts:7`) imports `AnyV3Table` from * `@cipherstash/stack/eql/v3` — the same declaration resolved here — so pinning * assignability to it pins the adapter pairing too, without this package taking * a build-graph dependency on one that depends on it. diff --git a/languages/typescript/packages/stack/integration/vitest.config.ts b/languages/typescript/packages/stack/integration/vitest.config.ts index 25e732b0e..255a8803f 100644 --- a/languages/typescript/packages/stack/integration/vitest.config.ts +++ b/languages/typescript/packages/stack/integration/vitest.config.ts @@ -10,7 +10,7 @@ import { /** * Integration suites: real ZeroKMS, real Postgres, real PostgREST. * - * Deliberately a SEPARATE config from `packages/stack/vitest.config.ts`, which + * Deliberately a SEPARATE config from `languages/typescript/packages/stack/vitest.config.ts`, which * excludes `integration/**`. `pnpm test` must stay runnable with no credentials * and no database; these run only under `test:integration:*`, from their own CI * jobs. That separation is what lets the integration suites throw on missing diff --git a/languages/typescript/packages/stack/integration/wasm/adapter.ts b/languages/typescript/packages/stack/integration/wasm/adapter.ts index 845fbec80..8c580e5ed 100644 --- a/languages/typescript/packages/stack/integration/wasm/adapter.ts +++ b/languages/typescript/packages/stack/integration/wasm/adapter.ts @@ -12,7 +12,7 @@ * term → query-domain cast → indexed operator → correct row set. * * The SQL shapes deliberately mirror the Drizzle v3 dialect - * (`packages/stack-drizzle/src/v3/sql-dialect.ts`): `eq`/`neq`, comparison + * (`languages/typescript/packages/stack-drizzle/src/v3/sql-dialect.ts`): `eq`/`neq`, comparison * fns, parenthesised `gte AND lte` ranges, `contains` for bloom matching, and * `ord_term` ordering. `in`/`notIn` decompose to OR-of-eq / AND-of-neq over * one `encryptQueryBulk` batch — exercising the bulk path on every family. diff --git a/languages/typescript/packages/stack/package.json b/languages/typescript/packages/stack/package.json index 8f3dbc7e0..9e1febef4 100644 --- a/languages/typescript/packages/stack/package.json +++ b/languages/typescript/packages/stack/package.json @@ -16,7 +16,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/stack" + "directory": "languages/typescript/packages/stack" }, "license": "MIT", "author": "CipherStash ", diff --git a/languages/typescript/packages/stack/scripts/install-eql-v3.ts b/languages/typescript/packages/stack/scripts/install-eql-v3.ts index 2df1b1324..96c32f888 100644 --- a/languages/typescript/packages/stack/scripts/install-eql-v3.ts +++ b/languages/typescript/packages/stack/scripts/install-eql-v3.ts @@ -4,7 +4,7 @@ import { config } from 'dotenv' // same key, since dotenv does not overwrite already-set vars). `quiet: true` // suppresses dotenv v17's `injected env (N) from …` banner so this script does // not print noisy, non-deterministic lines in CI. Mirrors the CLI entrypoint -// (packages/cli/src/bin/main.ts). +// (languages/typescript/packages/cli/src/bin/main.ts). config({ path: '.env.local', quiet: true }) config({ path: '.env.development.local', quiet: true }) config({ path: '.env.development', quiet: true }) diff --git a/languages/typescript/packages/stack/src/adapter-kit.ts b/languages/typescript/packages/stack/src/adapter-kit.ts index 630544759..754d8c590 100644 --- a/languages/typescript/packages/stack/src/adapter-kit.ts +++ b/languages/typescript/packages/stack/src/adapter-kit.ts @@ -36,7 +36,7 @@ export type { AuditConfig } from './encryption/operations/base-operation.js' // check silently fails for any consumer who resolved a different copy. That is // how encrypted filter operands once reached PostgREST in plaintext. Probe // structurally instead, as `isV3ColumnLike` -// (`packages/stack-supabase/src/column-map.ts`) and `hasBuildColumnKeyMap` +// (`languages/typescript/packages/stack-supabase/src/column-map.ts`) and `hasBuildColumnKeyMap` // (`src/types.ts`) do. export { type AnyEncryptedV3Column, diff --git a/languages/typescript/packages/stack/tsconfig.json b/languages/typescript/packages/stack/tsconfig.json index 7b8c05f90..8b325a52b 100644 --- a/languages/typescript/packages/stack/tsconfig.json +++ b/languages/typescript/packages/stack/tsconfig.json @@ -42,7 +42,7 @@ // `@/`). `tsc` does not read Vitest's `resolve.alias`, so without these // the catalog's builders lose their precise return types and the // `.test-d.ts` matrix collapses to `never`. Mirrors `vitest.shared.ts` - // and `packages/test-kit/tsconfig.json`; keep the three in step. + // and `languages/typescript/packages/test-kit/tsconfig.json`; keep the three in step. "@cipherstash/test-kit": ["../test-kit/src/index.ts"], "@cipherstash/test-kit/suite": ["../test-kit/src/run-family-suite.ts"], "@cipherstash/test-kit/integration-clerk": [ diff --git a/languages/typescript/packages/stack/vitest.config.ts b/languages/typescript/packages/stack/vitest.config.ts index 52cebe7d2..d78023872 100644 --- a/languages/typescript/packages/stack/vitest.config.ts +++ b/languages/typescript/packages/stack/vitest.config.ts @@ -9,7 +9,7 @@ export default defineConfig({ // and the `/wasm-inline` stubs (`src/wasm-inline.ts` imports subpaths Vitest // can't resolve; unit tests that only touch pure helpers load the stub, tests // needing real WASM mock the specifiers explicitly). Both point at fixed - // locations under packages/stack, so they live in vitest.shared. + // locations under languages/typescript/packages/stack, so they live in vitest.shared. alias: { ...sharedAlias, ...stackSourceAlias }, }, test: { diff --git a/languages/typescript/packages/stack/vitest.wasm-core.config.ts b/languages/typescript/packages/stack/vitest.wasm-core.config.ts index 92eb96bed..8e7f94f0a 100644 --- a/languages/typescript/packages/stack/vitest.wasm-core.config.ts +++ b/languages/typescript/packages/stack/vitest.wasm-core.config.ts @@ -1,7 +1,7 @@ import { defineConfig } from 'vitest/config' /** - * The one suite in `packages/stack` that loads the REAL protect-ffi WASM core + * The one suite in `languages/typescript/packages/stack` that loads the REAL protect-ffi WASM core * outside the integration harness. It is in neither of the package's other two * configs — excluded from `vitest.config.ts` (see WHERE IT RUNS below) and not * joined to `integration/vitest.config.ts` — which is what this third one is @@ -16,14 +16,14 @@ import { defineConfig } from 'vitest/config' * assertion lands before the first network call. That is what puts it in an * awkward middle. It cannot stay with the unit suites, and joining the * integration suites would give it dependencies it does not have: - * `packages/test-kit/src/integration/global-setup.ts` requires credentials AND + * `languages/typescript/packages/test-kit/src/integration/global-setup.ts` requires credentials AND * a database unconditionally (it throws rather than skips, then runs a real * `stash eql install`), and `integration-drizzle.yml`, the workflow that runs * them, is path-filtered, fork-skipped and matrixed over two databases. A * contract about the core would then go unchecked on any diff those paths do * not select. * - * So: a SEPARATE config from `packages/stack/vitest.config.ts`, for the same + * So: a SEPARATE config from `languages/typescript/packages/stack/vitest.config.ts`, for the same * reason `integration/vitest.config.ts` is one — the default suite has to run * with nothing but a checkout and `pnpm install`, and this file needs a build * that neither of those produces. diff --git a/languages/typescript/packages/test-kit/src/install.ts b/languages/typescript/packages/test-kit/src/install.ts index 04b73324e..abd2fdc5a 100644 --- a/languages/typescript/packages/test-kit/src/install.ts +++ b/languages/typescript/packages/test-kit/src/install.ts @@ -6,9 +6,12 @@ import { promisify } from 'node:util' const execFileAsync = promisify(execFile) -/** `packages/test-kit/src` → repo root. */ +/** `languages/typescript/packages/test-kit/src` → repo root. */ const REPO_ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '../../..') -const STASH_BIN = resolve(REPO_ROOT, 'packages/cli/dist/bin/stash.js') +const STASH_BIN = resolve( + REPO_ROOT, + 'languages/typescript/packages/cli/dist/bin/stash.js', +) export type DbVariant = 'postgres' | 'supabase' diff --git a/languages/typescript/packages/test-kit/tsconfig.json b/languages/typescript/packages/test-kit/tsconfig.json index 0730f54fb..f70310a32 100644 --- a/languages/typescript/packages/test-kit/tsconfig.json +++ b/languages/typescript/packages/test-kit/tsconfig.json @@ -11,7 +11,7 @@ "verbatimModuleSyntax": true, "noEmit": true, - // Mirrors `packages/stack/tsconfig.json`: protect-ffi 0.24+ uses + // Mirrors `languages/typescript/packages/stack/tsconfig.json`: protect-ffi 0.24+ uses // conditional exports, and bundler resolution omits `node` by default. "customConditions": ["node"], diff --git a/languages/typescript/packages/wizard/package.json b/languages/typescript/packages/wizard/package.json index 5bc82a125..439f54d75 100644 --- a/languages/typescript/packages/wizard/package.json +++ b/languages/typescript/packages/wizard/package.json @@ -5,7 +5,7 @@ "repository": { "type": "git", "url": "git+https://github.com/cipherstash/stack.git", - "directory": "packages/wizard" + "directory": "languages/typescript/packages/wizard" }, "license": "MIT", "author": "CipherStash ", diff --git a/languages/typescript/packages/wizard/src/__tests__/install-skills.test.ts b/languages/typescript/packages/wizard/src/__tests__/install-skills.test.ts index 0dfffe5ea..af3c64101 100644 --- a/languages/typescript/packages/wizard/src/__tests__/install-skills.test.ts +++ b/languages/typescript/packages/wizard/src/__tests__/install-skills.test.ts @@ -2,7 +2,7 @@ import { beforeEach, describe, expect, it, vi } from 'vitest' // Hermetic: mock the filesystem and prompts so the tests drive the failure // paths directly. The real-FS behaviour is covered by the `stash` CLI's copy -// of this logic (packages/cli install-skills.test.ts); this file pins the +// of this logic (languages/typescript/packages/cli install-skills.test.ts); this file pins the // wizard copy's never-throw contract, which previously had no coverage — // exactly how the original unguarded mkdirSync shipped twice (see // cipherstash/stack#736). diff --git a/languages/typescript/packages/wizard/src/__tests__/post-agent.test.ts b/languages/typescript/packages/wizard/src/__tests__/post-agent.test.ts index 96286900c..3e2f4c6d4 100644 --- a/languages/typescript/packages/wizard/src/__tests__/post-agent.test.ts +++ b/languages/typescript/packages/wizard/src/__tests__/post-agent.test.ts @@ -346,7 +346,7 @@ describe('drizzle migrate prompt after a staged rewrite', () => { // to sit after a `continue`, so the wizard surfaced neither: the user was told // a directory failed without being told which of its files had changed or // what it had flagged. The CLI twin has always reported the partial set - // (`packages/cli/src/commands/eql/migration.ts`). #837. + // (`languages/typescript/packages/cli/src/commands/eql/migration.ts`). #837. // // Mocked, unlike the tests above: the throw has to land *inside* the rewrite // loop to leave a partial set behind, which needs a mid-loop `writeFile` diff --git a/languages/typescript/packages/wizard/src/__tests__/rewrite-migrations.test.ts b/languages/typescript/packages/wizard/src/__tests__/rewrite-migrations.test.ts index 8e2e16933..a10d7bb67 100644 --- a/languages/typescript/packages/wizard/src/__tests__/rewrite-migrations.test.ts +++ b/languages/typescript/packages/wizard/src/__tests__/rewrite-migrations.test.ts @@ -204,7 +204,7 @@ describe('rewriteEncryptedAlterColumns', () => { }) // Every concrete `eql_v3_*` domain shipped by `@cipherstash/stack/eql/v3` - // (see `packages/stack/src/eql/v3/columns.ts`). Eight scalar bases carry the + // (see `languages/typescript/packages/stack/src/eql/v3/columns.ts`). Eight scalar bases carry the // four storage/eq/ord flavours; text adds `_match`/`_search`; boolean and json // stand alone. const V3_SCALAR_BASES = [ diff --git a/languages/typescript/packages/wizard/src/agent/interface.ts b/languages/typescript/packages/wizard/src/agent/interface.ts index e70c8e481..4cee97c3a 100644 --- a/languages/typescript/packages/wizard/src/agent/interface.ts +++ b/languages/typescript/packages/wizard/src/agent/interface.ts @@ -117,7 +117,7 @@ const SENSITIVE_FILE_PATTERNS = [ // `.env`, `.env.local`, `.env.production`, … but not the committed templates // `.env.example` / `.env.sample` / `.env.template`. Those carry placeholder // key names rather than values, and the agent doctrine - // (`packages/cli/src/commands/init/doctrine/AGENTS-doctrine.md`, invariant 3) + // (`languages/typescript/packages/cli/src/commands/init/doctrine/AGENTS-doctrine.md`, invariant 3) // instructs the agent to create and edit them — a blanket `.env.` rule made // that impossible, since this guard also covers Edit and Write. // diff --git a/languages/typescript/packages/wizard/src/lib/post-agent.ts b/languages/typescript/packages/wizard/src/lib/post-agent.ts index 3b0df666a..6be946cfe 100644 --- a/languages/typescript/packages/wizard/src/lib/post-agent.ts +++ b/languages/typescript/packages/wizard/src/lib/post-agent.ts @@ -208,7 +208,7 @@ async function rewriteEncryptedMigrations(cwd: string): Promise<{ // partial set on the failure path. Skipping the reporting below would // leave the user with a failure and no list of what it changed before it // stopped. The CLI twin reports the partial set for the same reason — - // `packages/cli/src/commands/eql/migration.ts` (#786, #837). + // `languages/typescript/packages/cli/src/commands/eql/migration.ts` (#786, #837). } if (rewritten.length > 0) { diff --git a/languages/typescript/packages/wizard/src/lib/rewrite-migrations.ts b/languages/typescript/packages/wizard/src/lib/rewrite-migrations.ts index 0a152f3be..b1ff1984a 100644 --- a/languages/typescript/packages/wizard/src/lib/rewrite-migrations.ts +++ b/languages/typescript/packages/wizard/src/lib/rewrite-migrations.ts @@ -47,7 +47,7 @@ const DOMAIN_RE = new RegExp(ENCRYPTED_DOMAIN, 'i') * Ordered longest-first so the alternation cannot match a prefix of a longer * form and leave a trailing fragment behind. * - * NOTE: this file is the sibling of `packages/cli/src/commands/db/rewrite-migrations.ts`, + * NOTE: this file is the sibling of `languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts`, * which cli's `stash eql migration --drizzle` uses. Both are tightly coupled to * drizzle-kit's output format — if drizzle-kit changes, both need updating * together. Keep them in sync. @@ -1222,7 +1222,7 @@ export async function rewriteEncryptedAlterColumns( } // #region wizard-only — deliberately has no counterpart in -// packages/cli/src/commands/db/rewrite-migrations.ts. Everything OUTSIDE this +// languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts. Everything OUTSIDE this // region is mirrored there byte-for-byte and is checked by // scripts/__tests__/rewriter-copies-in-sync.test.mjs. Only the wizard sweeps // several candidate directories; both CLI call sites pass one explicit --out. @@ -1375,7 +1375,7 @@ function renderSafeAlter( // the TABLE's schema (from a pgSchema() table) and says nothing about where // the domain lives. If EQL ever supports installing into a non-`public` // schema, this needs the install schema threaded in, here and in the - // sibling `packages/cli/src/commands/db/rewrite-migrations.ts`. + // sibling `languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts`. `ALTER TABLE ${qualifiedTable} ADD COLUMN "${encrypted}" "public"."${domain}";`, ].join('\n') } diff --git a/languages/typescript/packages/wizard/tsconfig.json b/languages/typescript/packages/wizard/tsconfig.json index d85358a58..97e2dfbd5 100644 --- a/languages/typescript/packages/wizard/tsconfig.json +++ b/languages/typescript/packages/wizard/tsconfig.json @@ -14,8 +14,8 @@ // not include `node` by default, so without this the wizard's three // `auth.AutoStrategy` call sites fail to typecheck even though they run // fine — the wizard is a Node CLI and always loads the `node` branch. - // Matches `packages/stack`, `packages/stack-prisma`, `packages/test-kit`, - // `packages/stack-drizzle` and `packages/stack-supabase`. + // Matches `languages/typescript/packages/stack`, `languages/typescript/packages/stack-prisma`, `languages/typescript/packages/test-kit`, + // `languages/typescript/packages/stack-drizzle` and `languages/typescript/packages/stack-supabase`. "customConditions": ["node"], "allowImportingTsExtensions": true, diff --git a/package.json b/package.json index 18f1d96bc..3163f4ab4 100644 --- a/package.json +++ b/package.json @@ -20,12 +20,12 @@ }, "license": "MIT", "scripts": { - "build": "turbo build --filter './packages/*'", - "build:js": "turbo build --filter './packages/nextjs'", + "build": "turbo build --filter './languages/typescript/packages/*'", + "build:js": "turbo build --filter './languages/typescript/packages/nextjs'", "changeset": "changeset", "changeset:version": "pnpm run version", "changeset:publish": "pnpm run release", - "dev": "turbo dev --filter './packages/**'", + "dev": "turbo dev --filter './languages/typescript/packages/**'", "clean": "rimraf --glob **/.next **/.turbo **/dist **/node_modules", "code:fix": "biome check --write", "code:check": "biome check", @@ -37,7 +37,7 @@ "release:gate": "node scripts/release-gate.mjs", "version": "changeset version && node scripts/sync-lockstep-versions.mjs", "release": "pnpm run build && changeset publish", - "test": "turbo test --filter './packages/**'", + "test": "turbo test --filter './languages/typescript/packages/**'", "test:e2e": "turbo run test:e2e", "test:scripts": "vitest run --config scripts/vitest.config.mjs" }, diff --git a/packages/eql/AGENTS.md b/packages/eql/AGENTS.md index c93cf39af..b6e5e1929 100644 --- a/packages/eql/AGENTS.md +++ b/packages/eql/AGENTS.md @@ -243,7 +243,7 @@ Because SQL, the crate, and npm all release in lockstep at one version, **every User-facing means: someone outside EQL would care. If in doubt, add the changeset; it's cheap. -**Every EQL release needs a `@cipherstash/stack-prisma` migration on `main` before its Version Packages PR merges** — even a release whose only SQL change is the version stamp. `stack-prisma` bakes the install SQL into content-addressed migrations, and its lockstep test (`packages/stack-prisma/test/v3/migration-v3.test.ts`) requires the installed release's `installSqlSha256` to be baked by some migration. The Version Packages PR is what moves that digest, so its own CI fails until the migration exists: 3.0.6 changed only `eql_v3.version()` and the schema comment, and still failed `cipherstash/stack#938`. Build the migration from the release's SQL (the Version Packages branch has it) — see `packages/stack-prisma/DEVELOPING.md`. +**Every EQL release needs a `@cipherstash/stack-prisma` migration on `main` before its Version Packages PR merges** — even a release whose only SQL change is the version stamp. `stack-prisma` bakes the install SQL into content-addressed migrations, and its lockstep test (`languages/typescript/packages/stack-prisma/test/v3/migration-v3.test.ts`) requires the installed release's `installSqlSha256` to be baked by some migration. The Version Packages PR is what moves that digest, so its own CI fails until the migration exists: 3.0.6 changed only `eql_v3.version()` and the schema comment, and still failed `cipherstash/stack#938`. Build the migration from the release's SQL (the Version Packages branch has it) — see `languages/typescript/packages/stack-prisma/DEVELOPING.md`. What does *not* need an entry: diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 59828c3d1..e0f4875bb 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -96,13 +96,13 @@ importers: dependencies: '@cipherstash/stack': specifier: workspace:* - version: link:../packages/stack + version: link:../languages/typescript/packages/stack '@cipherstash/wizard': specifier: workspace:* - version: link:../packages/wizard + version: link:../languages/typescript/packages/wizard stash: specifier: workspace:* - version: link:../packages/cli + version: link:../languages/typescript/packages/cli devDependencies: '@types/semver': specifier: 7.8.0 @@ -120,7 +120,7 @@ importers: specifier: ^2.9.0 version: 2.9.0 - examples/basic: + languages/typescript/examples/basic: dependencies: '@cipherstash/stack': specifier: workspace:* @@ -148,7 +148,7 @@ importers: specifier: catalog:repo version: 5.9.3 - examples/prisma: + languages/typescript/examples/prisma: dependencies: '@cipherstash/stack': specifier: workspace:* @@ -179,9 +179,9 @@ importers: specifier: catalog:repo version: 4.1.11(@types/node@22.20.1)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@22.20.1)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - examples/supabase-worker: {} + languages/typescript/examples/supabase-worker: {} - packages/bench: + languages/typescript/packages/bench: dependencies: '@cipherstash/stack': specifier: workspace:* @@ -215,14 +215,14 @@ importers: specifier: catalog:repo version: 4.1.11(@types/node@22.20.1)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@22.20.1)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - packages/cli: + languages/typescript/packages/cli: dependencies: '@cipherstash/auth': specifier: catalog:repo version: 0.44.0(@cipherstash/auth-darwin-arm64@0.44.0)(@cipherstash/auth-darwin-x64@0.44.0)(@cipherstash/auth-linux-arm64-gnu@0.44.0)(@cipherstash/auth-linux-x64-gnu@0.44.0)(@cipherstash/auth-linux-x64-musl@0.44.0)(@cipherstash/auth-win32-x64-msvc@0.44.0) '@cipherstash/eql': specifier: workspace:* - version: link:../eql/packages/eql + version: link:../../../../packages/eql/packages/eql '@cipherstash/migrate': specifier: workspace:* version: link:../migrate @@ -298,22 +298,7 @@ importers: specifier: catalog:repo version: 0.44.0 - packages/eql/packages/eql: - devDependencies: - '@types/node': - specifier: catalog:repo - version: 22.20.1 - tsup: - specifier: catalog:repo - version: 8.5.1(jiti@2.7.0)(postcss@8.5.26)(tsx@4.23.12)(typescript@5.9.3)(yaml@2.9.0) - typescript: - specifier: catalog:repo - version: 5.9.3 - vitest: - specifier: catalog:repo - version: 4.1.11(@types/node@22.20.1)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@22.20.1)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - - packages/migrate: + languages/typescript/packages/migrate: dependencies: zod: specifier: ^3.25.76 @@ -341,7 +326,7 @@ importers: specifier: catalog:repo version: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@26.2.0)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - packages/nextjs: + languages/typescript/packages/nextjs: dependencies: jose: specifier: ^6.2.9 @@ -370,7 +355,7 @@ importers: specifier: 4.62.4 version: 4.62.4 - packages/protect-ffi: + languages/typescript/packages/protect-ffi: dependencies: '@neon-rs/load': specifier: ^0.2.6 @@ -414,7 +399,7 @@ importers: specifier: workspace:* version: link:platforms/win32-x64-msvc - packages/protect-ffi/integration-tests: + languages/typescript/packages/protect-ffi/integration-tests: dependencies: '@cipherstash/auth': specifier: catalog:repo @@ -428,7 +413,7 @@ importers: devDependencies: '@cipherstash/eql': specifier: workspace:^ - version: link:../../eql/packages/eql + version: link:../../../../../packages/eql/packages/eql '@types/pg': specifier: ^8.23.1 version: 8.23.1 @@ -445,19 +430,19 @@ importers: specifier: catalog:repo version: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@26.2.0)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - packages/protect-ffi/platforms/darwin-arm64: {} + languages/typescript/packages/protect-ffi/platforms/darwin-arm64: {} - packages/protect-ffi/platforms/darwin-x64: {} + languages/typescript/packages/protect-ffi/platforms/darwin-x64: {} - packages/protect-ffi/platforms/linux-arm64-gnu: {} + languages/typescript/packages/protect-ffi/platforms/linux-arm64-gnu: {} - packages/protect-ffi/platforms/linux-x64-gnu: {} + languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu: {} - packages/protect-ffi/platforms/linux-x64-musl: {} + languages/typescript/packages/protect-ffi/platforms/linux-x64-musl: {} - packages/protect-ffi/platforms/win32-x64-msvc: {} + languages/typescript/packages/protect-ffi/platforms/win32-x64-msvc: {} - packages/stack: + languages/typescript/packages/stack: dependencies: '@byteslice/result': specifier: 0.2.0 @@ -480,7 +465,7 @@ importers: devDependencies: '@cipherstash/eql': specifier: workspace:^ - version: link:../eql/packages/eql + version: link:../../../../packages/eql/packages/eql '@clack/prompts': specifier: ^1.7.0 version: 1.7.0 @@ -555,7 +540,7 @@ importers: specifier: catalog:repo version: 0.44.0 - packages/stack-drizzle: + languages/typescript/packages/stack-drizzle: dependencies: '@byteslice/result': specifier: 0.2.0 @@ -592,11 +577,11 @@ importers: specifier: catalog:repo version: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@26.2.0)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - packages/stack-prisma: + languages/typescript/packages/stack-prisma: dependencies: '@cipherstash/eql': specifier: workspace:* - version: link:../eql/packages/eql + version: link:../../../../packages/eql/packages/eql '@cipherstash/stack': specifier: workspace:* version: link:../stack @@ -641,7 +626,7 @@ importers: specifier: catalog:repo version: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@26.2.0)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - packages/stack-supabase: + languages/typescript/packages/stack-supabase: dependencies: '@cipherstash/stack': specifier: workspace:* @@ -687,7 +672,7 @@ importers: specifier: catalog:repo version: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@26.2.0)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - packages/test-kit: + languages/typescript/packages/test-kit: dependencies: '@cipherstash/stack': specifier: workspace:* @@ -703,7 +688,7 @@ importers: specifier: catalog:repo version: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@26.2.0)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) - packages/wizard: + languages/typescript/packages/wizard: dependencies: '@anthropic-ai/claude-agent-sdk': specifier: ^0.3.234 @@ -768,6 +753,21 @@ importers: specifier: catalog:repo version: 0.44.0 + packages/eql/packages/eql: + devDependencies: + '@types/node': + specifier: catalog:repo + version: 22.20.1 + tsup: + specifier: catalog:repo + version: 8.5.1(jiti@2.7.0)(postcss@8.5.26)(tsx@4.23.12)(typescript@5.9.3)(yaml@2.9.0) + typescript: + specifier: catalog:repo + version: 5.9.3 + vitest: + specifier: catalog:repo + version: 4.1.11(@types/node@22.20.1)(@vitest/coverage-v8@4.1.11)(vite@7.3.6(@types/node@22.20.1)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.44.1)(tsx@4.23.12)(yaml@2.9.0)) + packages: '@anthropic-ai/claude-agent-sdk-darwin-arm64@0.3.234': diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index a2a838bdc..9f0419a8b 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -1,19 +1,19 @@ packages: - - packages/* + - languages/typescript/packages/* # The six per-platform binary packages for @cipherstash/protect-ffi. The - # `packages/*` glob above already covers the wrapper itself; these are nested + # `languages/typescript/packages/*` glob above already covers the wrapper itself; these are nested # a level deeper and need their own entry. - - packages/protect-ffi/platforms/* + - languages/typescript/packages/protect-ffi/platforms/* # @cipherstash/eql, from the encrypt-query-language subtree. The subtree is # imported at a VERBATIM prefix so its repo-root-relative paths keep resolving # (mise tasks, Doxyfile, sync-generated.mjs), which puts the npm package two - # levels down. `packages/*` matches the subtree ROOT, which carries no + # levels down. `languages/typescript/packages/*` matches the subtree ROOT, which carries no # package.json by design — the private @cipherstash/eql-workspace manifest was # deleted so this glob contributes exactly one member. - packages/eql/packages/* # The protect-ffi live integration suite. Nested a level deeper than - # `packages/*` reaches, like the two entries above, and named literally - # rather than globbed because `packages/protect-ffi/*` would also select + # `languages/typescript/packages/*` reaches, like the two entries above, and named literally + # rather than globbed because `languages/typescript/packages/protect-ffi/*` would also select # `crates/`, `docs/`, `lib/`, `scripts/` and `src/` — directories with no # package.json, which pnpm rejects rather than skips. # @@ -23,8 +23,8 @@ packages: # published bundle while the payloads under test came from the in-tree # `eql-bindings` — exactly the skew the subtree import exists to make # unrepresentable. - - packages/protect-ffi/integration-tests - - examples/* + - languages/typescript/packages/protect-ffi/integration-tests + - languages/typescript/examples/* - e2e catalogs: @@ -75,7 +75,7 @@ catalogs: # Related, but NOT fixable as an override: @anthropic-ai/sdk (alert #128, # GHSA-p7fg-763f-g4gf) is an auto-installed *peer* of claude-agent-sdk, and # pnpm overrides rewrite peer ranges, not peer resolutions. It is fixed by an -# explicit dependency in packages/wizard — that dep is a peer-resolution pin +# explicit dependency in languages/typescript/packages/wizard — that dep is a peer-resolution pin # (wizard never imports the sdk directly); do not remove it as "unused". overrides: # #96, #115-#127 — Next.js middleware bypass / SSRF / DoS / XSS batch @@ -189,7 +189,7 @@ blockExoticSubdeps: true # @cipherstash/eql was listed here until the encrypt-query-language subtree # landed. It is now a workspace package, so no pnpm install ever resolves it # from the registry and the entry became dead config. The last holdout was -# packages/protect-ffi/integration-tests, which pinned it by version and +# languages/typescript/packages/protect-ffi/integration-tests, which pinned it by version and # installed with `npm ci` — outside pnpm entirely, so minimumReleaseAge never # applied there either. That directory is a workspace member as of CIP-3744 and # resolves `workspace:^`, so there is now nothing in the tree that could. diff --git a/scripts/__tests__/bench-index-expressions.test.mjs b/scripts/__tests__/bench-index-expressions.test.mjs index ea50f41c3..624ab6081 100644 --- a/scripts/__tests__/bench-index-expressions.test.mjs +++ b/scripts/__tests__/bench-index-expressions.test.mjs @@ -23,7 +23,9 @@ import { REPO_ROOT } from './lib/repo-root.mjs' // bench's own EXPLAIN assertions require CipherStash credentials and never run // in CI. -const require = createRequire(resolve(REPO_ROOT, 'packages/cli/package.json')) +const require = createRequire( + resolve(REPO_ROOT, 'languages/typescript/packages/cli/package.json'), +) /** * The EQL v3 bundle `stash eql install --eql-version 3` applies. @@ -70,7 +72,7 @@ function eqlCalls(fragment) { } const SCHEMA_SQL = readFileSync( - resolve(REPO_ROOT, 'packages/bench/sql/schema.sql'), + resolve(REPO_ROOT, 'languages/typescript/packages/bench/sql/schema.sql'), 'utf8', ) diff --git a/scripts/__tests__/cargo-lock-freshness.test.mjs b/scripts/__tests__/cargo-lock-freshness.test.mjs index f37983d3f..ce942ba84 100644 --- a/scripts/__tests__/cargo-lock-freshness.test.mjs +++ b/scripts/__tests__/cargo-lock-freshness.test.mjs @@ -11,7 +11,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * * `scripts/sync-lockstep-versions.mjs` rewrites * `packages/eql/crates/eql-bindings/Cargo.toml` on every lockstep bump — that - * is its job. `packages/protect-ffi` depends on that crate BY PATH + * is its job. `languages/typescript/packages/protect-ffi` depends on that crate BY PATH * (`crates/protect-ffi/Cargo.toml`), so its `Cargo.lock` records the version * too, and nothing was updating it. After the 3.0.5 bump the lock still said * `eql-bindings 3.0.4` and `cargo metadata --locked` exited 101. @@ -26,7 +26,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * * `--locked` is the exact check and it needs a Rust toolchain. `AGENTS.md` is * explicit that the default `test` and `build` scripts must never invoke cargo - * — root `pnpm test` reaches `packages/protect-ffi`, so a cargo call on that + * — root `pnpm test` reaches `languages/typescript/packages/protect-ffi`, so a cargo call on that * path is a Rust toolchain on every contributor's machine — and `pnpm run * test:scripts` has the same reach, since everyone runs it. * @@ -36,7 +36,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * narrower than `--locked` — a lock stale because a crate gained a NEW * dependency still passes here — but it is the whole of the lockstep failure * mode, it runs everywhere, and it costs nothing. Pairing it with a `--locked` - * invocation on `packages/protect-ffi`'s `test:cargo` path would close the + * invocation on `languages/typescript/packages/protect-ffi`'s `test:cargo` path would close the * remainder; that script is owned elsewhere. */ @@ -174,7 +174,7 @@ describe('Cargo.lock records this tree’s crates at their real versions', () => }) it('locks each crate at the version its Cargo.toml declares', () => { - // THE DEFECT. `packages/protect-ffi/Cargo.lock` said `eql-bindings 3.0.4` + // THE DEFECT. `languages/typescript/packages/protect-ffi/Cargo.lock` said `eql-bindings 3.0.4` // while the crate said 3.0.5, because the lockstep sync rewrote the // manifest and no command in this repo passes `--locked`. const offenders = PAIRS.filter( diff --git a/scripts/__tests__/cargo-publish-opt-out.test.mjs b/scripts/__tests__/cargo-publish-opt-out.test.mjs index 77a8b446d..41d2b7a90 100644 --- a/scripts/__tests__/cargo-publish-opt-out.test.mjs +++ b/scripts/__tests__/cargo-publish-opt-out.test.mjs @@ -15,7 +15,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * * ## Why both, and why that took a second pass * - * This checked `packages/protect-ffi` ONLY, on the reasoning — written in this + * This checked `languages/typescript/packages/protect-ffi` ONLY, on the reasoning — written in this * header — that the repo "is about to grow a crates.io publisher * (`eql-bindings`, via release-plz, when `cipherstash/encrypt-query-language` * is absorbed)". The absorption happened. The publisher landed as @@ -24,7 +24,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * workspace this file did not read. The check was strictest exactly where * nothing could publish and absent where something can. * - * `packages/protect-ffi/crates/protect-ffi` carries no `publish` key and is + * `languages/typescript/packages/protect-ffi/crates/protect-ffi` carries no `publish` key and is * nonetheless correct: it has never been on crates.io (verified against the * registry API), it is a cdylib compiled into `index.node` and shipped inside * the six `@cipherstash/protect-ffi-` npm packages, and nothing @@ -46,7 +46,7 @@ const WORKSPACES = [ expects: 'crates/eql-bindings', }, { - root: 'packages/protect-ffi', + root: 'languages/typescript/packages/protect-ffi', publishable: new Set(), expects: 'crates/protect-ffi', }, diff --git a/scripts/__tests__/cli-vitest-alias.test.mjs b/scripts/__tests__/cli-vitest-alias.test.mjs index 0c12c0055..a144d63bd 100644 --- a/scripts/__tests__/cli-vitest-alias.test.mjs +++ b/scripts/__tests__/cli-vitest-alias.test.mjs @@ -3,10 +3,10 @@ import { describe, expect, it } from 'vitest' import cliVitestConfig from '../../packages/cli/vitest.config.ts' /** - * `packages/cli/vitest.config.ts` carries its own alias map, outside the one + * `languages/typescript/packages/cli/vitest.config.ts` carries its own alias map, outside the one * `vitest-shared-alias.test.mjs` guards. It has to: closing the CLI suite's * remaining build coupling would need `stackSourceAlias`, whose `'@/'` entry - * points at `packages/stack/src` and would clobber the CLI's own `'@/'`. So the + * points at `languages/typescript/packages/stack/src` and would clobber the CLI's own `'@/'`. So the * map is package-local and needs its own guard, for the same reason — an alias * pointing at a moved file fails LATE, with a "failed to resolve import" naming * a path nobody wrote. @@ -39,11 +39,11 @@ const targets = Object.entries(aliases) target.endsWith('/') ? target.slice(0, -1) : target, ]) -describe('packages/cli vitest alias map', () => { +describe('languages/typescript/packages/cli vitest alias map', () => { it('is the object-of-strings form this guard can read', () => { expect( nonStringTargets.map(([specifier]) => specifier), - 'packages/cli/vitest.config.ts switched away from the object-of-strings alias form. Update this guard to walk the new shape — do not delete it.', + 'languages/typescript/packages/cli/vitest.config.ts switched away from the object-of-strings alias form. Update this guard to walk the new shape — do not delete it.', ).toEqual([]) }) diff --git a/scripts/__tests__/eql-sql-asset-freshness.test.mjs b/scripts/__tests__/eql-sql-asset-freshness.test.mjs index 2732b4562..ddabf1d19 100644 --- a/scripts/__tests__/eql-sql-asset-freshness.test.mjs +++ b/scripts/__tests__/eql-sql-asset-freshness.test.mjs @@ -275,7 +275,7 @@ describe('eqlLockstepSkew catches each way the assets can lag', () => { it('catches a digest that is not the sha256 of the file beside it', () => { // The hand-edited case, and the partial-copy case: a manifest asserting - // bytes that are not there. `packages/cli`'s installer reads the SQL + // bytes that are not there. `languages/typescript/packages/cli`'s installer reads the SQL // verbatim, so nothing downstream re-checks this. const { skew } = skewOf({ installDigest: 'deadbeef' }) expect(skew.join('\n')).toMatch( diff --git a/scripts/__tests__/eql-suite-ci.test.mjs b/scripts/__tests__/eql-suite-ci.test.mjs index ee1ea0311..719e3f8f9 100644 --- a/scripts/__tests__/eql-suite-ci.test.mjs +++ b/scripts/__tests__/eql-suite-ci.test.mjs @@ -18,7 +18,7 @@ import { readWorkflow, WORKFLOW_DIR, workflowFiles } from './lib/workflows.mjs' * parity gates and the doc/known-failure checks executed nowhere, and a suite * that never starts reads exactly like a suite that passes. * - * `packages/protect-ffi/src/integrationSuiteCi.test.ts` is the same file for + * `languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts` is the same file for * the same failure one absorption earlier, and its comment predicted this one: * "the next subtree import brings its own `.github/`, and it will arrive * looking exactly as authoritative as this one did." @@ -27,7 +27,7 @@ import { readWorkflow, WORKFLOW_DIR, workflowFiles } from './lib/workflows.mjs' * sound. That a root workflow invokes the suite is loud when wrong — nothing * runs, no status appears. That its RELEVANCE FILTER still selects EQL's files * after the tree moved a level down is not: an unprefixed `src/**` matches - * `packages/stack/src/**` and misses `packages/eql/src/**` entirely, so the + * `languages/typescript/packages/stack/src/**` and misses `packages/eql/src/**` entirely, so the * heavy jobs would skip on exactly the changes they exist to check, report * `skipped`, and let `ci-required` go green having compiled nothing. */ @@ -255,7 +255,7 @@ describe('the relevance filter still selects the imported tree', () => { expect( offenders, - `These \`paths:\` entries in ${EQL_WORKFLOW} are not under \`${EQL_PREFIX}\`, are not the workflow itself, and are not a composite action it \`uses:\`. dorny/paths-filter matches repo-root-relative paths, so after the subtree import an unprefixed glob matches the WRONG tree — \`src/**\` selects \`packages/stack/src/**\` and never \`packages/eql/src/**\`. The heavy jobs then skip on real EQL changes, report \`skipped\`, and \`ci-required\` treats skipped as pass.\n${offenders.map((p) => ` ${p}`).join('\n')}`, + `These \`paths:\` entries in ${EQL_WORKFLOW} are not under \`${EQL_PREFIX}\`, are not the workflow itself, and are not a composite action it \`uses:\`. dorny/paths-filter matches repo-root-relative paths, so after the subtree import an unprefixed glob matches the WRONG tree — \`src/**\` selects \`languages/typescript/packages/stack/src/**\` and never \`packages/eql/src/**\`. The heavy jobs then skip on real EQL changes, report \`skipped\`, and \`ci-required\` treats skipped as pass.\n${offenders.map((p) => ` ${p}`).join('\n')}`, ).toEqual([]) }) }) @@ -394,7 +394,7 @@ describe('the shared Rust cache is pointed and saved correctly', () => { // --------------------------------------------------------------------------- /** - * The other half of the split this repo insists on for `packages/protect-ffi`. + * The other half of the split this repo insists on for `languages/typescript/packages/protect-ffi`. * * There, `lintWiring.test.ts` holds two properties from the manifest side: no * cargo on the default `test` path, and every cargo check reachable from diff --git a/scripts/__tests__/ffi-binding-action.test.mjs b/scripts/__tests__/ffi-binding-action.test.mjs index a4a8076b4..b311f872f 100644 --- a/scripts/__tests__/ffi-binding-action.test.mjs +++ b/scripts/__tests__/ffi-binding-action.test.mjs @@ -3,7 +3,7 @@ * action and the Rust workflow that shares its toolchain step. * * 1. A GitHub Actions cache restore is an untrusted write into the checkout. - * `packages/protect-ffi/dist/wasm` holds BOTH wasm-pack output and three + * `languages/typescript/packages/protect-ffi/dist/wasm` holds BOTH wasm-pack output and three * declaration files that are tracked in git (see the package `.gitignore` * for why they are tracked). Caching that directory whole, on a key hashed * from the Rust inputs only, means a restore replaces the checked-out @@ -46,7 +46,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' const ACTION = '.github/actions/build-ffi-binding/action.yml' const RUST_WORKFLOW = '.github/workflows/tests-rust.yml' -const FFI_PKG = 'packages/protect-ffi' +const FFI_PKG = 'languages/typescript/packages/protect-ffi' const read = (rel) => readFileSync(resolve(REPO_ROOT, rel), 'utf8') @@ -268,7 +268,9 @@ describe('build-ffi-binding — cache restores cannot clobber tracked files', () it('found the tracked declaration files this guard exists for', () => { // If `git ls-files` returns nothing here — wrong cwd, renamed directory, // the .gitignore negations lost — every assertion below passes vacuously. - const tracked = trackedUnder('packages/protect-ffi/dist/wasm') + const tracked = trackedUnder( + 'languages/typescript/packages/protect-ffi/dist/wasm', + ) expect(tracked.length).toBeGreaterThanOrEqual(3) expect(tracked.every((file) => file.endsWith('.d.ts'))).toBe(true) }) @@ -358,7 +360,7 @@ describe('build-ffi-binding — the WASM key covers the build it skips', () => { * The third question a cache key has to answer, and the one the two suites * above cannot see: does it cover every crate the build COMPILES? * - * Both of those reason about files inside `packages/protect-ffi`. Cargo does + * Both of those reason about files inside `languages/typescript/packages/protect-ffi`. Cargo does * not. `crates/protect-ffi/Cargo.toml` carries * * eql-bindings = { path = "../../../eql/crates/eql-bindings" } @@ -366,7 +368,7 @@ describe('build-ffi-binding — the WASM key covers the build it skips', () => { * — an in-tree path dependency in a DIFFERENT package, and a genuine compile * input to both `index.node` and the wasm32 build. A path dep carries no * registry checksum, so a src-only edit under that crate touches nothing else: - * not `packages/protect-ffi/crates/**`, not either `Cargo.toml`, and not + * not `languages/typescript/packages/protect-ffi/crates/**`, not either `Cargo.toml`, and not * `Cargo.lock` (which records the path dep by name and version, and only moves * when the version does). Every glob in both keys therefore hashes identically, * the restore hits, `Build index.node (cargo)` is SKIPPED, and every @@ -397,7 +399,7 @@ const CARGO_ROOT_CRATE = `${FFI_PKG}/crates/protect-ffi/Cargo.toml` * * Deliberately a narrow reader over the text rather than a TOML parse: there is * no TOML parser in this repo's dependency tree, and `cargo metadata` would put - * a Rust toolchain on `pnpm test:scripts` — which `packages/protect-ffi`'s + * a Rust toolchain on `pnpm test:scripts` — which `languages/typescript/packages/protect-ffi`'s * `lintWiring.test.ts` exists to keep off the JS entry points. * * It reads both spellings cargo accepts: the inline table @@ -450,7 +452,7 @@ function parsePathDependencies(text) { * Every crate `cargo build` compiles into the artifact, as repo-relative * directories, starting from the cdylib crate and following path deps * transitively. The starting crate itself is excluded: it lives under - * `packages/protect-ffi/crates/**`, which both keys already hash. + * `languages/typescript/packages/protect-ffi/crates/**`, which both keys already hash. */ function compiledPathDependencies(rootManifestRel) { const crates = new Map() diff --git a/scripts/__tests__/ffi-binding-step-order.test.mjs b/scripts/__tests__/ffi-binding-step-order.test.mjs index e83cd0b5c..dcca3fd63 100644 --- a/scripts/__tests__/ffi-binding-step-order.test.mjs +++ b/scripts/__tests__/ffi-binding-step-order.test.mjs @@ -207,7 +207,7 @@ const EXPECTED_CREDENTIALED_JOBS = [ * * The two entries are the EQL suite, and they are the first jobs in this repo * to encrypt WITHOUT the Node binding. `index.node` is the Node-API wrapper - * `packages/stack` loads; these are Rust tests linking `cipherstash-client` + * `languages/typescript/packages/stack` loads; these are Rust tests linking `cipherstash-client` * directly, so a `build-ffi-binding` step here would compile a binding nothing * in the job can load and add minutes to the critical path of a suite that * already compiles its own encryption core. They still hold live credentials — @@ -346,7 +346,7 @@ describe('protect-ffi binding builds after the secrets pre-flight', () => { * already pair the two actions, so a job that never builds the binding at all * is invisible to them — it is not failing them, it is not in them. * - * That gap is not theoretical. `packages/protect-ffi` is a workspace package + * That gap is not theoretical. `languages/typescript/packages/protect-ffi` is a workspace package * now, so `lib/`, `index.node` and `dist/wasm/**` are BUILD OUTPUTS rather than * tarball contents, and every job that encrypts has to produce them itself. Two * credentialed jobs in `tests.yml` were missed when the `workspace:*` links @@ -354,7 +354,7 @@ describe('protect-ffi binding builds after the secrets pre-flight', () => { * `tests/prisma-example-readme.e2e.test.ts`, whose `describe.skipIf` un-skips * the moment CS_CLIENT_ID and CS_CLIENT_KEY are set, and whose `pnpm start` * step encrypts for real) and `run-tests-bun` (writes the four CS_* into - * `packages/stack/.env`, then runs 120 `packages/stack` suites of which only 8 + * `languages/typescript/packages/stack/.env`, then runs 120 `languages/typescript/packages/stack` suites of which only 8 * mock protect-ffi). * * The failure mode is `Cannot find module '.../index.node'`, reported once per @@ -390,7 +390,7 @@ describe('every credentialed job builds the protect-ffi binding', () => { expect( offenders, - `These jobs receive CipherStash credentials but never run ${BUILD_FFI}.\n\`packages/protect-ffi\` is a workspace package: \`lib/\`, \`index.node\` and \`dist/wasm/**\` are build outputs, not tarball contents, so a job that encrypts or decrypts must build them itself. Without the step the suite fails with \`Cannot find module '.../protect-ffi-linux-x64-gnu/index.node'\`, once per test.\nAdd the step AFTER any \`${REQUIRE_SECRETS}\` pre-flight and BEFORE anything that consumes the binding. Pass \`wasm: 'true'\` only if the job loads the real WASM build.\nIf a job genuinely does not need it, add it to BINDING_EXEMPT_JOBS with the reason.`, + `These jobs receive CipherStash credentials but never run ${BUILD_FFI}.\n\`languages/typescript/packages/protect-ffi\` is a workspace package: \`lib/\`, \`index.node\` and \`dist/wasm/**\` are build outputs, not tarball contents, so a job that encrypts or decrypts must build them itself. Without the step the suite fails with \`Cannot find module '.../protect-ffi-linux-x64-gnu/index.node'\`, once per test.\nAdd the step AFTER any \`${REQUIRE_SECRETS}\` pre-flight and BEFORE anything that consumes the binding. Pass \`wasm: 'true'\` only if the job loads the real WASM build.\nIf a job genuinely does not need it, add it to BINDING_EXEMPT_JOBS with the reason.`, ).toEqual([]) }) }) @@ -407,7 +407,7 @@ describe('every credentialed job builds the protect-ffi binding', () => { * because the job is a legitimate new entry rather than a missing old one. * * `tests.yml`'s `run-tests-bun` was the live instance: it writes all four CS_* - * into `packages/stack/.env` and runs `./.github/actions/build-ffi-binding` + * into `languages/typescript/packages/stack/.env` and runs `./.github/actions/build-ffi-binding` * with no pre-flight before it. It appeared in `EXPECTED_CREDENTIALED_JOBS`, * satisfied the coverage check, and generated zero ordering assertions. * diff --git a/scripts/__tests__/ffi-release-matrix.test.mjs b/scripts/__tests__/ffi-release-matrix.test.mjs index 03c1d0d77..3a71919ac 100644 --- a/scripts/__tests__/ffi-release-matrix.test.mjs +++ b/scripts/__tests__/ffi-release-matrix.test.mjs @@ -15,14 +15,14 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * matrix got right for upstream and wrong here — see the header of * `scripts/ffi-release-matrix.mjs`. * - * These checks are derived from `packages/protect-ffi/package.json` rather than + * These checks are derived from `languages/typescript/packages/protect-ffi/package.json` rather than * restated: the script the matrix names must exist, and the log file it names * must be the one that script actually redirects to. Rename a script or move a * redirect and this fails, which is the only way the matrix stays true to the * package. */ -const FFI = join(REPO_ROOT, 'packages/protect-ffi') +const FFI = join(REPO_ROOT, 'languages/typescript/packages/protect-ffi') const pkg = JSON.parse(readFileSync(join(FFI, 'package.json'), 'utf8')) /** @@ -103,7 +103,7 @@ describe('release matrix', () => { for (const entry of MATRIX) { expect( pkg.scripts[entry.script], - `${entry.platform} selects "${entry.script}", which packages/protect-ffi/package.json does not define`, + `${entry.platform} selects "${entry.script}", which languages/typescript/packages/protect-ffi/package.json does not define`, ).toBeDefined() } }) diff --git a/scripts/__tests__/ffi-repository-urls.test.mjs b/scripts/__tests__/ffi-repository-urls.test.mjs index 4aa70ef20..33c7d35a5 100644 --- a/scripts/__tests__/ffi-repository-urls.test.mjs +++ b/scripts/__tests__/ffi-repository-urls.test.mjs @@ -17,13 +17,13 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * `repository.directory` is the quieter half. It resolves from the ROOT of the * repository named in `repository.url`, so `platforms/

` addressed a real * directory in the old repo and addresses nothing here, where the packages live - * at `packages/protect-ffi/platforms/

`. The two fields fail differently: a + * at `languages/typescript/packages/protect-ffi/platforms/

`. The two fields fail differently: a * stale `url` fails the publish outright, while a `directory` that does not * resolve publishes fine and silently breaks the source link on the package * page. Only one of those gets noticed, which is why both are asserted. */ -const FFI = join(REPO_ROOT, 'packages/protect-ffi') +const FFI = join(REPO_ROOT, 'languages/typescript/packages/protect-ffi') /** The repository these packages publish from as of the cutover. */ const EXPECTED = 'https://github.com/cipherstash/stack' @@ -72,7 +72,7 @@ describe('FFI manifests name this repository', () => { readFileSync(join(FFI, 'platforms', platform, 'package.json'), 'utf8'), ) expect(pkg.repository.directory).toBe( - `packages/protect-ffi/platforms/${platform}`, + `languages/typescript/packages/protect-ffi/platforms/${platform}`, ) }) } diff --git a/scripts/__tests__/frozen-publisher-runtime-pins.test.mjs b/scripts/__tests__/frozen-publisher-runtime-pins.test.mjs index 9bec4950a..8fa3ddcec 100644 --- a/scripts/__tests__/frozen-publisher-runtime-pins.test.mjs +++ b/scripts/__tests__/frozen-publisher-runtime-pins.test.mjs @@ -62,7 +62,7 @@ import { * absent there: pnpm rewrites the `workspace:` specifier in that table too and * the rewritten range does ship inside the packed `package.json`, but nothing * installing the package ever resolves it. The asymmetry is live in this tree — - * `packages/stack` declares `@cipherstash/eql` under `devDependencies` and is + * `languages/typescript/packages/stack` declares `@cipherstash/eql` under `devDependencies` and is * not a finding — so it is asserted below rather than left as an absence. */ const RUNTIME_TABLES = new Set([ @@ -160,7 +160,7 @@ describe('frozen-publisher runtime pins', () => { }) it('does not fault a devDependency, which no consumer installs', () => { - // `packages/stack` and the protect-ffi integration suite both declare + // `languages/typescript/packages/stack` and the protect-ffi integration suite both declare // `@cipherstash/eql` under `devDependencies`. They are the cases that prove // the narrowing above is a decision rather than an oversight: if either // appears in the finding list, RUNTIME_TABLES has drifted from diff --git a/scripts/__tests__/integration-workflow-paths.test.mjs b/scripts/__tests__/integration-workflow-paths.test.mjs index eb5fd0374..c3b1e812a 100644 --- a/scripts/__tests__/integration-workflow-paths.test.mjs +++ b/scripts/__tests__/integration-workflow-paths.test.mjs @@ -10,7 +10,7 @@ import { readWorkflow, workflowFiles } from './lib/workflows.mjs' * entry covers, is live coverage that silently does not run: edit only that * directory and the job the code depends on never starts. * - * `packages/stack/src/dynamodb/**` was exactly that (#815 review). The only + * `languages/typescript/packages/stack/src/dynamodb/**` was exactly that (#815 review). The only * live EQL v2 read coverage in the repo lives in * `integration/shared/v2-decrypt-compat.integration.test.ts`, which exercises * the DynamoDB legacy read path — and `grep -rn dynamodb .github/` returned @@ -36,8 +36,8 @@ import { readWorkflow, workflowFiles } from './lib/workflows.mjs' * did cover are covered there. */ -const STACK_SRC = 'packages/stack/src' -const STACK_MANIFEST = 'packages/stack/package.json' +const STACK_SRC = 'languages/typescript/packages/stack/src' +const STACK_MANIFEST = 'languages/typescript/packages/stack/package.json' const CATALOG_MANIFEST = 'pnpm-workspace.yaml' /** Both trigger events, in the order GitHub evaluates them. */ @@ -45,7 +45,7 @@ const TRIGGER_EVENTS = ['push', 'pull_request'] /** * The integration workflows, discovered rather than listed: any workflow whose - * `CS_IT_SUITE` globs select suites out of `packages/stack/` is in scope. A + * `CS_IT_SUITE` globs select suites out of `languages/typescript/packages/stack/` is in scope. A * fourth integration job added later is therefore held to the same bar without * anyone remembering to add it here. */ @@ -82,7 +82,7 @@ function suiteGlobs(wf) { return globs } -/** Test files under `packages/stack/` matching a `CS_IT_SUITE` glob. */ +/** Test files under `languages/typescript/packages/stack/` matching a `CS_IT_SUITE` glob. */ function suiteFiles(globs) { const files = [] const walk = (dir) => { @@ -97,7 +97,7 @@ function suiteFiles(globs) { // Walk the literal prefix; the glob tail only ever narrows to // `*.integration.test.ts`, which the walk already filters on. const prefix = glob.split('/').slice(0, 2).join('/') - walk(join(REPO_ROOT, 'packages/stack', prefix)) + walk(join(REPO_ROOT, 'languages/typescript/packages/stack', prefix)) } return [...new Set(files)] } @@ -124,7 +124,7 @@ function importedSourcePaths(file) { return targets } -/** `packages/stack`'s dependency declarations, specifier -> version range. */ +/** `languages/typescript/packages/stack`'s dependency declarations, specifier -> version range. */ function stackDependencies() { const manifest = JSON.parse( readFileSync(join(REPO_ROOT, STACK_MANIFEST), 'utf8'), @@ -149,7 +149,7 @@ function stackDependencies() { * directly — so a protect-ffi bump is precisely the change most able to break * them, and precisely the change that touches no source directory at all. * - * Specifiers with no entry in `packages/stack/package.json` (e.g. + * Specifiers with no entry in `languages/typescript/packages/stack/package.json` (e.g. * `@cipherstash/test-kit`, resolved through tsconfig `paths` to a workspace * package) are skipped: `importedSourcePaths`' sibling globs already cover them. */ @@ -231,7 +231,7 @@ describe('integration workflow paths filters', () => { // Mutation-tested: rewriting the suites' `from '@/…'` to the public // `@cipherstash/stack/…` entry — an ordinary "test the built package, // not internals" refactor — empties this set, and the check then passed - // with `packages/stack/src/dynamodb/**` deleted from the filter, which + // with `languages/typescript/packages/stack/src/dynamodb/**` deleted from the filter, which // is verbatim the #815 gap described at the top of this file. The // sibling manifest check above already asserts its own premise; this one // has to as well. diff --git a/scripts/__tests__/lib/package-readmes.mjs b/scripts/__tests__/lib/package-readmes.mjs index fdfe25188..a1b8a6d8c 100644 --- a/scripts/__tests__/lib/package-readmes.mjs +++ b/scripts/__tests__/lib/package-readmes.mjs @@ -8,10 +8,10 @@ import { REPO_ROOT } from './repo-root.mjs' * * ## Why this is derived rather than written down * - * Both callers used to hardcode `:(glob)packages/*/README.md`. `:(glob)` stops + * Both callers used to hardcode `:(glob)languages/typescript/packages/*/README.md`. `:(glob)` stops * `*` at a path separator — which is what makes `lib/*.ts` behave — and this * repo has TWO package roots nested deeper than one level: - * `packages/protect-ffi/platforms/*` and `packages/eql/packages/*`. So the + * `languages/typescript/packages/protect-ffi/platforms/*` and `packages/eql/packages/*`. So the * hardcoded spec selected `packages/eql/README.md`, the 15 KB subtree root that * ships in no tarball, and never `packages/eql/packages/eql/README.md`, the * 518-byte file listed in that package's `files`. Same for the six per-platform @@ -24,7 +24,7 @@ import { REPO_ROOT } from './repo-root.mjs' * root is covered the day it lands, rather than the day someone remembers this * file. Same reasoning, and the same parser, as `workspaceManifests()`. * - * Narrowed to `packages/` deliberately: `examples/*` and `e2e` are workspace + * Narrowed to `packages/` deliberately: `languages/typescript/examples/*` and `e2e` are workspace * members too, but they are private and their READMEs are not shipped to * anyone. The callers are guards on SHIPPED text. */ diff --git a/scripts/__tests__/lib/workflows.mjs b/scripts/__tests__/lib/workflows.mjs index 9f25387f6..e8f933176 100644 --- a/scripts/__tests__/lib/workflows.mjs +++ b/scripts/__tests__/lib/workflows.mjs @@ -22,7 +22,7 @@ import { REPO_ROOT } from './repo-root.mjs' /** * Where GitHub reads workflows from — and the only place it reads them from. A * workflow file deposited under a package's own `.github/workflows` is inert, - * which is the failure `packages/protect-ffi/src/integrationSuiteCi.test.ts` + * which is the failure `languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts` * exists to catch. */ export const WORKFLOW_DIR = '.github/workflows' diff --git a/scripts/__tests__/lint-no-dead-package-paths.test.mjs b/scripts/__tests__/lint-no-dead-package-paths.test.mjs index b95315932..e68aa7f76 100644 --- a/scripts/__tests__/lint-no-dead-package-paths.test.mjs +++ b/scripts/__tests__/lint-no-dead-package-paths.test.mjs @@ -54,7 +54,7 @@ describe('lint-no-dead-package-paths', () => { }) // #772 review, finding 15. The name capture had no right anchor, so a - // sentence-final `packages/stack.` swallowed the period and the linter + // sentence-final `languages/typescript/packages/stack.` swallowed the period and the linter // reported a LIVE package as dead — failing the build with a message naming a // directory that plainly exists. Never fired in 400 commits only because the // repo's backtick convention happened to dodge it. @@ -226,16 +226,16 @@ describe('lint-no-dead-package-paths', () => { }) it('matches the longest package name, not a shorter prefix', () => { - // `packages/stack-drizzle` must not be read as `packages/stack` + suffix, + // `languages/typescript/packages/stack-drizzle` must not be read as `languages/typescript/packages/stack` + suffix, // and a dead `packages/stack-forge` must not be excused by live - // `packages/stack`. + // `languages/typescript/packages/stack`. const r = run(fx('prefix.md')) expect(r.exitCode).toBe(1) expect(r.output).toMatch(/packages\/stack-forge/) expect(r.output).not.toMatch(/packages\/stack-drizzle/) }) - it('ignores `packages/*` globs and `./packages/*` filters', () => { + it('ignores `languages/typescript/packages/*` globs and `./languages/typescript/packages/*` filters', () => { expect(run(fx('globs.md')).exitCode).toBe(0) }) diff --git a/scripts/__tests__/lint-no-eql-registry-pins.test.mjs b/scripts/__tests__/lint-no-eql-registry-pins.test.mjs index 9b581fc01..541b0a643 100644 --- a/scripts/__tests__/lint-no-eql-registry-pins.test.mjs +++ b/scripts/__tests__/lint-no-eql-registry-pins.test.mjs @@ -83,7 +83,7 @@ describe('the tree it actually guards', () => { const { exitCode, output } = run() expect(output).toContain('resolves in-tree') expect(output).toContain( - '(1 exempt: packages/cli/package.json :: @cipherstash/eql-upgrade-baseline)', + '(1 exempt: languages/typescript/packages/cli/package.json :: @cipherstash/eql-upgrade-baseline)', ) expect(exitCode).toBe(0) }) @@ -94,7 +94,8 @@ describe('the tree it actually guards', () => { // this manifest would also exit 0. const declaration = lint().declarations.find( (d) => - d.file === 'packages/protect-ffi/crates/protect-ffi/Cargo.toml' && + d.file === + 'languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml' && d.dependency === 'eql-bindings', ) expect(declaration).toBeDefined() @@ -122,7 +123,8 @@ describe('the tree it actually guards', () => { // disagreed in a database, not in CI. const declaration = lint().declarations.find( (d) => - d.file === 'packages/protect-ffi/integration-tests/package.json' && + d.file === + 'languages/typescript/packages/protect-ffi/integration-tests/package.json' && d.dependency === '@cipherstash/eql', ) expect(declaration).toBeDefined() @@ -598,7 +600,9 @@ describe('pnpm-workspace.yaml: the file no manifest scan opens', () => { it('is collected by the walk', () => { // The hole this whole block is about: pnpm 10 reads `overrides` from here, // and the scan only ever opened `Cargo.toml` and `package.json`. - const root = tree({ 'pnpm-workspace.yaml': 'packages:\n - packages/*\n' }) + const root = tree({ + 'pnpm-workspace.yaml': 'packages:\n - languages/typescript/packages/*\n', + }) expect(manifestFiles(root)).toContain('pnpm-workspace.yaml') }) @@ -654,7 +658,7 @@ describe('pnpm-workspace.yaml: the file no manifest scan opens', () => { declarations( [ 'packages:', - ' - packages/*', + ' - languages/typescript/packages/*', 'catalogs:', ' repo:', ' typescript: 5.9.3', @@ -672,7 +676,7 @@ describe('pnpm-workspace.yaml: the file no manifest scan opens', () => { // and confirm it now exits 1. const root = tree({ 'pnpm-workspace.yaml': - "packages:\n - packages/*\noverrides:\n '@cipherstash/eql': 3.0.4\n", + "packages:\n - languages/typescript/packages/*\noverrides:\n '@cipherstash/eql': 3.0.4\n", 'packages/a/package.json': '{"dependencies":{"@cipherstash/eql":"workspace:^"}}', }) @@ -683,7 +687,7 @@ describe('pnpm-workspace.yaml: the file no manifest scan opens', () => { it('flags a catalog entry end to end', () => { const root = tree({ 'pnpm-workspace.yaml': - "packages:\n - packages/*\ncatalogs:\n repo:\n '@cipherstash/eql': 3.0.4\n", + "packages:\n - languages/typescript/packages/*\ncatalogs:\n repo:\n '@cipherstash/eql': 3.0.4\n", }) expect(run(root).exitCode).toBe(1) }) @@ -846,10 +850,12 @@ describe('the linter fails when its own configuration goes stale', () => { it('exits 2 — not 1 — when an expected declarer disappears', () => { const { code, err } = report({ ...clean, - missingExpected: ['packages/stack/package.json :: @cipherstash/eql'], + missingExpected: [ + 'languages/typescript/packages/stack/package.json :: @cipherstash/eql', + ], }) expect(code).toBe(2) - expect(err).toContain('packages/stack/package.json') + expect(err).toContain('languages/typescript/packages/stack/package.json') // The scan's own output, so a rename is a copy rather than a re-derivation. expect(err).toContain('x :: y') }) @@ -993,13 +999,15 @@ describe('the remediation names a specifier that packs exact', () => { report({ offenders: [ { - file: 'packages/cli/package.json', + file: 'languages/typescript/packages/cli/package.json', table: 'dependencies', dependency: '@cipherstash/eql', spec: '3.0.5', }, ], - ids: ['packages/cli/package.json [dependencies] @cipherstash/eql'], + ids: [ + 'languages/typescript/packages/cli/package.json [dependencies] @cipherstash/eql', + ], exempted: [], missingSources: [], missingExpected: [], diff --git a/scripts/__tests__/neon-dist-crate-name.test.mjs b/scripts/__tests__/neon-dist-crate-name.test.mjs index b944ebdbe..c37b385a1 100644 --- a/scripts/__tests__/neon-dist-crate-name.test.mjs +++ b/scripts/__tests__/neon-dist-crate-name.test.mjs @@ -48,7 +48,10 @@ import { readWorkflow, workflowFiles } from './lib/workflows.mjs' /** The crate whose cdylib becomes `index.node`. */ function crateName() { const toml = readFileSync( - join(REPO_ROOT, 'packages/protect-ffi/crates/protect-ffi/Cargo.toml'), + join( + REPO_ROOT, + 'languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml', + ), 'utf8', ) const match = toml.match(/^\s*name\s*=\s*"([^"]+)"/m) diff --git a/scripts/__tests__/no-parked-changesets.test.mjs b/scripts/__tests__/no-parked-changesets.test.mjs index 55e8f1d49..0dd069e19 100644 --- a/scripts/__tests__/no-parked-changesets.test.mjs +++ b/scripts/__tests__/no-parked-changesets.test.mjs @@ -96,7 +96,7 @@ describe('the changeset parking convention is retired, and stays retired', () => '`@cipherstash/protect-ffi@0.32.0`. A file still carrying the suffix today is ' + 'almost certainly riding a branch cut BEFORE that commit, where reactivating it ' + 'republishes a shipped changelog entry and bumps the package again for it:\n\n' + - ' git log origin/main --oneline -- packages/protect-ffi/CHANGELOG.md\n\n' + + ' git log origin/main --oneline -- languages/typescript/packages/protect-ffi/CHANGELOG.md\n\n' + 'Delete it if its content is already in a released CHANGELOG; `git mv` it back to ' + '`.md` only if it is genuinely unreleased:\n' + `${parked.map((name) => ` ${CHANGESET_DIR}/${name}`).join('\n')}`, diff --git a/scripts/__tests__/no-removed-drizzle-surface.test.mjs b/scripts/__tests__/no-removed-drizzle-surface.test.mjs index b271c58f9..2b013f71e 100644 --- a/scripts/__tests__/no-removed-drizzle-surface.test.mjs +++ b/scripts/__tests__/no-removed-drizzle-surface.test.mjs @@ -35,9 +35,9 @@ const SHIPPED_GLOBS = [ 'README.md', 'AGENTS.md', // `stash init` writes these strings into the user's project as real source. - 'packages/cli/src/commands/init/utils.ts', - ':(glob)packages/cli/src/commands/init/lib/*.ts', - ':(glob)packages/cli/src/commands/init/doctrine/*.md', + 'languages/typescript/packages/cli/src/commands/init/utils.ts', + ':(glob)languages/typescript/packages/cli/src/commands/init/lib/*.ts', + ':(glob)languages/typescript/packages/cli/src/commands/init/doctrine/*.md', ] /** Tracked files matching the shipped globs, via git so it honours .gitignore. */ @@ -55,14 +55,14 @@ describe('removed stack-drizzle surface is absent from shipped files', () => { it('finds the shipped file set (guards against a silently-empty glob)', () => { expect(files.length).toBeGreaterThan(5) expect(files).toContain('skills/stash-drizzle/SKILL.md') - expect(files).toContain('packages/stack/README.md') - // The two roots nested deeper than `packages/*`. Pinned by name because - // they are what the hardcoded `:(glob)packages/*/README.md` silently + expect(files).toContain('languages/typescript/packages/stack/README.md') + // The two roots nested deeper than `languages/typescript/packages/*`. Pinned by name because + // they are what the hardcoded `:(glob)languages/typescript/packages/*/README.md` silently // missed: `:(glob)` does not cross `/`, so it selected the EQL subtree // ROOT's README — which ships in no tarball — instead of the package's. expect(files).toContain('packages/eql/packages/eql/README.md') expect(files).toContain( - 'packages/protect-ffi/platforms/linux-x64-gnu/README.md', + 'languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/README.md', ) }) diff --git a/scripts/__tests__/no-removed-eql-version-flag.test.mjs b/scripts/__tests__/no-removed-eql-version-flag.test.mjs index d11016a38..5ea4c7866 100644 --- a/scripts/__tests__/no-removed-eql-version-flag.test.mjs +++ b/scripts/__tests__/no-removed-eql-version-flag.test.mjs @@ -78,15 +78,15 @@ describe('public eql install examples use the current CLI', () => { expect(files).not.toHaveLength(0) expect(files).toContain('skills/stash-drizzle/SKILL.md') expect(files).toContain('skills/stash-supabase/SKILL.md') - expect(files).toContain('packages/stack/README.md') + expect(files).toContain('languages/typescript/packages/stack/README.md') expect(files).toContain('docs/reference/supabase-sdk.md') - // The two roots nested deeper than `packages/*`. Pinned by name because - // they are what the hardcoded `:(glob)packages/*/README.md` silently + // The two roots nested deeper than `languages/typescript/packages/*`. Pinned by name because + // they are what the hardcoded `:(glob)languages/typescript/packages/*/README.md` silently // missed: `:(glob)` does not cross `/`, so it selected the EQL subtree // ROOT's README — which ships in no tarball — instead of the package's. expect(files).toContain('packages/eql/packages/eql/README.md') expect(files).toContain( - 'packages/protect-ffi/platforms/linux-x64-gnu/README.md', + 'languages/typescript/packages/protect-ffi/platforms/linux-x64-gnu/README.md', ) }) diff --git a/scripts/__tests__/release-gate.test.mjs b/scripts/__tests__/release-gate.test.mjs index 445cf70c9..efb849114 100644 --- a/scripts/__tests__/release-gate.test.mjs +++ b/scripts/__tests__/release-gate.test.mjs @@ -117,12 +117,12 @@ describe('workspacePackagePatterns', () => { expect(workspacePackagePatterns(SOURCE)).toEqual(yaml.load(SOURCE).packages) }) - it('keeps the nested platform packages, which `packages/*` does not cover', () => { + it('keeps the nested platform packages, which `languages/typescript/packages/*` does not cover', () => { // The six platform packages sit a level deeper than the glob above them. // Losing this entry is the concrete shape of a narrowed gate: six // unpublished packages reported as nothing to publish. expect(workspacePackagePatterns(SOURCE)).toContain( - 'packages/protect-ffi/platforms/*', + 'languages/typescript/packages/protect-ffi/platforms/*', ) }) @@ -208,8 +208,8 @@ describe('classify', () => { * * That is not hypothetical here. `@cipherstash/eql` is published from * `cipherstash/encrypt-query-language`, so a version bumped in this workspace - * cannot be published from this repository — while `packages/cli` and - * `packages/stack-prisma` carry `"@cipherstash/eql": "workspace:*"` in their + * cannot be published from this repository — while `languages/typescript/packages/cli` and + * `languages/typescript/packages/stack-prisma` carry `"@cipherstash/eql": "workspace:*"` in their * RUNTIME dependencies, which pnpm rewrites to that exact version at pack time. * The hand-applied 3.0.5 bump put both of them a release ahead of the registry: * a range no published version satisfied, in a tarball that publishes fine. @@ -489,8 +489,8 @@ describe('publishBlockers', () => { it('ignores devDependencies', () => { // A published tarball keeps its devDependencies in the manifest, but no // consumer installs them, so an unsatisfiable one breaks nothing. This is - // why `packages/stack`'s `@cipherstash/eql: workspace:^` is not a finding - // while `packages/cli`'s identical line is. + // why `languages/typescript/packages/stack`'s `@cipherstash/eql: workspace:^` is not a finding + // while `languages/typescript/packages/cli`'s identical line is. expect( publishBlockers({ manifests: [ @@ -511,7 +511,7 @@ describe('publishBlockers', () => { }) it('does not check a private package’s own dependencies', () => { - // `examples/*`, `e2e` and `packages/bench` are never packed, so their + // `languages/typescript/examples/*`, `e2e` and `languages/typescript/packages/bench` are never packed, so their // `workspace:*` lines reach no consumer. expect( publishBlockers({ @@ -696,9 +696,9 @@ describe('the gate over this repo’s real manifests', () => { }) it('names every published package that would ship the unsatisfiable range', () => { - // THE REGRESSION. `packages/cli` (`stash`) and `packages/stack-prisma` + // THE REGRESSION. `languages/typescript/packages/cli` (`stash`) and `languages/typescript/packages/stack-prisma` // both carry `"@cipherstash/eql": "workspace:*"` under `dependencies`, so - // both pack the exact version. `packages/stack` carries the same line + // both pack the exact version. `languages/typescript/packages/stack` carries the same line // under `devDependencies` and must NOT appear. expect( blockers diff --git a/scripts/__tests__/rewriter-copies-in-sync.test.mjs b/scripts/__tests__/rewriter-copies-in-sync.test.mjs index 649a5ee6e..3c8ff1689 100644 --- a/scripts/__tests__/rewriter-copies-in-sync.test.mjs +++ b/scripts/__tests__/rewriter-copies-in-sync.test.mjs @@ -7,7 +7,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * The ALTER-COLUMN rewriter exists twice: `@cipherstash/wizard` * runs it after its agent edits a schema, and `stash eql migration --drizzle` * runs it over an explicit `--out`. Both are published, neither depends on the - * other, and `packages/utils` is not a package while `@cipherstash/test-kit` is + * other, and `languages/typescript/packages/utils` is not a package while `@cipherstash/test-kit` is * private and build-less — so there is nowhere to put shared runtime code that * both npm tarballs could resolve. Extracting one means either publishing a new * package into a fixed release group or adding `noExternal` to two CLI bundles. @@ -20,8 +20,10 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * So: everything outside the wizard's `#region wizard-only` must match the CLI * copy exactly, modulo comments and the tool name in the emitted header. */ -const WIZARD = 'packages/wizard/src/lib/rewrite-migrations.ts' -const CLI = 'packages/cli/src/commands/db/rewrite-migrations.ts' +const WIZARD = + 'languages/typescript/packages/wizard/src/lib/rewrite-migrations.ts' +const CLI = + 'languages/typescript/packages/cli/src/commands/db/rewrite-migrations.ts' const REGION_OPEN = '// #region wizard-only' const REGION_CLOSE = '// #endregion wizard-only' diff --git a/scripts/__tests__/skills-retired-package-scopes.test.mjs b/scripts/__tests__/skills-retired-package-scopes.test.mjs index f7178101e..71fc044ce 100644 --- a/scripts/__tests__/skills-retired-package-scopes.test.mjs +++ b/scripts/__tests__/skills-retired-package-scopes.test.mjs @@ -1,7 +1,7 @@ /** * A shipped skill must not name a package that no longer exists. * - * `skills/*` are published artefacts: `packages/cli/tsup.config.ts` copies them + * `skills/*` are published artefacts: `languages/typescript/packages/cli/tsup.config.ts` copies them * into the `stash` tarball and `installSkills()` copies them into a customer's * `.claude/skills/`. A code sample there is not compiled by anything — not by * `tsc`, not by Biome, not by any suite in this repo — so an import naming a diff --git a/scripts/__tests__/skills-select-star-not-a-read-backstop.test.mjs b/scripts/__tests__/skills-select-star-not-a-read-backstop.test.mjs index e38177b11..77399880a 100644 --- a/scripts/__tests__/skills-select-star-not-a-read-backstop.test.mjs +++ b/scripts/__tests__/skills-select-star-not-a-read-backstop.test.mjs @@ -12,12 +12,12 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * ## The property * * `encryptedSupabase` built from declared `schemas` refuses `select('*')` and - * bare `select()` — `expandStarOrThrow()`, `packages/stack-supabase/src/ + * bare `select()` — `expandStarOrThrow()`, `languages/typescript/packages/stack-supabase/src/ * query-builder.ts:159-166`. It reads like a safety net: name your columns or * get nothing. It is not one. A query awaited with **no `.select()` call at * all** takes the other branch — `query-builder.ts:703-725` sends a raw `*` — * and `decryptResults` returns it untouched on its `!hasSelect` passthrough - * (`packages/stack-supabase/src/query-results.ts:127-130`). Every column comes + * (`languages/typescript/packages/stack-supabase/src/query-results.ts:127-130`). Every column comes * back undecrypted, declared or not. That is long-standing behaviour the * source deliberately leaves alone; only the docs were wrong about it. * @@ -31,10 +31,10 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * - Nothing type-checks a SKILL.md or a README, and these are shipped text. * `skills/` rides inside the `stash` npm tarball and `stash init` copies it * into the customer's repository, where their coding agent reads it as - * instruction. `packages/stack-supabase/README.md` renders on the npm + * instruction. `languages/typescript/packages/stack-supabase/README.md` renders on the npm * package page. * - The runtime tests pin the two behaviours separately and correctly - * (`packages/stack-supabase/__tests__/supabase-declared-mode.test.ts`), but a + * (`languages/typescript/packages/stack-supabase/__tests__/supabase-declared-mode.test.ts`), but a * passing test says nothing about what a document claims. * - The specific failure was a CORRECTION THAT LANDED IN ONE OF TWO COPIES. * `578783ad` fixed the claim in `skills/stash-supabase/SKILL.md` and left the @@ -68,7 +68,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * - The second false claim fixed alongside this one, that an ambient * `DATABASE_URL` is ignored "with a warning" on the edge entry. Both the * ambient read and the warning are gated on `introspector` - * (`packages/stack-supabase/src/create.ts:304,330`), which is `null` on the + * (`languages/typescript/packages/stack-supabase/src/create.ts:304,330`), which is `null` on the * `wasm-inline` build. It is left unguarded deliberately: "a warning is * logged" has no stable phrasing to key on, and the correction ("gated on the * introspector") is a word that appears freely in any section discussing @@ -213,7 +213,9 @@ describe("the select('*') refusal is documented as not a read backstop", () => { expect(files.length).toBeGreaterThan(5) expect(files).toContain('skills/stash-supabase/SKILL.md') expect(files).toContain('skills/stash-managed-platforms/SKILL.md') - expect(files).toContain('packages/stack-supabase/README.md') + expect(files).toContain( + 'languages/typescript/packages/stack-supabase/README.md', + ) }) /** diff --git a/scripts/__tests__/supabase-runtime-claims.test.mjs b/scripts/__tests__/supabase-runtime-claims.test.mjs index 4ec96d4b5..b4fc1f1fa 100644 --- a/scripts/__tests__/supabase-runtime-claims.test.mjs +++ b/scripts/__tests__/supabase-runtime-claims.test.mjs @@ -25,13 +25,13 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * **2. Importing `@cipherstash/protect-ffi` does not load a Node-API binary.** * `index.ts` and `create.ts` both named it as the import-time native load. It * is the one package in the graph that deliberately does NOT do that: - * `packages/protect-ffi/src/index.cts` writes `import native = + * `languages/typescript/packages/protect-ffi/src/index.cts` writes `import native = * require('./load.cjs')` precisely so `__importStar` cannot enumerate the * `@neon-rs/load` proxy into resolving the platform binary, and - * `packages/protect-ffi/src/nativeLoading.test.ts` guards it. The module- + * `languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts` guards it. The module- * evaluation-time `dlopen` in that graph belongs to `@cipherstash/auth`, whose * Node entry ends `module.exports = loadBinding()`. - * `packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts` holds the + * `languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts` holds the * mechanical half of this; here we only stop the wrong name being written back. * * **3. "a Worker" is ambiguous, and false under the reading most people take @@ -51,7 +51,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' * The reference doc, the two shipped documents, and the three sources whose * TSDoc ships in `.d.ts`. * - * `packages/stack-supabase/README.md` and `skills/stash-supabase/SKILL.md` + * `languages/typescript/packages/stack-supabase/README.md` and `skills/stash-supabase/SKILL.md` * were both held off this list while #951 rewrote the same lines — the README * carried defect 1 verbatim, and #951's first draft kept the false `so` while * dropping the browser half. This comment is part of #951: both sentences now @@ -72,11 +72,11 @@ import { REPO_ROOT } from './lib/repo-root.mjs' */ const GUARDED = [ 'docs/reference/supabase-sdk.md', - 'packages/stack-supabase/README.md', + 'languages/typescript/packages/stack-supabase/README.md', 'skills/stash-supabase/SKILL.md', - 'packages/stack-supabase/src/index.ts', - 'packages/stack-supabase/src/create.ts', - 'packages/stack-supabase/src/wasm-inline.ts', + 'languages/typescript/packages/stack-supabase/src/index.ts', + 'languages/typescript/packages/stack-supabase/src/create.ts', + 'languages/typescript/packages/stack-supabase/src/wasm-inline.ts', ] function read(file) { @@ -348,7 +348,7 @@ describe('the Supabase two-entry runtime story, as written', () => { (file) => { expect( falseRuntimeCause(prose(file, read(file))), - `${file} attributes a runtime restriction to introspection or to declaring \`schemas\`. The native entry is Node-only because it binds the native engine and because its emitted bundle carries an import("pg") specifier — both true whether or not \`schemas\` is passed. See packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts.`, + `${file} attributes a runtime restriction to introspection or to declaring \`schemas\`. The native entry is Node-only because it binds the native engine and because its emitted bundle carries an import("pg") specifier — both true whether or not \`schemas\` is passed. See languages/typescript/packages/stack-supabase/__tests__/wasm-entry-edge-safety.test.ts.`, ).toEqual([]) }, ) @@ -368,7 +368,7 @@ describe('the Supabase two-entry runtime story, as written', () => { (file) => { expect( protectFfiImportLoadClaims(prose(file, read(file))), - `${file} says importing \`@cipherstash/protect-ffi\` loads a native binary. It does not: packages/protect-ffi/src/index.cts uses \`import native = require('./load.cjs')\` so the @neon-rs/load proxy is never enumerated into resolving the platform binary, guarded by packages/protect-ffi/src/nativeLoading.test.ts. The module-evaluation-time load in that graph is \`@cipherstash/auth\`'s.`, + `${file} says importing \`@cipherstash/protect-ffi\` loads a native binary. It does not: languages/typescript/packages/protect-ffi/src/index.cts uses \`import native = require('./load.cjs')\` so the @neon-rs/load proxy is never enumerated into resolving the platform binary, guarded by languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts. The module-evaluation-time load in that graph is \`@cipherstash/auth\`'s.`, ).toEqual([]) }, ) diff --git a/scripts/__tests__/sync-lockstep-versions.test.mjs b/scripts/__tests__/sync-lockstep-versions.test.mjs index 8b7ff3d0c..baac703d1 100644 --- a/scripts/__tests__/sync-lockstep-versions.test.mjs +++ b/scripts/__tests__/sync-lockstep-versions.test.mjs @@ -90,7 +90,7 @@ function captureRefresh() { refreshCargoLock({ root: '/repo', eqlRoot: '/repo/packages/eql', - workspace: 'packages/protect-ffi', + workspace: 'languages/typescript/packages/protect-ffi', run: (...args) => calls.push(args), }) expect(calls).toHaveLength(1) @@ -104,7 +104,7 @@ function captureRefresh() { * version. Every `Cargo.lock` that resolves that crate FROM A PATH records the * old one, and nothing in this repo passes `--locked`, so the stale lock is * regenerated on every CI run, used, and discarded — green the whole way. - * `cargo metadata --locked` in `packages/protect-ffi` exited 101 for exactly + * `cargo metadata --locked` in `languages/typescript/packages/protect-ffi` exited 101 for exactly * this reason after the 3.0.5 bump. * * `scripts/__tests__/cargo-lock-freshness.test.mjs` is the guard that fails a @@ -117,11 +117,11 @@ describe('lockstep Cargo.lock refresh', () => { // The floor. Discovery over a hardcoded list means a walk that stops // matching refreshes nothing and reports success — so an empty result is a - // failure, not a no-op. `packages/protect-ffi` is named because it is the + // failure, not a no-op. `languages/typescript/packages/protect-ffi` is named because it is the // consumer that broke: it path-depends on the crate from a SEPARATE cargo // workspace, so no eql-side build ever touches its lock. expect(found.length).toBeGreaterThan(0) - expect(found).toContain('packages/protect-ffi') + expect(found).toContain('languages/typescript/packages/protect-ffi') }) test('refreshes through mise, against the named workspace', () => { @@ -140,7 +140,9 @@ describe('lockstep Cargo.lock refresh', () => { expect(args).toContain('--package') expect(args).toContain(LOCKED_CRATE) expect(args).toContain('--manifest-path') - expect(args).toContain('/repo/packages/protect-ffi/Cargo.toml') + expect(args).toContain( + '/repo/languages/typescript/packages/protect-ffi/Cargo.toml', + ) }) /** @@ -150,7 +152,7 @@ describe('lockstep Cargo.lock refresh', () => { * why would refreshing it need a registry? Because `cargo update -p X` does * not update X in isolation: it re-resolves the WHOLE graph and rewrites a * complete lock, and in offline mode every other package has to come from - * the local registry cache. `packages/protect-ffi` has 167 of them. + * the local registry cache. `languages/typescript/packages/protect-ffi` has 167 of them. * * The release job has no such cache. `jdx/mise-action` runs there with * `install: true, cache: false` — it installs toolchains and populates @@ -210,7 +212,7 @@ describe('lockstep Cargo.lock refresh', () => { refreshCargoLock({ root: '/repo', eqlRoot: '/repo/packages/eql', - workspace: 'packages/protect-ffi', + workspace: 'languages/typescript/packages/protect-ffi', run: () => { throw new Error('spawn mise ENOENT') }, diff --git a/scripts/__tests__/turbo-skills-inputs.test.mjs b/scripts/__tests__/turbo-skills-inputs.test.mjs index a7c0998e1..3fe0240f3 100644 --- a/scripts/__tests__/turbo-skills-inputs.test.mjs +++ b/scripts/__tests__/turbo-skills-inputs.test.mjs @@ -1,7 +1,7 @@ /** * A build that copies `skills/` must declare `skills/` as an input. * - * `packages/cli` and `packages/wizard` both `cpSync('../../skills', + * `languages/typescript/packages/cli` and `languages/typescript/packages/wizard` both `cpSync('../../skills', * 'dist/skills')` — they consume a directory outside their own package, which * turbo's `$TURBO_DEFAULT$` does not cover. On its own that only meant a stale * cache entry stayed valid; once `build` declared `outputs: ["dist/**"]`, a diff --git a/scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs b/scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs index a8d34b898..5c986964c 100644 --- a/scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs +++ b/scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs @@ -24,7 +24,7 @@ import { readWorkflow, workflowFiles } from './lib/workflows.mjs' * * That was live, twice. * - * - `packages/protect-ffi/scripts/inline-wasm.mjs` and + * - `languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs` and * `tsconfig.wasm-errors.json` are both in the WASM key (they are * `build:wasm`'s non-cargo half) and neither was listed in * `integration-drizzle.yml` — the workflow whose `CS_IT_SUITE` selects @@ -60,7 +60,7 @@ const CACHE_ACTION = /^actions\/cache(\/(restore|save))?@/ const FILTERED_EVENTS = ['push', 'pull_request'] /** The package whose Rust both cache keys are about. */ -const FFI_PACKAGE = 'packages/protect-ffi' +const FFI_PACKAGE = 'languages/typescript/packages/protect-ffi' const FFI_PACKAGE_NAME = '@cipherstash/protect-ffi' /** What a command has to reach before it is compiling anything. */ @@ -108,8 +108,8 @@ function cachedPaths(step) { * Everything before a glob's first wildcard SEGMENT — the deepest path both a * cache pattern and a `paths:` entry can be compared on. * - * `packages/protect-ffi/crates/**` -> `packages/protect-ffi/crates` - * `packages/protect-ffi/src/errors.ts` -> itself (no wildcard) + * `languages/typescript/packages/protect-ffi/crates/**` -> `languages/typescript/packages/protect-ffi/crates` + * `languages/typescript/packages/protect-ffi/src/errors.ts` -> itself (no wildcard) */ function literalPrefix(pattern) { const segments = pattern.split('/') @@ -123,7 +123,7 @@ function literalPrefix(pattern) { * The patterns a key hashes that are BUILD INPUTS, which is not all of them. * * A key hashes files for two different reasons, and only one of them implies a - * trigger. `packages/protect-ffi/dist/wasm/*.d.ts` is in the WASM key because + * trigger. `languages/typescript/packages/protect-ffi/dist/wasm/*.d.ts` is in the WASM key because * those declarations are tracked in git AND inside the cached directory, so a * restore would overwrite them — hashing them makes any restore that lands * necessarily byte-identical (see the action's comment, and the first suite in @@ -294,7 +294,7 @@ function usesAction(relPath, { wasmOnly = false } = {}) { * Compiles this package's Rust — through the action, or directly. * * The direct forms are scoped: either the command targets the package by name - * (`pnpm --filter @cipherstash/protect-ffi …`, `pnpm --dir packages/protect-ffi + * (`pnpm --filter @cipherstash/protect-ffi …`, `pnpm --dir languages/typescript/packages/protect-ffi * …`) or the step runs INSIDE it, so a `cargo` elsewhere in the monorepo — the * EQL workspace has its own, with its own workflows — is not mistaken for this * one. @@ -395,7 +395,7 @@ const KEYS = [ { id: 'wasm', step: WASM_CACHE_STEP, - what: '`packages/protect-ffi/dist/wasm/**` — including `protect_ffi_inline.js`, the bundle `@cipherstash/stack/wasm-inline` imports', + what: '`languages/typescript/packages/protect-ffi/dist/wasm/**` — including `protect_ffi_inline.js`, the bundle `@cipherstash/stack/wasm-inline` imports', reaches: "runs the action with `wasm: 'true'`", workflows: ALL_WORKFLOWS.filter((relPath) => usesAction(relPath, { wasmOnly: true }), @@ -430,7 +430,7 @@ describe('the FFI cache keys and the filters that trigger them agree', () => { it('derives the commands that compile this package Rust', () => { // The native key's consumers are not only the action's callers, so the - // discovery reads `packages/protect-ffi`'s own scripts and mise tasks. If + // discovery reads `languages/typescript/packages/protect-ffi`'s own scripts and mise tasks. If // either set empties, `compilesFfiRust` degrades to "uses the action" and // a workflow like tests-rust.yml silently stops being checked. expect( diff --git a/scripts/__tests__/wasm-core-contract-ci.test.mjs b/scripts/__tests__/wasm-core-contract-ci.test.mjs index 6435cce05..e95d6ecac 100644 --- a/scripts/__tests__/wasm-core-contract-ci.test.mjs +++ b/scripts/__tests__/wasm-core-contract-ci.test.mjs @@ -12,16 +12,16 @@ import { REPO_ROOT } from './lib/repo-root.mjs' import { readWorkflow, workflowFiles } from './lib/workflows.mjs' /** - * `packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts` loads + * `languages/typescript/packages/stack/__tests__/wasm-inline-core-credential-contract.test.ts` loads * the REAL protect-ffi WASM core. It is NOT the only suite that does — - * `packages/stack/integration/wasm/**`, protect-ffi's own `wasm-round-trip` / + * `languages/typescript/packages/stack/integration/wasm/**`, protect-ffi's own `wasm-round-trip` / * `wasm-error-codes`, and the Deno smoke tests in `e2e/wasm/` all do, and three * CI jobs build `dist/wasm/**` for them. Nor is it the only one that needs the * core and NOTHING ELSE — protect-ffi's `wasm-error-codes` is deliberately * credential-free too, but it lives in `integration-tests/`, whose other files * need Docker and credentials and whose workflow is path-filtered and * fork-skipped: the fate this arrangement declines. What put THIS suite in its - * own config is that its alternative, `packages/stack/integration/**`, has a + * own config is that its alternative, `languages/typescript/packages/stack/integration/**`, has a * `globalSetup` requiring credentials AND a database unconditionally, throwing * rather than skipping — pinned by the last case in the first block below, * because until then that fact lived in prose alone. This docblock claimed the @@ -31,15 +31,15 @@ import { readWorkflow, workflowFiles } from './lib/workflows.mjs' * What the arrangement does depend on is FOUR pieces, and losing any one leaves * the contract unchecked: * - * 1. the exclusion in `packages/stack/vitest.config.ts` - * 2. the `test:wasm-core` script in `packages/stack/package.json` + * 1. the exclusion in `languages/typescript/packages/stack/vitest.config.ts` + * 2. the `test:wasm-core` script in `languages/typescript/packages/stack/package.json` * 3. the step in the CI job that builds `dist/wasm/**` * 4. the `test:wasm-core` task in `turbo.json` * * Piece 3 is the quiet one: delete the step and the suite runs nowhere while * the exclusion keeps `pnpm test` green, so nothing says the contract stopped * being checked. Same shape as - * `packages/protect-ffi/src/integrationSuiteCi.test.ts` (a suite whose workflow + * `languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts` (a suite whose workflow * was deposited where GitHub never reads it) and `lintWiring.test.ts`'s "a * check nothing invokes reads exactly like a check that passes". * @@ -91,7 +91,10 @@ const VITEST_DEFAULT_TIMEOUT_MS = 5000 const BROWSER_GUARD_SUITE = '__tests__/browser-export-condition.test.ts' const stackPackageJson = JSON.parse( - readFileSync(join(REPO_ROOT, 'packages/stack/package.json'), 'utf8'), + readFileSync( + join(REPO_ROOT, 'languages/typescript/packages/stack/package.json'), + 'utf8', + ), ) /** `turbo.json` carries comments, so it needs the jsonc reader. */ @@ -143,9 +146,11 @@ function excludedBy(patterns, relPath) { describe('the WASM core credential contract runs somewhere (#804)', () => { it('the suite the whole arrangement is about still exists', () => { - expect(existsSync(join(REPO_ROOT, 'packages/stack', WASM_CORE_SUITE))).toBe( - true, - ) + expect( + existsSync( + join(REPO_ROOT, 'languages/typescript/packages/stack', WASM_CORE_SUITE), + ), + ).toBe(true) }) it('is the only file its own config collects', () => { @@ -177,7 +182,10 @@ describe('the WASM core credential contract runs somewhere (#804)', () => { it(`is invoked by \`${SCRIPT}\`, pointed at that config`, () => { const command = stackPackageJson.scripts?.[SCRIPT] - expect(command, `packages/stack has no \`${SCRIPT}\` script`).toBeDefined() + expect( + command, + `languages/typescript/packages/stack has no \`${SCRIPT}\` script`, + ).toBeDefined() expect(command).toContain('vitest.wasm-core.config.ts') }) @@ -240,15 +248,18 @@ describe('the WASM core credential contract runs somewhere (#804)', () => { // wrong, and nothing would say so. The reviewer who next proposes the // move should find this red rather than find prose. const globalSetup = readFileSync( - join(REPO_ROOT, 'packages/test-kit/src/integration/global-setup.ts'), + join( + REPO_ROOT, + 'languages/typescript/packages/test-kit/src/integration/global-setup.ts', + ), 'utf8', ) // Both requirements in the UNCONDITIONAL base literal. `pgrest` is the one // pushed under an `if`, and that asymmetry is exactly the claim. expect( globalSetup, - 'packages/test-kit/src/integration/global-setup.ts no longer requires BOTH `cipherstash` and `database` unconditionally.\n' + - `If that is deliberate, ${WASM_CORE_SUITE} can move into packages/stack/integration/wasm/ and this whole arrangement (config, script, turbo task, CI step) can go with it — see the docblocks in vitest.wasm-core.config.ts and tests.yml, which argue from this fact.`, + 'languages/typescript/packages/test-kit/src/integration/global-setup.ts no longer requires BOTH `cipherstash` and `database` unconditionally.\n' + + `If that is deliberate, ${WASM_CORE_SUITE} can move into languages/typescript/packages/stack/integration/wasm/ and this whole arrangement (config, script, turbo task, CI step) can go with it — see the docblocks in vitest.wasm-core.config.ts and tests.yml, which argue from this fact.`, ).toMatch( /const requirements: Requirement\[\] = \[\s*'cipherstash',\s*'database',?\s*\]/, ) @@ -283,8 +294,11 @@ describe('the `browser` export-condition guard runs everywhere (#804)', () => { // runs only Biome). Moving it into each package's default suite is what // these two cases hold in place. const guards = [ - { pkg: 'packages/stack', config: stackVitestConfig }, - { pkg: 'packages/stack-supabase', config: supabaseVitestConfig }, + { pkg: 'languages/typescript/packages/stack', config: stackVitestConfig }, + { + pkg: 'languages/typescript/packages/stack-supabase', + config: supabaseVitestConfig, + }, ] for (const { pkg, config } of guards) { diff --git a/scripts/__tests__/workflow-mise-setup.test.mjs b/scripts/__tests__/workflow-mise-setup.test.mjs index cbc3f0f1f..7e1629b5a 100644 --- a/scripts/__tests__/workflow-mise-setup.test.mjs +++ b/scripts/__tests__/workflow-mise-setup.test.mjs @@ -333,7 +333,7 @@ describe('the mise setup step carries the inputs it depends on', () => { it('points every mise setup step at a directory that has a mise config', () => { // THE TRUST ERROR. mise reads config from the current directory and its // PARENTS, and this repo has NO mise config at its root — the two that - // exist are `packages/eql/mise.toml` and `packages/protect-ffi/mise.toml`. + // exist are `packages/eql/mise.toml` and `languages/typescript/packages/protect-ffi/mise.toml`. // So an action running at the default working directory finds nothing to // install and leaves the config untrusted, and the first `mise run` fails // with "Config files … are not trusted", which reads as a broken toolchain diff --git a/scripts/__tests__/workflow-trigger-comments.test.mjs b/scripts/__tests__/workflow-trigger-comments.test.mjs index fe1431222..21644f013 100644 --- a/scripts/__tests__/workflow-trigger-comments.test.mjs +++ b/scripts/__tests__/workflow-trigger-comments.test.mjs @@ -18,7 +18,7 @@ import { readWorkflow, workflowFiles } from './lib/workflows.mjs' * It did. Both prisma workflows carried "the step itself is only ever exercised * by the push-to-main run", written when the protect-ffi inputs were about to be * added to the `push` filter, and left in place after they were added to the - * `pull_request` filter as well. A PR touching `packages/protect-ffi/src/**` has + * `pull_request` filter as well. A PR touching `languages/typescript/packages/protect-ffi/src/**` has * run both workflows since the day those entries landed. The comment told you it * could not — which is worse than no comment, because the next person reasoning * about protect-ffi coverage on PRs reads it and concludes there is none, and @@ -64,7 +64,7 @@ const BUILD_FFI_ACTION = '.github/actions/build-ffi-binding' * binding": anything in them must miss the cache and recompile. Reusing them * means this scope follows the action. Add a build input to the key and the set * of workflows held to the invariant below grows with it; the alternative — a - * hardcoded `packages/protect-ffi/**` — would keep passing while quietly + * hardcoded `languages/typescript/packages/protect-ffi/**` — would keep passing while quietly * describing a different package than the one CI builds. * * The action's own directory is in the set for the same reason it is in both @@ -91,9 +91,9 @@ const BINDING_INPUTS = bindingBuildInputs() * Do a `paths:` entry and a build input describe overlapping trees? * * Overlap in EITHER direction, because both sides are globs and either can be - * the broader one: the filter may say `packages/protect-ffi/src/**` against an - * input file, or `packages/protect-ffi/crates/protect-ffi/**` against the - * input glob `packages/protect-ffi/crates/**`. Both mean a change to the + * the broader one: the filter may say `languages/typescript/packages/protect-ffi/src/**` against an + * input file, or `languages/typescript/packages/protect-ffi/crates/protect-ffi/**` against the + * input glob `languages/typescript/packages/protect-ffi/crates/**`. Both mean a change to the * binding can trigger the workflow, which is the only question being asked. */ function overlaps(entry, input) { @@ -235,7 +235,7 @@ describe('workflow trigger comments match the trigger', () => { expect( BINDING_INPUTS, `No \`hashFiles(...)\` globs were parsed out of ${BUILD_FFI_ACTION}/action.yml, so "a change to the protect-ffi binding" resolves to nothing and every workflow falls out of scope. Either the cache steps moved (follow them), or the key syntax changed (update bindingBuildInputs).`, - ).toContain('packages/protect-ffi/crates/**') + ).toContain('languages/typescript/packages/protect-ffi/crates/**') expect(BINDING_INPUTS).toContain(`${BUILD_FFI_ACTION}/**`) }) diff --git a/scripts/ffi-release-matrix.mjs b/scripts/ffi-release-matrix.mjs index 20495eb01..c4475fbf7 100644 --- a/scripts/ffi-release-matrix.mjs +++ b/scripts/ffi-release-matrix.mjs @@ -36,7 +36,10 @@ import process from 'node:process' import { fileURLToPath } from 'node:url' const REPO_ROOT = resolve(import.meta.dirname, '..') -const PLATFORMS_DIR = join(REPO_ROOT, 'packages/protect-ffi/platforms') +const PLATFORMS_DIR = join( + REPO_ROOT, + 'languages/typescript/packages/protect-ffi/platforms', +) /** * Where each platform builds. diff --git a/scripts/lint-no-dead-package-paths.mjs b/scripts/lint-no-dead-package-paths.mjs index 9d3b52ed3..33f0a15ea 100644 --- a/scripts/lint-no-dead-package-paths.mjs +++ b/scripts/lint-no-dead-package-paths.mjs @@ -24,7 +24,7 @@ const TARGETS = process.argv.slice(2).length '.github', 'skills', 'e2e/README.md', - 'packages/cli/AGENTS.md', + 'languages/typescript/packages/cli/AGENTS.md', // The linters themselves carry package paths — an allowlist entry for a // deleted package sat here unnoticed because `scripts/` was not scanned. // `__tests__` is excluded below: its fixtures MUST name dead packages. @@ -46,12 +46,12 @@ const SKIP_FILES = new Set(['CHANGELOG.md']) const TEXT_EXT = /\.(md|ya?ml|json|mjs|ts|txt)$/ // `packages/` where `` is a real directory name. The character -// class excludes `*`, so workspace globs (`packages/*`, `./packages/*`) are +// class excludes `*`, so workspace globs (`languages/typescript/packages/*`, `./languages/typescript/packages/*`) are // left alone, and it is greedy so a longer directory name is never excused by // a live package whose name is a prefix of it. // // The name must END on an alphanumeric. Without that anchor a sentence-final -// `packages/stack.` — or a hyphen at a line wrap, or a trailing underscore — +// `languages/typescript/packages/stack.` — or a hyphen at a line wrap, or a trailing underscore — // captured the punctuation too and reported a LIVE package as dead, failing // the build with a message naming a directory that plainly exists. Uppercase // is admitted so a capitalised directory name is checked rather than silently @@ -69,8 +69,8 @@ const PACKAGE_REF = /packages\/([a-zA-Z0-9](?:[a-zA-Z0-9._-]*[a-zA-Z0-9])?)/g // by this very stack are sitting on `main` right now as exactly such shells // (#772 review, finding 15). // -// Note this deliberately does NOT require a `package.json`: `packages/utils` has -// none (it is two loose files consumed by relative path from `packages/nextjs`) +// Note this deliberately does NOT require a `package.json`: `languages/typescript/packages/utils` has +// none (it is two loose files consumed by relative path from `languages/typescript/packages/nextjs`) // yet is tracked, live, and referenced from AGENTS.md. // // Shelling out to git is a dependency this linter has to own: git missing, or a diff --git a/scripts/lint-no-eql-registry-pins.mjs b/scripts/lint-no-eql-registry-pins.mjs index 0bdc21174..8338f26ce 100644 --- a/scripts/lint-no-eql-registry-pins.mjs +++ b/scripts/lint-no-eql-registry-pins.mjs @@ -9,7 +9,7 @@ * the SQL bundle that STORES and queries one). They are released at a single * lockstep version for exactly that reason. * - * Before the subtree import, `packages/protect-ffi` pinned `eql-bindings + * Before the subtree import, `languages/typescript/packages/protect-ffi` pinned `eql-bindings * = "=3.0.2"` from crates.io while the EQL tree carried 3.0.4. That skew was * benign only by luck — the Rust was byte-identical across those releases, and * what 3.0.3/3.0.4 changed was SQL. Phase 3 of the absorption plan replaced the @@ -140,12 +140,12 @@ const SKIP_DIRS = new Set([ * message rather than a re-derivation from the tree. */ export const EXPECTED_DECLARERS = [ - `packages/cli/package.json :: ${NPM_DEPENDENCY}`, + `languages/typescript/packages/cli/package.json :: ${NPM_DEPENDENCY}`, `packages/eql/tests/sqlx/Cargo.toml :: ${CARGO_DEPENDENCY}`, - `packages/protect-ffi/crates/protect-ffi/Cargo.toml :: ${CARGO_DEPENDENCY}`, - `packages/protect-ffi/integration-tests/package.json :: ${NPM_DEPENDENCY}`, - `packages/stack-prisma/package.json :: ${NPM_DEPENDENCY}`, - `packages/stack/package.json :: ${NPM_DEPENDENCY}`, + `languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml :: ${CARGO_DEPENDENCY}`, + `languages/typescript/packages/protect-ffi/integration-tests/package.json :: ${NPM_DEPENDENCY}`, + `languages/typescript/packages/stack-prisma/package.json :: ${NPM_DEPENDENCY}`, + `languages/typescript/packages/stack/package.json :: ${NPM_DEPENDENCY}`, ] /** @@ -171,7 +171,7 @@ export const EXPECTED_SOURCES = [WORKSPACE_FILE] * place the two halves of EQL can drift apart again, and the reason is what a * later reader needs in order to decide whether it is still true. * - * There was one, for `packages/protect-ffi/integration-tests`: it was not a + * There was one, for `languages/typescript/packages/protect-ffi/integration-tests`: it was not a * pnpm workspace member, installed with `npm ci`, and so could not resolve a * `workspace:` specifier at all. Absorbing it into the workspace (CIP-3744) was * what retired the exemption — and the `staleExemptions` spelling below is what @@ -185,7 +185,7 @@ export const EXPECTED_SOURCES = [WORKSPACE_FILE] */ export const EXEMPT_DECLARATIONS = new Map([ [ - 'packages/cli/package.json :: @cipherstash/eql-upgrade-baseline', + 'languages/typescript/packages/cli/package.json :: @cipherstash/eql-upgrade-baseline', 'Test-only immutable upgrade origin: the credentialed live installer test ' + 'must install a real previously released bundle before the workspace ' + 'installer upgrades it. Runtime `@cipherstash/eql` and the payload-emitting ' + @@ -661,7 +661,7 @@ export function lint({ // // Measured against the declarations that are ACTUALLY registry-pinned, not // against every declaration found. The difference is the case that already - // happened: `packages/protect-ffi/integration-tests` was exempt because it + // happened: `languages/typescript/packages/protect-ffi/integration-tests` was exempt because it // installed with `npm ci` and could not take a `workspace:` specifier, and // absorbing it into the workspace was a scheduled follow-up. When that // landed the manifest still declared `@cipherstash/eql` — so an diff --git a/scripts/lint-no-hardcoded-runners.mjs b/scripts/lint-no-hardcoded-runners.mjs index bdf058650..cf1158b38 100644 --- a/scripts/lint-no-hardcoded-runners.mjs +++ b/scripts/lint-no-hardcoded-runners.mjs @@ -7,8 +7,8 @@ const REPO_ROOT = resolve(import.meta.dirname, '..') // Files that legitimately contain a `npx` literal — keep this list // short and explicit so additions require deliberate review. const ALLOWLISTED_PATHS = new Set([ - 'packages/wizard/src/lib/detect.ts', // npm row of the PM table - 'packages/cli/src/commands/init/utils.ts', // runnerCommand `case 'npm'` + 'languages/typescript/packages/wizard/src/lib/detect.ts', // npm row of the PM table + 'languages/typescript/packages/cli/src/commands/init/utils.ts', // runnerCommand `case 'npm'` 'scripts/lint-no-hardcoded-runners.mjs', // this script's own docs ]) @@ -186,8 +186,8 @@ if (offenders.length > 0) { for (const o of offenders) console.error(` ${o}`) console.error( '\nUse the detected package manager instead. See ' + - 'packages/cli/src/commands/init/utils.ts (runnerCommand) and ' + - 'packages/wizard/src/lib/detect.ts (detectPackageManager).', + 'languages/typescript/packages/cli/src/commands/init/utils.ts (runnerCommand) and ' + + 'languages/typescript/packages/wizard/src/lib/detect.ts (detectPackageManager).', ) process.exit(1) } diff --git a/scripts/lint-no-workflow-caching.mjs b/scripts/lint-no-workflow-caching.mjs index b8d280523..bbc3f309b 100644 --- a/scripts/lint-no-workflow-caching.mjs +++ b/scripts/lint-no-workflow-caching.mjs @@ -75,7 +75,7 @@ const PARENT_USES = /^\.\.\// // `useblacksmith/cache@v5` and `Swatinem/rust-cache@v2`: `OK`, exit 0. Both are // live-relevant here — eleven jobs in this repo run on `blacksmith-*` runners, // where `useblacksmith/cache` is the documented drop-in for `actions/cache`, -// and the absorbed Cargo workspace at `packages/protect-ffi` is exactly where +// and the absorbed Cargo workspace at `languages/typescript/packages/protect-ffi` is exactly where // someone reaches for `Swatinem/rust-cache`. // // The obvious repair is to enumerate the cache actions — by name @@ -162,7 +162,7 @@ const AUDITED_ACTIONS = new Map([ ['actions/upload-artifact', { cacheInput: null }], ['actions/download-artifact', { cacheInput: null }], // Supplies zig + cargo-zigbuild (the glibc-pinned gnu builds) and wasm-pack, - // all pinned in packages/protect-ffi/mise.toml. `cache` DEFAULTS TO TRUE, so + // all pinned in languages/typescript/packages/protect-ffi/mise.toml. `cache` DEFAULTS TO TRUE, so // an omitted key is a cache restore — and the generic `with.cache` rule below // fires only on a truthy value, which is how a mise-action step carrying no // `cache:` passed this gate. SHA-pinned at every call site. diff --git a/scripts/lint-typecheck-scope.mjs b/scripts/lint-typecheck-scope.mjs index 1dee35582..25ba01352 100644 --- a/scripts/lint-typecheck-scope.mjs +++ b/scripts/lint-typecheck-scope.mjs @@ -31,13 +31,13 @@ const REPO_ROOT = resolve(import.meta.dirname, '..') // with argv[2..] for tests / ad-hoc checks (each arg is a package directory). // // NESTED roots are listed separately because the walk below is one level deep, -// matching how pnpm globs `packages/*`. Three sets of packages sit a level +// matching how pnpm globs `languages/typescript/packages/*`. Three sets of packages sit a level // further down and need their own entry here for the same reason they need one // in `pnpm-workspace.yaml`: // -// packages/protect-ffi/platforms/* the six per-platform binary packages +// languages/typescript/packages/protect-ffi/platforms/* the six per-platform binary packages // packages/eql/packages/* @cipherstash/eql, from the EQL subtree -// packages/protect-ffi/* the live integration suite +// languages/typescript/packages/protect-ffi/* the live integration suite // // The last is spelled as its PARENT rather than as the member, because the walk // takes roots and lists their children. That sweeps protect-ffi's non-package @@ -52,8 +52,8 @@ const REPO_ROOT = resolve(import.meta.dirname, '..') const WORKSPACE_ROOTS = [ 'packages', 'examples', - 'packages/protect-ffi', - 'packages/protect-ffi/platforms', + 'languages/typescript/packages/protect-ffi', + 'languages/typescript/packages/protect-ffi/platforms', 'packages/eql/packages', ] @@ -185,7 +185,7 @@ if (offenders.length > 0) { ' "exclude": ["dist", "node_modules"]\n\n' + '(`exclude` REPLACES the default list, so `node_modules` must be re-listed.)\n' + 'Or give it an explicit `include` naming the source roots, as `e2e` and\n' + - '`examples/prisma` do.', + '`languages/typescript/examples/prisma` do.', ) process.exit(1) } diff --git a/scripts/release-gate.mjs b/scripts/release-gate.mjs index 95b52b86d..52e031c71 100644 --- a/scripts/release-gate.mjs +++ b/scripts/release-gate.mjs @@ -100,10 +100,10 @@ const DEPENDENCY_TABLES = [ * specifier there too, and the rewritten range does ship inside the packed * `package.json` — but nothing installing the package ever resolves it, so an * unsatisfiable one breaks nobody. That asymmetry is live in this tree: - * `packages/stack` declares `"@cipherstash/eql": "workspace:^"` under + * `languages/typescript/packages/stack` declares `"@cipherstash/eql": "workspace:^"` under * devDependencies and is not a finding — a caret there is harmless, which is - * why it is still written that way, while `packages/cli` and - * `packages/stack-prisma` carry the same dependency under `dependencies` and + * why it is still written that way, while `languages/typescript/packages/cli` and + * `languages/typescript/packages/stack-prisma` carry the same dependency under `dependencies` and * pin it with `workspace:*` so the packed range is exact. */ const INSTALLED_TABLES = new Set([ @@ -161,7 +161,7 @@ export const FROZEN_PUBLISHERS = new Map([]) * `@cipherstash/eql`, while it was frozen, was the case that proved it. The * subtree sat at `3.0.5` with an install bundle hashing `7ad9c9f8…` while npm's * `3.0.5` was `accde0030…` — upstream had restored the deprecated - * `ste_vec_contains` aliases in the actual release. `packages/cli`'s installer + * `ste_vec_contains` aliases in the actual release. `languages/typescript/packages/cli`'s installer * reads that SQL verbatim (`readInstallSql`, no digest check), so * `stash eql install` would have put functions into a customer database that * the version it reports does not define. It was caught by a human reading the diff --git a/scripts/sync-lockstep-versions.mjs b/scripts/sync-lockstep-versions.mjs index ffc848288..4c2dd7b31 100644 --- a/scripts/sync-lockstep-versions.mjs +++ b/scripts/sync-lockstep-versions.mjs @@ -17,7 +17,7 @@ // crate and the npm package — UNLESS the tree already carries those assets // at V, in which case step 4 is skipped. See `eqlLockstepSkew` for why. // -// Step 3 is not decoration. Step 2 moves a version that `packages/protect-ffi`'s +// Step 3 is not decoration. Step 2 moves a version that `languages/typescript/packages/protect-ffi`'s // SEPARATE cargo workspace has pinned in its own lock, and nothing else updates // it — `packages/eql`'s lock is refreshed as a side effect of step 4, that one // by nothing at all. Since no command in this repo passes `--locked`, the stale @@ -75,10 +75,10 @@ const SKIP_DIRS = new Set([ * tree, repo-relative. * * DISCOVERED, not listed. The crate is consumed across cargo workspace - * boundaries — `packages/protect-ffi/crates/protect-ffi/Cargo.toml` reaches it + * boundaries — `languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml` reaches it * by `path = "../../../eql/crates/eql-bindings"` — and a hardcoded list is * exactly what was missing before: `packages/eql`'s own lock is refreshed as a - * side effect of the SQL build below, `packages/protect-ffi`'s was refreshed by + * side effect of the SQL build below, `languages/typescript/packages/protect-ffi`'s was refreshed by * nothing, and no one noticed because no command in this repo passes * `--locked`. * @@ -126,7 +126,7 @@ export function cargoLockWorkspaces(root) { * path, so the flag reads as free — but `cargo update -p X` does not update X * in isolation. It re-resolves the whole graph and rewrites a complete lock, * and offline that means every OTHER package has to be served from the local - * registry cache; `packages/protect-ffi` has 167 of them. The release job has + * registry cache; `languages/typescript/packages/protect-ffi` has 167 of them. The release job has * no such cache — `jdx/mise-action` runs there with `cache: false`, installing * toolchains and populating nothing under `~/.cargo/registry`, and * `scripts/lint-no-workflow-caching.mjs` forbids a cache restore anywhere an diff --git a/skills/stash-edge/SKILL.md b/skills/stash-edge/SKILL.md index de81dd4aa..57ecf6a2f 100644 --- a/skills/stash-edge/SKILL.md +++ b/skills/stash-edge/SKILL.md @@ -486,7 +486,7 @@ entry is ESM-only. Move the consumer to ESM. **Missing `CS_*` at runtime** — the secret store was never populated, or the function was served without `--env-file`. Validate the ones you pass at handler entry and return an actionable error rather than letting client construction fail -opaquely; the example in `examples/supabase-worker` does exactly this. +opaquely; the example in `languages/typescript/examples/supabase-worker` does exactly this. **Encryption works, search returns zero rows** — not a credential problem: a keyset mismatch fails everything loudly, decrypt included (see [Keysets and @@ -514,5 +514,5 @@ user-scoped, so it is reused across invocations on a warm isolate. wherever the app runs). - `stash-supabase` — the PostgREST wrapper, for Supabase apps that are not writing raw SQL. -- Working example: `examples/supabase-worker` in the `cipherstash/stack` repo. +- Working example: `languages/typescript/examples/supabase-worker` in the `cipherstash/stack` repo. - Bundling guide: https://cipherstash.com/docs/stack/deploy/bundling diff --git a/skills/stash-supply-chain-security/SKILL.md b/skills/stash-supply-chain-security/SKILL.md index 9940dc359..6df77728f 100644 --- a/skills/stash-supply-chain-security/SKILL.md +++ b/skills/stash-supply-chain-security/SKILL.md @@ -63,7 +63,7 @@ Dependabot opens grouped, cooldown'd PRs (7 days minor/patch) for `npm`, `cargo` There is deliberately **no `semver-major-days` cooldown** on any entry. It would delay major *version update* PRs, which the `ignore` above means Dependabot never opens, and cooldown does not reach the security path either ("the cooldown option is only available for version updates, not security updates"). Don't add one back as a safety net for the day the `ignore` is dropped — dead config reads as policy, and the test below fails on the pair. -`cargo` covers the in-tree Rust workspace at `packages/protect-ffi` (**not** the repo root — that is where `Cargo.toml`/`Cargo.lock` live). It runs monthly rather than weekly because each bump costs a native rebuild to validate, and it ignores the exact-pinned CipherStash crates (`cipherstash-client`, `cts-common`, `stack-auth`, `stack-profile`, `eql-bindings`, `vitaminc`) — they share a release train with the `@cipherstash/auth` catalog and must be bumped together, manually. +`cargo` covers the in-tree Rust workspace at `languages/typescript/packages/protect-ffi` (**not** the repo root — that is where `Cargo.toml`/`Cargo.lock` live). It runs monthly rather than weekly because each bump costs a native rebuild to validate, and it ignores the exact-pinned CipherStash crates (`cipherstash-client`, `cts-common`, `stack-auth`, `stack-profile`, `eql-bindings`, `vitaminc`) — they share a release train with the `@cipherstash/auth` catalog and must be bumped together, manually. - **Where**: `.github/dependabot.yml` - **Test asserts**: cooldown ≥ 3 days on npm/github-actions; every entry ignores `version-update:semver-major` for `*` **and** sets no `semver-major-days` (both ends, so neither half can drift alone); every lockfile present in the repo maps to a monitored `package-ecosystem`; every entry's `directory` actually contains the manifest its ecosystem reads @@ -169,7 +169,7 @@ Constraints baked into that workflow — don't undo them: - uses: jdx/mise-action@ # v3.6.3 with: install: true - working_directory: packages/protect-ffi + working_directory: languages/typescript/packages/protect-ffi cache: false # defaults to TRUE — omitting this restores the Actions cache ``` diff --git a/turbo.json b/turbo.json index ac38cf670..a16e2ed75 100644 --- a/turbo.json +++ b/turbo.json @@ -21,7 +21,7 @@ "env": ["STASH_TEST_DATABASE_URL"], "cache": false }, - // `packages/bench`'s "build" is `tsc --noEmit` — a typecheck, not a bundle — + // `languages/typescript/packages/bench`'s "build" is `tsc --noEmit` — a typecheck, not a bundle — // so it emits nothing and the repo-wide `dist/**` would warn on every run. "@cipherstash/bench#build": { "dependsOn": ["^build"], @@ -56,7 +56,7 @@ "inputs": ["$TURBO_DEFAULT$", "$TURBO_ROOT$/skills/**", ".env*"], "env": ["STASH_POSTHOG_KEY"] }, - // Typechecks `packages/stack/dist-types` against the BUILT declarations, so + // Typechecks `languages/typescript/packages/stack/dist-types` against the BUILT declarations, so // it must run after `build` — unlike `test:types`, which reads source. "test:types:dist": { "dependsOn": ["build"], @@ -92,8 +92,8 @@ "inputs": ["$TURBO_DEFAULT$", ".env*"], "cache": false }, - // `packages/stack`'s WASM-core contract suite — see - // `packages/stack/vitest.wasm-core.config.ts` for why it is not part of + // `languages/typescript/packages/stack`'s WASM-core contract suite — see + // `languages/typescript/packages/stack/vitest.wasm-core.config.ts` for why it is not part of // `test`. A task rather than a bare `pnpm --filter` because // `scripts/__tests__/workflow-turbo-build-deps.test.mjs` requires one: // stack depends on workspace packages that emit build output, so a bare diff --git a/vitest.shared.ts b/vitest.shared.ts index 3b2c3554b..c61dd4c1a 100644 --- a/vitest.shared.ts +++ b/vitest.shared.ts @@ -8,8 +8,8 @@ import { resolve } from 'node:path' * subpaths (not stack's internal `@/` alias) because packages outside stack — * `@cipherstash/drizzle`, and the adapter packages after the split — have to be * able to import it too. Left unaliased, those specifiers resolve to - * `packages/stack/dist`, which would couple `pnpm test` to a prior `pnpm build`. - * The matching compile-time mapping is `packages/test-kit/tsconfig.json` `paths`. + * `languages/typescript/packages/stack/dist`, which would couple `pnpm test` to a prior `pnpm build`. + * The matching compile-time mapping is `languages/typescript/packages/test-kit/tsconfig.json` `paths`. * * Spread into each package's vitest config rather than copied, so the two * cannot drift: @@ -23,77 +23,83 @@ export const sharedAlias: Record = { // Longest specifiers first: Vite alias keys are prefix-matched in order. '@cipherstash/test-kit/json-suite': resolve( repoRoot, - 'packages/test-kit/src/run-json-suite.ts', + 'languages/typescript/packages/test-kit/src/run-json-suite.ts', ), '@cipherstash/test-kit/suite': resolve( repoRoot, - 'packages/test-kit/src/run-family-suite.ts', + 'languages/typescript/packages/test-kit/src/run-family-suite.ts', ), '@cipherstash/test-kit/catalog': resolve( repoRoot, - 'packages/test-kit/src/catalog.ts', + 'languages/typescript/packages/test-kit/src/catalog.ts', ), '@cipherstash/test-kit/install': resolve( repoRoot, - 'packages/test-kit/src/install.ts', + 'languages/typescript/packages/test-kit/src/install.ts', ), '@cipherstash/test-kit/integration-clerk': resolve( repoRoot, - 'packages/test-kit/src/integration/clerk.ts', + 'languages/typescript/packages/test-kit/src/integration/clerk.ts', + ), + '@cipherstash/test-kit': resolve( + repoRoot, + 'languages/typescript/packages/test-kit/src/index.ts', ), - '@cipherstash/test-kit': resolve(repoRoot, 'packages/test-kit/src/index.ts'), '@cipherstash/stack/eql/v3': resolve( repoRoot, - 'packages/stack/src/eql/v3/index.ts', + 'languages/typescript/packages/stack/src/eql/v3/index.ts', ), '@cipherstash/stack/schema': resolve( repoRoot, - 'packages/stack/src/schema/index.ts', + 'languages/typescript/packages/stack/src/schema/index.ts', ), '@cipherstash/stack/v3': resolve( repoRoot, - 'packages/stack/src/encryption/v3.ts', + 'languages/typescript/packages/stack/src/encryption/v3.ts', ), // The core↔adapter seam, consumed by the split adapter packages. '@cipherstash/stack/adapter-kit': resolve( repoRoot, - 'packages/stack/src/adapter-kit.ts', + 'languages/typescript/packages/stack/src/adapter-kit.ts', ), '@cipherstash/stack/encryption': resolve( repoRoot, - 'packages/stack/src/encryption/index.ts', + 'languages/typescript/packages/stack/src/encryption/index.ts', ), '@cipherstash/stack/types': resolve( repoRoot, - 'packages/stack/src/types-public.ts', + 'languages/typescript/packages/stack/src/types-public.ts', ), '@cipherstash/stack/errors': resolve( repoRoot, - 'packages/stack/src/errors/index.ts', + 'languages/typescript/packages/stack/src/errors/index.ts', ), '@cipherstash/stack/identity': resolve( repoRoot, - 'packages/stack/src/identity/index.ts', + 'languages/typescript/packages/stack/src/identity/index.ts', ), // The Supabase adapter now lives in its own package (was // `@cipherstash/stack/supabase`); resolve it to source too. '@cipherstash/stack-supabase': resolve( repoRoot, - 'packages/stack-supabase/src/index.ts', + 'languages/typescript/packages/stack-supabase/src/index.ts', ), // The Drizzle adapter package (was `@cipherstash/stack/drizzle` + // `@cipherstash/stack/eql/v3/drizzle`). Root only: the `./v3` subpath // collapsed into it, so there is no longer a longer prefix to order first. '@cipherstash/stack-drizzle': resolve( repoRoot, - 'packages/stack-drizzle/src/index.ts', + 'languages/typescript/packages/stack-drizzle/src/index.ts', ), // Bare entry LAST: it is a prefix of every subpath above, and Vite matches in // order, so the subpaths must win first. Both sibling tsconfigs map bare // `@cipherstash/stack` → `src/index.ts`; without the runtime match here a // consumer importing the bare specifier would fall through to - // `packages/stack/dist`, re-coupling `pnpm test` to a prior `pnpm build`. - '@cipherstash/stack': resolve(repoRoot, 'packages/stack/src/index.ts'), + // `languages/typescript/packages/stack/dist`, re-coupling `pnpm test` to a prior `pnpm build`. + '@cipherstash/stack': resolve( + repoRoot, + 'languages/typescript/packages/stack/src/index.ts', + ), } /** @@ -101,19 +107,19 @@ export const sharedAlias: Record = { * vitest config: stack's own internal `@/` alias — which its source uses and which * therefore leaks into any package that source-resolves it — plus the wasm-inline * stubs for the two `/wasm-inline` subpaths Vitest cannot resolve. All resolve to - * fixed locations under `packages/stack`, so they are shared here rather than + * fixed locations under `languages/typescript/packages/stack`, so they are shared here rather than * copy-pasted into every package's vitest config. * * Spread AFTER `sharedAlias`: `resolve: { alias: { ...sharedAlias, ...stackSourceAlias } }`. */ export const stackSourceAlias: Record = { - '@/': `${resolve(repoRoot, 'packages/stack/src')}/`, + '@/': `${resolve(repoRoot, 'languages/typescript/packages/stack/src')}/`, '@cipherstash/protect-ffi/wasm-inline': resolve( repoRoot, - 'packages/stack/__tests__/helpers/stub-protect-ffi-wasm-inline.ts', + 'languages/typescript/packages/stack/__tests__/helpers/stub-protect-ffi-wasm-inline.ts', ), '@cipherstash/auth/wasm-inline': resolve( repoRoot, - 'packages/stack/__tests__/helpers/stub-auth-wasm-inline.ts', + 'languages/typescript/packages/stack/__tests__/helpers/stub-auth-wasm-inline.ts', ), } From 5867232bde2e15891bd08f4da728c6d1173cef7a Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 09:00:08 +1000 Subject: [PATCH 3/9] fix: repath relative paths that climb out of a moved package Each moved package now sits two levels deeper, so every relative path that climbs to the repository root gains two `..`. A rewrite of `packages/` cannot see these, and several fail silently: - cli and wizard tsup configs copy ../../../../skills. The copy is guarded by existsSync, so the old path built tarballs without skills/ and no error. - seven vitest configs import ../../../../vitest.shared, and the cli scaffold tsconfig extends ../../../../tsconfig.json. - protect-ffi's eql-bindings path dependency becomes ../../../../../../packages/eql/crates/eql-bindings. The comments in workflows, the build-ffi-binding action and scripts that quote it follow. - repository-root helpers built from resolve(x, '../..') or join(..., '..', '..') in the cli tests, test-kit/src/install.ts, the stack-prisma tests and the cli's bundled-folder dev fallback. - protect-ffi tests that read ../../.github and ../../turbo.json relative to process.cwd(), the package root. - e2e/tests imports of ../../packages/cli/src/*.js, which name .ts files, the dist/ and node_modules/ mappings in e2e/wasm/deno.json, and scripts/__tests__ imports of package vitest configs. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- .github/actions/build-ffi-binding/action.yml | 2 +- .github/workflows/integration-drizzle.yml | 4 ++-- .github/workflows/integration-prisma-next.yml | 4 ++-- .github/workflows/integration-protect-ffi.yml | 4 ++-- .github/workflows/integration-supabase.yml | 4 ++-- .github/workflows/prisma-example-readme-e2e.yml | 4 ++-- .github/workflows/prisma-next-e2e.yml | 4 ++-- .github/workflows/tests-rust.yml | 2 +- e2e/tests/package-managers.e2e.test.ts | 8 ++++---- e2e/tests/skill-map-parity.e2e.test.ts | 8 ++++---- e2e/wasm/deno.json | 14 +++++++------- languages/typescript/packages/bench/README.md | 2 +- .../cli/src/__tests__/release-train.test.ts | 2 +- .../cli/src/__tests__/skill-supabase-apply.test.ts | 2 +- .../cli/src/commands/init/lib/bundled-paths.ts | 7 ++++--- .../typescript/packages/cli/tsconfig.scaffold.json | 2 +- languages/typescript/packages/cli/tsup.config.ts | 4 ++-- .../protect-ffi/crates/protect-ffi/Cargo.toml | 2 +- .../protect-ffi/src/integrationSuiteCi.test.ts | 4 ++-- .../packages/protect-ffi/src/lintWiring.test.ts | 4 ++-- .../packages/protect-ffi/src/nativeLoading.test.ts | 5 ++++- .../stack-drizzle/integration/vitest.config.ts | 2 +- .../packages/stack-drizzle/vitest.config.ts | 2 +- .../stack-prisma/integration/vitest.config.ts | 2 +- .../test/v3/stale-vendored-space.test.ts | 10 ++++++++-- .../stack-supabase/integration/vitest.config.ts | 2 +- .../packages/stack-supabase/vitest.config.ts | 2 +- .../eql-v3-capability-matrix-skill.test.ts | 2 +- .../packages/stack/__tests__/readme-sync.test.ts | 2 +- .../packages/stack/integration/vitest.config.ts | 2 +- languages/typescript/packages/stack/package.json | 2 +- .../typescript/packages/stack/vitest.config.ts | 2 +- .../typescript/packages/test-kit/src/install.ts | 5 ++++- .../typescript/packages/wizard/tsup.config.ts | 4 ++-- scripts/__tests__/cli-live-postgres-ci.test.mjs | 2 +- scripts/__tests__/cli-vitest-alias.test.mjs | 2 +- scripts/__tests__/ffi-binding-action.test.mjs | 2 +- .../wasm-build-inputs-paths-filter.test.mjs | 2 +- scripts/__tests__/wasm-core-contract-ci.test.mjs | 8 ++++---- scripts/lint-no-eql-registry-pins.mjs | 2 +- scripts/sync-lockstep-versions.mjs | 2 +- 41 files changed, 82 insertions(+), 69 deletions(-) diff --git a/.github/actions/build-ffi-binding/action.yml b/.github/actions/build-ffi-binding/action.yml index 02e3be6d3..ba7bca9e2 100644 --- a/.github/actions/build-ffi-binding/action.yml +++ b/.github/actions/build-ffi-binding/action.yml @@ -56,7 +56,7 @@ runs: # the build step below and the job proceeds on a stale index.node. # # The last two are NOT in this package. `crates/protect-ffi/Cargo.toml` - # carries `eql-bindings = { path = "../../../eql/crates/eql-bindings" }` + # carries `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }` # — an in-tree path dependency that compiles into `index.node` and into # the wasm build below. A path dep has no registry checksum, so a # source-only edit there moves NOTHING this key would otherwise hash: diff --git a/.github/workflows/integration-drizzle.yml b/.github/workflows/integration-drizzle.yml index 02a726790..aa51eeba0 100644 --- a/.github/workflows/integration-drizzle.yml +++ b/.github/workflows/integration-drizzle.yml @@ -89,7 +89,7 @@ on: - 'languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs' # Out of that package, and compiled into the same two artifacts: the # cdylib crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into `index.node` and into # `protect_ffi_inline.js`. Both cache keys in # `.github/actions/build-ffi-binding` hash them, so an edit here misses @@ -174,7 +174,7 @@ on: - 'languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs' # Out of that package, and compiled into the same two artifacts: the # cdylib crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into `index.node` and into # `protect_ffi_inline.js`. Both cache keys in # `.github/actions/build-ffi-binding` hash them, so an edit here misses diff --git a/.github/workflows/integration-prisma-next.yml b/.github/workflows/integration-prisma-next.yml index 8ad8faf9c..2a63c86d5 100644 --- a/.github/workflows/integration-prisma-next.yml +++ b/.github/workflows/integration-prisma-next.yml @@ -51,7 +51,7 @@ on: - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into the `index.node` this job encrypts # through. The native cache key in `.github/actions/build-ffi-binding` # hashes both, so an edit here misses that cache and the binding gets @@ -98,7 +98,7 @@ on: - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into the `index.node` this job encrypts # through. The native cache key in `.github/actions/build-ffi-binding` # hashes both, so an edit here misses that cache and the binding gets diff --git a/.github/workflows/integration-protect-ffi.yml b/.github/workflows/integration-protect-ffi.yml index 05cea407b..38fbf73f4 100644 --- a/.github/workflows/integration-protect-ffi.yml +++ b/.github/workflows/integration-protect-ffi.yml @@ -78,7 +78,7 @@ on: - 'languages/typescript/packages/protect-ffi/package.json' - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of this package, and a real compile input: the cdylib crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into `index.node` AND into the wasm32 build # this suite's `wasm-round-trip` test loads. Both cache keys in # `.github/actions/build-ffi-binding` hash these, so an edit misses the @@ -108,7 +108,7 @@ on: - 'languages/typescript/packages/protect-ffi/package.json' - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of this package, and a real compile input: the cdylib crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into `index.node` AND into the wasm32 build # this suite's `wasm-round-trip` test loads. Both cache keys in # `.github/actions/build-ffi-binding` hash these, so an edit misses the diff --git a/.github/workflows/integration-supabase.yml b/.github/workflows/integration-supabase.yml index d1a2a3b65..6da214867 100644 --- a/.github/workflows/integration-supabase.yml +++ b/.github/workflows/integration-supabase.yml @@ -69,7 +69,7 @@ on: - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into the `index.node` this job encrypts # through. The native cache key in `.github/actions/build-ffi-binding` # hashes both, so an edit here misses that cache and the binding gets @@ -139,7 +139,7 @@ on: - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into the `index.node` this job encrypts # through. The native cache key in `.github/actions/build-ffi-binding` # hashes both, so an edit here misses that cache and the binding gets diff --git a/.github/workflows/prisma-example-readme-e2e.yml b/.github/workflows/prisma-example-readme-e2e.yml index f46a9d67b..e19b2e4af 100644 --- a/.github/workflows/prisma-example-readme-e2e.yml +++ b/.github/workflows/prisma-example-readme-e2e.yml @@ -34,7 +34,7 @@ on: - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into the `index.node` this job encrypts # through. The native cache key in `.github/actions/build-ffi-binding` # hashes both, so an edit here misses that cache and the binding gets @@ -66,7 +66,7 @@ on: - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into the `index.node` this job encrypts # through. The native cache key in `.github/actions/build-ffi-binding` # hashes both, so an edit here misses that cache and the binding gets diff --git a/.github/workflows/prisma-next-e2e.yml b/.github/workflows/prisma-next-e2e.yml index 23061ae7b..bb34df723 100644 --- a/.github/workflows/prisma-next-e2e.yml +++ b/.github/workflows/prisma-next-e2e.yml @@ -33,7 +33,7 @@ on: - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into the `index.node` this job encrypts # through. The native cache key in `.github/actions/build-ffi-binding` # hashes both, so an edit here misses that cache and the binding gets @@ -66,7 +66,7 @@ on: - 'languages/typescript/packages/protect-ffi/mise.toml' # Out of that package, and a compile input all the same: the cdylib # crate carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so the + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the # EQL wire types are linked into the `index.node` this job encrypts # through. The native cache key in `.github/actions/build-ffi-binding` # hashes both, so an edit here misses that cache and the binding gets diff --git a/.github/workflows/tests-rust.yml b/.github/workflows/tests-rust.yml index b3e0961c9..a41510043 100644 --- a/.github/workflows/tests-rust.yml +++ b/.github/workflows/tests-rust.yml @@ -23,7 +23,7 @@ on: - 'languages/typescript/packages/protect-ffi/package.json' # Out of that package, and compiled by every check below all the same: # `crates/protect-ffi/Cargo.toml` carries - # `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so + # `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so # `cargo test`, `cargo fmt --check` and both clippy passes build that # tree. A change there can break this job in a PR touching no file under # languages/typescript/packages/protect-ffi at all. The workspace root manifest comes with it: diff --git a/e2e/tests/package-managers.e2e.test.ts b/e2e/tests/package-managers.e2e.test.ts index 5c72e810d..55f286c86 100644 --- a/e2e/tests/package-managers.e2e.test.ts +++ b/e2e/tests/package-managers.e2e.test.ts @@ -5,10 +5,10 @@ import { dirname, join, resolve } from 'node:path' import { fileURLToPath } from 'node:url' import { afterEach, beforeAll, beforeEach, describe, expect, it } from 'vitest' -import { createBaseProvider } from '../../packages/cli/src/commands/init/providers/base.js' -import { createDrizzleProvider } from '../../packages/cli/src/commands/init/providers/drizzle.js' -import { createSupabaseProvider } from '../../packages/cli/src/commands/init/providers/supabase.js' -import type { PackageManager } from '../../packages/cli/src/commands/init/utils.js' +import { createBaseProvider } from '../../languages/typescript/packages/cli/src/commands/init/providers/base.js' +import { createDrizzleProvider } from '../../languages/typescript/packages/cli/src/commands/init/providers/drizzle.js' +import { createSupabaseProvider } from '../../languages/typescript/packages/cli/src/commands/init/providers/supabase.js' +import type { PackageManager } from '../../languages/typescript/packages/cli/src/commands/init/utils.js' const __dirname = dirname(fileURLToPath(import.meta.url)) const REPO_ROOT = resolve(__dirname, '../..') diff --git a/e2e/tests/skill-map-parity.e2e.test.ts b/e2e/tests/skill-map-parity.e2e.test.ts index 3766a48d1..9e804cdb8 100644 --- a/e2e/tests/skill-map-parity.e2e.test.ts +++ b/e2e/tests/skill-map-parity.e2e.test.ts @@ -20,10 +20,10 @@ import { describe, expect, it } from 'vitest' -import { SKILL_MAP as CLI_SKILL_MAP } from '../../packages/cli/src/commands/init/lib/install-skills.js' -import type { Integration as CliIntegration } from '../../packages/cli/src/commands/init/types.js' -import { SKILL_MAP as WIZARD_SKILL_MAP } from '../../packages/wizard/src/lib/install-skills.js' -import type { Integration as WizardIntegration } from '../../packages/wizard/src/lib/types.js' +import { SKILL_MAP as CLI_SKILL_MAP } from '../../languages/typescript/packages/cli/src/commands/init/lib/install-skills.js' +import type { Integration as CliIntegration } from '../../languages/typescript/packages/cli/src/commands/init/types.js' +import { SKILL_MAP as WIZARD_SKILL_MAP } from '../../languages/typescript/packages/wizard/src/lib/install-skills.js' +import type { Integration as WizardIntegration } from '../../languages/typescript/packages/wizard/src/lib/types.js' // Exhaustive over the wizard union: a new wizard integration added without a // CLI counterpart fails to compile here, rather than shipping a divergent set. diff --git a/e2e/wasm/deno.json b/e2e/wasm/deno.json index 262d51fcc..a3d9ba33c 100644 --- a/e2e/wasm/deno.json +++ b/e2e/wasm/deno.json @@ -9,12 +9,12 @@ "test": "deno test --no-check --allow-env --allow-net --allow-read --allow-sys --no-prompt" }, "imports": { - "@cipherstash/stack/wasm-inline": "../../packages/stack/dist/wasm-inline.js", - "@cipherstash/stack-supabase/wasm-inline": "../../packages/stack-supabase/dist/wasm-inline.js", - "@cipherstash/stack/adapter-kit": "../../packages/stack/dist/adapter-kit.js", - "@cipherstash/stack/eql/v3": "../../packages/stack/dist/eql/v3/index.js", - "@cipherstash/stack/errors": "../../packages/stack/dist/errors/index.js", - "@cipherstash/protect-ffi/wasm-inline": "../../packages/stack/node_modules/@cipherstash/protect-ffi/dist/wasm/protect_ffi_inline.js", - "@cipherstash/auth/wasm-inline": "../../packages/stack/node_modules/@cipherstash/auth/wasm-inline.mjs" + "@cipherstash/stack/wasm-inline": "../../languages/typescript/packages/stack/dist/wasm-inline.js", + "@cipherstash/stack-supabase/wasm-inline": "../../languages/typescript/packages/stack-supabase/dist/wasm-inline.js", + "@cipherstash/stack/adapter-kit": "../../languages/typescript/packages/stack/dist/adapter-kit.js", + "@cipherstash/stack/eql/v3": "../../languages/typescript/packages/stack/dist/eql/v3/index.js", + "@cipherstash/stack/errors": "../../languages/typescript/packages/stack/dist/errors/index.js", + "@cipherstash/protect-ffi/wasm-inline": "../../languages/typescript/packages/stack/node_modules/@cipherstash/protect-ffi/dist/wasm/protect_ffi_inline.js", + "@cipherstash/auth/wasm-inline": "../../languages/typescript/packages/stack/node_modules/@cipherstash/auth/wasm-inline.mjs" } } diff --git a/languages/typescript/packages/bench/README.md b/languages/typescript/packages/bench/README.md index cd5409815..0ec277625 100644 --- a/languages/typescript/packages/bench/README.md +++ b/languages/typescript/packages/bench/README.md @@ -16,7 +16,7 @@ It runs in two layers: - Local Postgres + EQL via the repo-root `local/docker-compose.yml`: ```bash - cd ../../local && docker compose up -d + cd ../../../../local && docker compose up -d ``` - A CipherStash profile signed in (`stash login`). Auth is read from the CipherStash profile; no environment variables required. diff --git a/languages/typescript/packages/cli/src/__tests__/release-train.test.ts b/languages/typescript/packages/cli/src/__tests__/release-train.test.ts index 800b7d0dd..b07e56940 100644 --- a/languages/typescript/packages/cli/src/__tests__/release-train.test.ts +++ b/languages/typescript/packages/cli/src/__tests__/release-train.test.ts @@ -9,7 +9,7 @@ import { } from '../release-train.js' const CLI_ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '../..') -const REPO_ROOT = resolve(CLI_ROOT, '../..') +const REPO_ROOT = resolve(CLI_ROOT, '../../../..') const SKILLS_ROOT = resolve(REPO_ROOT, 'skills') /** The stable version a workspace manifest belongs to: `1.0.0-rc.4` → `1.0.0`. */ diff --git a/languages/typescript/packages/cli/src/__tests__/skill-supabase-apply.test.ts b/languages/typescript/packages/cli/src/__tests__/skill-supabase-apply.test.ts index 7883340ab..1df593bb9 100644 --- a/languages/typescript/packages/cli/src/__tests__/skill-supabase-apply.test.ts +++ b/languages/typescript/packages/cli/src/__tests__/skill-supabase-apply.test.ts @@ -4,7 +4,7 @@ import { fileURLToPath } from 'node:url' import { describe, expect, it } from 'vitest' const CLI_ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '../..') -const REPO_ROOT = resolve(CLI_ROOT, '../..') +const REPO_ROOT = resolve(CLI_ROOT, '../../../..') const SKILLS_ROOT = resolve(REPO_ROOT, 'skills') /** diff --git a/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts b/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts index 68a6af7a5..9b7ab71f3 100644 --- a/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts +++ b/languages/typescript/packages/cli/src/commands/init/lib/bundled-paths.ts @@ -27,9 +27,10 @@ export function findBundledDir(name: string): string | undefined { join(here, '..', '..', name), join(here, '..', '..', '..', name), join(here, '..', '..', '..', '..', name), - // Dev fallback: running from `languages/typescript/packages/cli/src/commands/init/lib/`, - // the monorepo `/` is six levels up. - join(here, '..', '..', '..', '..', '..', '..', name), + // Dev fallback: running from + // `languages/typescript/packages/cli/src/commands/init/lib/`, the + // monorepo `/` is eight levels up. + join(here, '..', '..', '..', '..', '..', '..', '..', '..', name), ] for (const candidate of candidates) { if (existsSync(candidate)) { diff --git a/languages/typescript/packages/cli/tsconfig.scaffold.json b/languages/typescript/packages/cli/tsconfig.scaffold.json index 226889b1d..d53fcf43a 100644 --- a/languages/typescript/packages/cli/tsconfig.scaffold.json +++ b/languages/typescript/packages/cli/tsconfig.scaffold.json @@ -11,7 +11,7 @@ // // Deliberately scoped to the fixtures so it gates the scaffold without // waiting on the rest of the package to compile. - "extends": "../../tsconfig.json", + "extends": "../../../../tsconfig.json", "compilerOptions": { "noEmit": true, "module": "ESNext", diff --git a/languages/typescript/packages/cli/tsup.config.ts b/languages/typescript/packages/cli/tsup.config.ts index da02e4120..0cc9c98d4 100644 --- a/languages/typescript/packages/cli/tsup.config.ts +++ b/languages/typescript/packages/cli/tsup.config.ts @@ -83,8 +83,8 @@ export default defineConfig([ // `stash init` can copy them into the user's `.claude/skills/` or // `.codex/skills/` directory at handoff time. Mirror of // languages/typescript/packages/wizard/tsup.config.ts:24. - if (existsSync('../../skills')) { - cpSync('../../skills', 'dist/skills', { recursive: true }) + if (existsSync('../../../../skills')) { + cpSync('../../../../skills', 'dist/skills', { recursive: true }) } // The AGENTS.md doctrine fragment is read at handoff time and // wrapped in a sentinel block. The runtime resolver diff --git a/languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml b/languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml index b6c9f9b83..6d42d8499 100644 --- a/languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml +++ b/languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml @@ -34,7 +34,7 @@ cts-common = { version = "=0.42.3", default-features = false } # `[lints] workspace = true`, so it carries nothing to inherit), and the two # workspaces stay separate deliberately — see Phase 3 of # `docs/plans/2026-08-13-eql-monorepo-absorption.md`. -eql-bindings = { path = "../../../eql/crates/eql-bindings" } +eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" } stack-auth = { version = "=0.42.3" } hex = "0.4.3" # Carries the error code across the FFI boundary (#146). `derive` is the only diff --git a/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts b/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts index ae642742c..41af6b68e 100644 --- a/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts +++ b/languages/typescript/packages/protect-ffi/src/integrationSuiteCi.test.ts @@ -24,7 +24,7 @@ import { describe, expect, it } from 'vitest' // package. `import.meta` is unavailable: tsconfig emits CommonJS and tsc // rejects it (TS1470). Same reasoning as lintWiring.test.ts. const packageRoot = process.cwd() -const workflowDir = join(packageRoot, '../../.github/workflows') +const workflowDir = join(packageRoot, '../../../../.github/workflows') /** * `//` line comments removed, so `JSON.parse` accepts `turbo.json`. @@ -184,7 +184,7 @@ describe('integration-tests suite runs in CI', () => { ( JSON.parse( stripJsonComments( - readFileSync(join(packageRoot, '../../turbo.json'), 'utf8'), + readFileSync(join(packageRoot, '../../../../turbo.json'), 'utf8'), ), ) as { tasks?: Record } ).tasks ?? {}, diff --git a/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts b/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts index e44440759..03546ff51 100644 --- a/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts +++ b/languages/typescript/packages/protect-ffi/src/lintWiring.test.ts @@ -60,7 +60,7 @@ const withoutComments = (yaml: string) => yaml.replace(/^[ \t]*#.*$/gm, '') // package — that was true of the deposited upstream copy this used to read, // which made the CI assertion below vacuous from the day of the absorption. const testWorkflow = withoutComments( - read('../../.github/workflows/tests-rust.yml'), + read('../../../../.github/workflows/tests-rust.yml'), ) // Every root workflow an exempted script may hang off, discovered by reading // the DIRECTORY rather than by listing filenames. Same rule as above: root @@ -72,7 +72,7 @@ const testWorkflow = withoutComments( // this reads as "the script runs nowhere", and the tempting repair is to widen // the list until it includes the dead package-local path. A directory cannot // drift out of date with itself. -const ROOT_WORKFLOW_DIR = '../../.github/workflows' +const ROOT_WORKFLOW_DIR = '../../../../.github/workflows' const rootWorkflowNames = readdirSync( join(packageRoot, ROOT_WORKFLOW_DIR), ).filter((name) => name.endsWith('.yml') || name.endsWith('.yaml')) diff --git a/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts b/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts index b047c53df..08dec4e32 100644 --- a/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts +++ b/languages/typescript/packages/protect-ffi/src/nativeLoading.test.ts @@ -248,7 +248,10 @@ describe('assertNativeBindingAvailable', () => { // that mentions proving the binding loads is not a step that proves it. // Comments inside `runs:` go for the same reason. const action = readFileSync( - join(packageRoot, '../../.github/actions/build-ffi-binding/action.yml'), + join( + packageRoot, + '../../../../.github/actions/build-ffi-binding/action.yml', + ), 'utf8', ) const runsAt = action.search(/^runs:/m) diff --git a/languages/typescript/packages/stack-drizzle/integration/vitest.config.ts b/languages/typescript/packages/stack-drizzle/integration/vitest.config.ts index b5f6762dc..35cb18703 100644 --- a/languages/typescript/packages/stack-drizzle/integration/vitest.config.ts +++ b/languages/typescript/packages/stack-drizzle/integration/vitest.config.ts @@ -1,6 +1,6 @@ import { resolve } from 'node:path' import { defineConfig } from 'vitest/config' -import { sharedAlias, stackSourceAlias } from '../../../vitest.shared' +import { sharedAlias, stackSourceAlias } from '../../../../../vitest.shared' import { integrationHarness, integrationTestDefaults, diff --git a/languages/typescript/packages/stack-drizzle/vitest.config.ts b/languages/typescript/packages/stack-drizzle/vitest.config.ts index 9fed3fefd..ecc2bbcc6 100644 --- a/languages/typescript/packages/stack-drizzle/vitest.config.ts +++ b/languages/typescript/packages/stack-drizzle/vitest.config.ts @@ -1,5 +1,5 @@ import { configDefaults, defineConfig } from 'vitest/config' -import { sharedAlias, stackSourceAlias } from '../../vitest.shared' +import { sharedAlias, stackSourceAlias } from '../../../../vitest.shared' export default defineConfig({ resolve: { diff --git a/languages/typescript/packages/stack-prisma/integration/vitest.config.ts b/languages/typescript/packages/stack-prisma/integration/vitest.config.ts index c14dd8817..3d60b8f9e 100644 --- a/languages/typescript/packages/stack-prisma/integration/vitest.config.ts +++ b/languages/typescript/packages/stack-prisma/integration/vitest.config.ts @@ -1,6 +1,6 @@ import { resolve } from 'node:path' import { defineConfig } from 'vitest/config' -import { sharedAlias, stackSourceAlias } from '../../../vitest.shared' +import { sharedAlias, stackSourceAlias } from '../../../../../vitest.shared' import { integrationHarness, integrationTestDefaults, diff --git a/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts b/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts index c98c771ee..bf4513006 100644 --- a/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts +++ b/languages/typescript/packages/stack-prisma/test/v3/stale-vendored-space.test.ts @@ -657,13 +657,16 @@ describe('fresh database: both install paths must converge on eql-3.0.6', () => // driving `db init` in a repo upgraded from 1.0.0 hits this refusal with no // route out of it. Nothing type-checks either file; this assertion is the // only thing holding the pair to the planner's real message. - // `test/v3` -> `test` -> `languages/typescript/packages/stack-prisma` -> `packages` -> root. + // `test/v3` -> `test` -> `stack-prisma` -> `packages` -> `typescript` + // -> `languages` -> root. const repoRoot = join( dirname(fileURLToPath(import.meta.url)), '..', '..', '..', '..', + '..', + '..', ) const shipped = { 'languages/typescript/packages/stack-prisma/README.md': await readFile( @@ -780,13 +783,16 @@ describe('no seed phase run: the 3.0.5 / 3.0.6 upgrades are silently invisible', * reaches the repo root to hold shipped docs to a fact. */ describe('shipped skills: claims verified false, which must not come back', () => { - // `test/v3` -> `test` -> `languages/typescript/packages/stack-prisma` -> `packages` -> root. + // `test/v3` -> `test` -> `stack-prisma` -> `packages` -> `typescript` + // -> `languages` -> root. const repoRoot = join( dirname(fileURLToPath(import.meta.url)), '..', '..', '..', '..', + '..', + '..', ) const skillsDir = join(repoRoot, 'skills') diff --git a/languages/typescript/packages/stack-supabase/integration/vitest.config.ts b/languages/typescript/packages/stack-supabase/integration/vitest.config.ts index 4dc30e9c2..defc30a73 100644 --- a/languages/typescript/packages/stack-supabase/integration/vitest.config.ts +++ b/languages/typescript/packages/stack-supabase/integration/vitest.config.ts @@ -1,6 +1,6 @@ import { resolve } from 'node:path' import { defineConfig } from 'vitest/config' -import { sharedAlias, stackSourceAlias } from '../../../vitest.shared' +import { sharedAlias, stackSourceAlias } from '../../../../../vitest.shared' import { integrationHarness, integrationTestDefaults, diff --git a/languages/typescript/packages/stack-supabase/vitest.config.ts b/languages/typescript/packages/stack-supabase/vitest.config.ts index 9931d316c..bfd2fc75b 100644 --- a/languages/typescript/packages/stack-supabase/vitest.config.ts +++ b/languages/typescript/packages/stack-supabase/vitest.config.ts @@ -1,5 +1,5 @@ import { configDefaults, defineConfig } from 'vitest/config' -import { sharedAlias, stackSourceAlias } from '../../vitest.shared' +import { sharedAlias, stackSourceAlias } from '../../../../vitest.shared' export default defineConfig({ resolve: { diff --git a/languages/typescript/packages/stack/__tests__/eql-v3-capability-matrix-skill.test.ts b/languages/typescript/packages/stack/__tests__/eql-v3-capability-matrix-skill.test.ts index f436159a7..2de6f8540 100644 --- a/languages/typescript/packages/stack/__tests__/eql-v3-capability-matrix-skill.test.ts +++ b/languages/typescript/packages/stack/__tests__/eql-v3-capability-matrix-skill.test.ts @@ -28,7 +28,7 @@ import { types } from '@/eql/v3' const SKILL = resolve( dirname(fileURLToPath(import.meta.url)), - '../../../skills/stash-encryption/SKILL.md', + '../../../../../skills/stash-encryption/SKILL.md', ) /** Only the matrix, so an example elsewhere in the file cannot satisfy a row. */ diff --git a/languages/typescript/packages/stack/__tests__/readme-sync.test.ts b/languages/typescript/packages/stack/__tests__/readme-sync.test.ts index 0eb716eb8..eff4fd600 100644 --- a/languages/typescript/packages/stack/__tests__/readme-sync.test.ts +++ b/languages/typescript/packages/stack/__tests__/readme-sync.test.ts @@ -20,7 +20,7 @@ describe('package README', () => { 'utf8', ) const rootReadme = readFileSync( - fileURLToPath(new URL('../../../README.md', import.meta.url)), + fileURLToPath(new URL('../../../../../README.md', import.meta.url)), 'utf8', ) expect( diff --git a/languages/typescript/packages/stack/integration/vitest.config.ts b/languages/typescript/packages/stack/integration/vitest.config.ts index 255a8803f..335653090 100644 --- a/languages/typescript/packages/stack/integration/vitest.config.ts +++ b/languages/typescript/packages/stack/integration/vitest.config.ts @@ -1,7 +1,7 @@ import { existsSync } from 'node:fs' import { resolve } from 'node:path' import { defineConfig } from 'vitest/config' -import { sharedAlias, stackSourceAlias } from '../../../vitest.shared' +import { sharedAlias, stackSourceAlias } from '../../../../../vitest.shared' import { integrationHarness, integrationTestDefaults, diff --git a/languages/typescript/packages/stack/package.json b/languages/typescript/packages/stack/package.json index 9e1febef4..36e581c4c 100644 --- a/languages/typescript/packages/stack/package.json +++ b/languages/typescript/packages/stack/package.json @@ -191,7 +191,7 @@ "./package.json": "./package.json" }, "scripts": { - "prebuild": "node -e \"const fs=require('node:fs');fs.rmSync('dist',{recursive:true,force:true});fs.copyFileSync('../../README.md','README.md')\"", + "prebuild": "node -e \"const fs=require('node:fs');fs.rmSync('dist',{recursive:true,force:true});fs.copyFileSync('../../../../README.md','README.md')\"", "build": "tsup", "dev": "tsup --watch", "analyze:complexity": "fta src/eql/v3 --score-cap 69", diff --git a/languages/typescript/packages/stack/vitest.config.ts b/languages/typescript/packages/stack/vitest.config.ts index d78023872..ce1ef56b4 100644 --- a/languages/typescript/packages/stack/vitest.config.ts +++ b/languages/typescript/packages/stack/vitest.config.ts @@ -1,5 +1,5 @@ import { configDefaults, defineConfig } from 'vitest/config' -import { sharedAlias, stackSourceAlias } from '../../vitest.shared' +import { sharedAlias, stackSourceAlias } from '../../../../vitest.shared' import { WASM_CORE_SUITE } from './vitest.wasm-core.config' export default defineConfig({ diff --git a/languages/typescript/packages/test-kit/src/install.ts b/languages/typescript/packages/test-kit/src/install.ts index abd2fdc5a..4ac727aee 100644 --- a/languages/typescript/packages/test-kit/src/install.ts +++ b/languages/typescript/packages/test-kit/src/install.ts @@ -7,7 +7,10 @@ import { promisify } from 'node:util' const execFileAsync = promisify(execFile) /** `languages/typescript/packages/test-kit/src` → repo root. */ -const REPO_ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '../../..') +const REPO_ROOT = resolve( + dirname(fileURLToPath(import.meta.url)), + '../../../../..', +) const STASH_BIN = resolve( REPO_ROOT, 'languages/typescript/packages/cli/dist/bin/stash.js', diff --git a/languages/typescript/packages/wizard/tsup.config.ts b/languages/typescript/packages/wizard/tsup.config.ts index 041ddb9fc..e92bb7381 100644 --- a/languages/typescript/packages/wizard/tsup.config.ts +++ b/languages/typescript/packages/wizard/tsup.config.ts @@ -21,8 +21,8 @@ var require = __createRequire(import.meta.url);`, // the agent can install them into the user's `.claude/skills` directory // (CIP-2992). The cli used to ship these too — they belong with the // wizard now. - if (existsSync('../../skills')) { - cpSync('../../skills', 'dist/skills', { recursive: true }) + if (existsSync('../../../../skills')) { + cpSync('../../../../skills', 'dist/skills', { recursive: true }) } }, }) diff --git a/scripts/__tests__/cli-live-postgres-ci.test.mjs b/scripts/__tests__/cli-live-postgres-ci.test.mjs index 75d1e164c..5819eaee8 100644 --- a/scripts/__tests__/cli-live-postgres-ci.test.mjs +++ b/scripts/__tests__/cli-live-postgres-ci.test.mjs @@ -40,7 +40,7 @@ describe('CLI live-Postgres CI contract', () => { it('serializes live suites that share the EQL schemas', async () => { const config = await import( - '../../packages/cli/vitest.config.ts?cli-live-ci-contract' + '../../languages/typescript/packages/cli/vitest.config.ts?cli-live-ci-contract' ) const live = config.default.test.projects.find( (project) => project.test.name === 'live', diff --git a/scripts/__tests__/cli-vitest-alias.test.mjs b/scripts/__tests__/cli-vitest-alias.test.mjs index a144d63bd..e892615e0 100644 --- a/scripts/__tests__/cli-vitest-alias.test.mjs +++ b/scripts/__tests__/cli-vitest-alias.test.mjs @@ -1,6 +1,6 @@ import { existsSync } from 'node:fs' import { describe, expect, it } from 'vitest' -import cliVitestConfig from '../../packages/cli/vitest.config.ts' +import cliVitestConfig from '../../languages/typescript/packages/cli/vitest.config.ts' /** * `languages/typescript/packages/cli/vitest.config.ts` carries its own alias map, outside the one diff --git a/scripts/__tests__/ffi-binding-action.test.mjs b/scripts/__tests__/ffi-binding-action.test.mjs index b311f872f..09aba0b0d 100644 --- a/scripts/__tests__/ffi-binding-action.test.mjs +++ b/scripts/__tests__/ffi-binding-action.test.mjs @@ -363,7 +363,7 @@ describe('build-ffi-binding — the WASM key covers the build it skips', () => { * Both of those reason about files inside `languages/typescript/packages/protect-ffi`. Cargo does * not. `crates/protect-ffi/Cargo.toml` carries * - * eql-bindings = { path = "../../../eql/crates/eql-bindings" } + * eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" } * * — an in-tree path dependency in a DIFFERENT package, and a genuine compile * input to both `index.node` and the wasm32 build. A path dep carries no diff --git a/scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs b/scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs index 5c986964c..c7917e452 100644 --- a/scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs +++ b/scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs @@ -32,7 +32,7 @@ import { readWorkflow, workflowFiles } from './lib/workflows.mjs' * emits. Reported in review on #863; this file was written for it. * - `packages/eql/crates/**` and `packages/eql/Cargo.toml` are in BOTH keys — * `crates/protect-ffi/Cargo.toml` carries - * `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`, so that + * `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so that * tree compiles into `index.node` — and five path-filtered workflows that * build or compile the binding did not list them. Four of them run the * action NATIVELY (`wasm:` left at its default), so the first version of diff --git a/scripts/__tests__/wasm-core-contract-ci.test.mjs b/scripts/__tests__/wasm-core-contract-ci.test.mjs index e95d6ecac..d60f538ba 100644 --- a/scripts/__tests__/wasm-core-contract-ci.test.mjs +++ b/scripts/__tests__/wasm-core-contract-ci.test.mjs @@ -1,12 +1,12 @@ import { existsSync, readFileSync } from 'node:fs' import { join } from 'node:path' import { describe, expect, it } from 'vitest' -import stackVitestConfig from '../../packages/stack/vitest.config.ts' +import stackVitestConfig from '../../languages/typescript/packages/stack/vitest.config.ts' import wasmCoreVitestConfig, { WASM_CORE_SUITE, -} from '../../packages/stack/vitest.wasm-core.config.ts' -import supabaseVitestConfig from '../../packages/stack-supabase/vitest.config.ts' -import { requireIntegrationEnv } from '../../packages/test-kit/src/env.ts' +} from '../../languages/typescript/packages/stack/vitest.wasm-core.config.ts' +import supabaseVitestConfig from '../../languages/typescript/packages/stack-supabase/vitest.config.ts' +import { requireIntegrationEnv } from '../../languages/typescript/packages/test-kit/src/env.ts' import { readJsonc } from './lib/read-jsonc.mjs' import { REPO_ROOT } from './lib/repo-root.mjs' import { readWorkflow, workflowFiles } from './lib/workflows.mjs' diff --git a/scripts/lint-no-eql-registry-pins.mjs b/scripts/lint-no-eql-registry-pins.mjs index 8338f26ce..76e0bc9a3 100644 --- a/scripts/lint-no-eql-registry-pins.mjs +++ b/scripts/lint-no-eql-registry-pins.mjs @@ -783,7 +783,7 @@ export function report(result) { 'registry pin lets the installed SQL and the emitting Rust drift apart\n' + 'silently — it compiles, it passes CI, and it fails in a database.\n\n' + 'Resolve it in-tree instead:\n\n' + - ` ${CARGO_DEPENDENCY} = { path = "../../../eql/crates/eql-bindings" }\n` + + ` ${CARGO_DEPENDENCY} = { path = "../../../../../../packages/eql/crates/eql-bindings" }\n` + ` "${NPM_DEPENDENCY}": "workspace:*"\n\n` + '`workspace:*` and not `workspace:^`: both resolve in-tree and both\n' + 'satisfy this linter, but pnpm packs them differently into a published\n' + diff --git a/scripts/sync-lockstep-versions.mjs b/scripts/sync-lockstep-versions.mjs index 4c2dd7b31..99a3f0884 100644 --- a/scripts/sync-lockstep-versions.mjs +++ b/scripts/sync-lockstep-versions.mjs @@ -76,7 +76,7 @@ const SKIP_DIRS = new Set([ * * DISCOVERED, not listed. The crate is consumed across cargo workspace * boundaries — `languages/typescript/packages/protect-ffi/crates/protect-ffi/Cargo.toml` reaches it - * by `path = "../../../eql/crates/eql-bindings"` — and a hardcoded list is + * by `path = "../../../../../../packages/eql/crates/eql-bindings"` — and a hardcoded list is * exactly what was missing before: `packages/eql`'s own lock is refreshed as a * side effect of the SQL build below, `languages/typescript/packages/protect-ffi`'s was refreshed by * nothing, and no one noticed because no command in this repo passes From 6df068d06599e40833ec2a8541915afcf8162afb Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 09:02:42 +1000 Subject: [PATCH 4/9] test(scripts): give the repository checks the new package roots A path rewrite does not touch a package root held as a bare string, because it has no trailing slash. Two checks skip a missing root without an error, so after the move they passed while checking nothing: - lint-typecheck-scope walked `packages` and `examples`, so it checked only EQL. With a migrate tsconfig that compiles dist/, it exited 0. It now walks languages/typescript/packages and languages/typescript/examples as well, and reports the break. - lint-no-hardcoded-runners scanned only `packages`. With a bare 'npx' in stack/src it exited 0. It now scans languages/typescript/packages and packages, and reports it. Three failed loudly and needed the same change: - lint-no-dead-package-paths took its live set from packages/ alone. It now checks each reference against the root it names, so a leftover root-level path to a moved package is reported dead. Its fixtures name the new root. - lib/package-readmes.mjs selects README pathspecs from both roots. The unshipped EQL subtree root README (packages/eql/README.md) is no longer selected, because packages/* is no longer a workspace glob; the guards that use it run three fewer cases (912 to 909). - turbo-skills-inputs reads languages/typescript/packages and matches the four-level cpSync('../../../../skills'). Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- .../lint-no-dead-package-paths/dead-ref.md | 2 +- .../lint-no-dead-package-paths/globs.md | 4 +-- .../lint-no-dead-package-paths/live-refs.md | 6 ++-- .../many-dead-refs.md | 2 +- .../lint-no-dead-package-paths/prefix.md | 4 +-- .../sentence-final.md | 10 +++--- scripts/__tests__/lib/package-readmes.mjs | 15 ++++++--- .../no-removed-drizzle-surface.test.mjs | 4 +-- .../no-removed-eql-version-flag.test.mjs | 4 +-- .../__tests__/turbo-skills-inputs.test.mjs | 6 ++-- .../__tests__/wasm-core-contract-ci.test.mjs | 2 +- scripts/lint-no-dead-package-paths.mjs | 32 ++++++++++++------- scripts/lint-no-hardcoded-runners.mjs | 6 ++-- scripts/lint-typecheck-scope.mjs | 11 ++++--- 14 files changed, 63 insertions(+), 45 deletions(-) diff --git a/scripts/__tests__/fixtures/lint-no-dead-package-paths/dead-ref.md b/scripts/__tests__/fixtures/lint-no-dead-package-paths/dead-ref.md index 4863381c2..296db761a 100644 --- a/scripts/__tests__/fixtures/lint-no-dead-package-paths/dead-ref.md +++ b/scripts/__tests__/fixtures/lint-no-dead-package-paths/dead-ref.md @@ -1,4 +1,4 @@ # Dead reference - `packages/protect/src/ffi/*` mirrors this flow under the older name. -- `packages/stack` is fine. +- `languages/typescript/packages/stack` is fine. diff --git a/scripts/__tests__/fixtures/lint-no-dead-package-paths/globs.md b/scripts/__tests__/fixtures/lint-no-dead-package-paths/globs.md index 809fcbf07..d236c8f77 100644 --- a/scripts/__tests__/fixtures/lint-no-dead-package-paths/globs.md +++ b/scripts/__tests__/fixtures/lint-no-dead-package-paths/globs.md @@ -1,2 +1,2 @@ -Build everything with `turbo build --filter './packages/*'`. -The workspace glob is `packages/*`. +Build everything with `turbo build --filter './languages/typescript/packages/*'`. +The workspace glob is `languages/typescript/packages/*`. diff --git a/scripts/__tests__/fixtures/lint-no-dead-package-paths/live-refs.md b/scripts/__tests__/fixtures/lint-no-dead-package-paths/live-refs.md index f6ea4400f..d98426c7b 100644 --- a/scripts/__tests__/fixtures/lint-no-dead-package-paths/live-refs.md +++ b/scripts/__tests__/fixtures/lint-no-dead-package-paths/live-refs.md @@ -1,5 +1,5 @@ # Live references -- `packages/stack/src/encryption/index.ts` is the client. -- `packages/cli` owns the `stash` binary; see `./packages/cli/AGENTS.md`. -- `packages/stack-drizzle` and `packages/stack-supabase` are the split adapters. +- `languages/typescript/packages/stack/src/encryption/index.ts` is the client. +- `languages/typescript/packages/cli` owns the `stash` binary; see `./languages/typescript/packages/cli/AGENTS.md`. +- `languages/typescript/packages/stack-drizzle` and `languages/typescript/packages/stack-supabase` are the split adapters. diff --git a/scripts/__tests__/fixtures/lint-no-dead-package-paths/many-dead-refs.md b/scripts/__tests__/fixtures/lint-no-dead-package-paths/many-dead-refs.md index f3c075aad..d6d82facd 100644 --- a/scripts/__tests__/fixtures/lint-no-dead-package-paths/many-dead-refs.md +++ b/scripts/__tests__/fixtures/lint-no-dead-package-paths/many-dead-refs.md @@ -1,4 +1,4 @@ - packages/protect - packages/schema - packages/protect-dynamodb -- packages/stack +- languages/typescript/packages/stack diff --git a/scripts/__tests__/fixtures/lint-no-dead-package-paths/prefix.md b/scripts/__tests__/fixtures/lint-no-dead-package-paths/prefix.md index 6c9aa347d..16cc11661 100644 --- a/scripts/__tests__/fixtures/lint-no-dead-package-paths/prefix.md +++ b/scripts/__tests__/fixtures/lint-no-dead-package-paths/prefix.md @@ -1,3 +1,3 @@ -- `packages/stack-drizzle` exists. +- `languages/typescript/packages/stack-drizzle` exists. - `packages/stack-forge` does not. -- `packages/stack` exists. +- `languages/typescript/packages/stack` exists. diff --git a/scripts/__tests__/fixtures/lint-no-dead-package-paths/sentence-final.md b/scripts/__tests__/fixtures/lint-no-dead-package-paths/sentence-final.md index 7ae81cfb4..f5b406e2f 100644 --- a/scripts/__tests__/fixtures/lint-no-dead-package-paths/sentence-final.md +++ b/scripts/__tests__/fixtures/lint-no-dead-package-paths/sentence-final.md @@ -1,7 +1,7 @@ # Sentence-final package paths -The client lives in packages/stack. -A hyphen at a wrap: packages/migrate- -An underscore: packages/wizard_ -An ellipsis: packages/cli... -Parenthesised (packages/stack) and comma'd packages/cli, both fine. +The client lives in languages/typescript/packages/stack. +A hyphen at a wrap: languages/typescript/packages/migrate- +An underscore: languages/typescript/packages/wizard_ +An ellipsis: languages/typescript/packages/cli... +Parenthesised (languages/typescript/packages/stack) and comma'd languages/typescript/packages/cli, both fine. diff --git a/scripts/__tests__/lib/package-readmes.mjs b/scripts/__tests__/lib/package-readmes.mjs index a1b8a6d8c..2381be6a9 100644 --- a/scripts/__tests__/lib/package-readmes.mjs +++ b/scripts/__tests__/lib/package-readmes.mjs @@ -3,12 +3,15 @@ import { join } from 'node:path' import { workspacePackagePatterns } from '../../release-gate.mjs' import { REPO_ROOT } from './repo-root.mjs' +/** The two roots npm packages live under: EQL's subtree, and everything else. */ +const PACKAGE_ROOTS = ['packages', 'languages/typescript/packages'] + /** * git pathspecs selecting every workspace package's `README.md`. * * ## Why this is derived rather than written down * - * Both callers used to hardcode `:(glob)languages/typescript/packages/*/README.md`. `:(glob)` stops + * Both callers used to hardcode `:(glob)packages/*/README.md`. `:(glob)` stops * `*` at a path separator — which is what makes `lib/*.ts` behave — and this * repo has TWO package roots nested deeper than one level: * `languages/typescript/packages/protect-ffi/platforms/*` and `packages/eql/packages/*`. So the @@ -24,18 +27,20 @@ import { REPO_ROOT } from './repo-root.mjs' * root is covered the day it lands, rather than the day someone remembers this * file. Same reasoning, and the same parser, as `workspaceManifests()`. * - * Narrowed to `packages/` deliberately: `languages/typescript/examples/*` and `e2e` are workspace - * members too, but they are private and their READMEs are not shipped to + * Narrowed to the two package roots deliberately: + * `languages/typescript/examples/*` and `e2e` are workspace members too, but they are private and their READMEs are not shipped to * anyone. The callers are guards on SHIPPED text. */ export function packageReadmePathspecs() { const patterns = workspacePackagePatterns( readFileSync(join(REPO_ROOT, 'pnpm-workspace.yaml'), 'utf8'), - ).filter((pattern) => pattern.startsWith('packages/')) + ).filter((pattern) => + PACKAGE_ROOTS.some((root) => pattern.startsWith(`${root}/`)), + ) if (patterns.length === 0) { throw new Error( - 'pnpm-workspace.yaml lists no `packages/` patterns — either the layout moved or this derivation broke. Failing rather than returning an empty pathspec list, which `git ls-files` would answer with the whole tree.', + 'pnpm-workspace.yaml lists no `packages/` or `languages/typescript/packages/` patterns — either the layout moved or this derivation broke. Failing rather than returning an empty pathspec list, which `git ls-files` would answer with the whole tree.', ) } diff --git a/scripts/__tests__/no-removed-drizzle-surface.test.mjs b/scripts/__tests__/no-removed-drizzle-surface.test.mjs index 2b013f71e..eb89fcb1e 100644 --- a/scripts/__tests__/no-removed-drizzle-surface.test.mjs +++ b/scripts/__tests__/no-removed-drizzle-surface.test.mjs @@ -56,8 +56,8 @@ describe('removed stack-drizzle surface is absent from shipped files', () => { expect(files.length).toBeGreaterThan(5) expect(files).toContain('skills/stash-drizzle/SKILL.md') expect(files).toContain('languages/typescript/packages/stack/README.md') - // The two roots nested deeper than `languages/typescript/packages/*`. Pinned by name because - // they are what the hardcoded `:(glob)languages/typescript/packages/*/README.md` silently + // The two roots nested deeper than one level. Pinned by name because + // they are what the hardcoded `:(glob)packages/*/README.md` silently // missed: `:(glob)` does not cross `/`, so it selected the EQL subtree // ROOT's README — which ships in no tarball — instead of the package's. expect(files).toContain('packages/eql/packages/eql/README.md') diff --git a/scripts/__tests__/no-removed-eql-version-flag.test.mjs b/scripts/__tests__/no-removed-eql-version-flag.test.mjs index 5ea4c7866..e510271cf 100644 --- a/scripts/__tests__/no-removed-eql-version-flag.test.mjs +++ b/scripts/__tests__/no-removed-eql-version-flag.test.mjs @@ -80,8 +80,8 @@ describe('public eql install examples use the current CLI', () => { expect(files).toContain('skills/stash-supabase/SKILL.md') expect(files).toContain('languages/typescript/packages/stack/README.md') expect(files).toContain('docs/reference/supabase-sdk.md') - // The two roots nested deeper than `languages/typescript/packages/*`. Pinned by name because - // they are what the hardcoded `:(glob)languages/typescript/packages/*/README.md` silently + // The two roots nested deeper than one level. Pinned by name because + // they are what the hardcoded `:(glob)packages/*/README.md` silently // missed: `:(glob)` does not cross `/`, so it selected the EQL subtree // ROOT's README — which ships in no tarball — instead of the package's. expect(files).toContain('packages/eql/packages/eql/README.md') diff --git a/scripts/__tests__/turbo-skills-inputs.test.mjs b/scripts/__tests__/turbo-skills-inputs.test.mjs index 3fe0240f3..40d9582ee 100644 --- a/scripts/__tests__/turbo-skills-inputs.test.mjs +++ b/scripts/__tests__/turbo-skills-inputs.test.mjs @@ -1,7 +1,7 @@ /** * A build that copies `skills/` must declare `skills/` as an input. * - * `languages/typescript/packages/cli` and `languages/typescript/packages/wizard` both `cpSync('../../skills', + * `languages/typescript/packages/cli` and `languages/typescript/packages/wizard` both `cpSync('../../../../skills', * 'dist/skills')` — they consume a directory outside their own package, which * turbo's `$TURBO_DEFAULT$` does not cover. On its own that only meant a stale * cache entry stayed valid; once `build` declared `outputs: ["dist/**"]`, a @@ -25,7 +25,7 @@ import { REPO_ROOT } from './lib/repo-root.mjs' /** Packages whose tsup config copies the repo-root `skills/` into `dist/`. */ function packagesCopyingSkills() { - const pkgsDir = join(REPO_ROOT, 'packages') + const pkgsDir = join(REPO_ROOT, 'languages/typescript/packages') const found = [] for (const entry of readdirSync(pkgsDir, { withFileTypes: true })) { if (!entry.isDirectory()) continue @@ -33,7 +33,7 @@ function packagesCopyingSkills() { const pkgJson = join(pkgsDir, entry.name, 'package.json') if (!existsSync(tsup) || !existsSync(pkgJson)) continue if ( - !/cpSync\(\s*['"]\.\.\/\.\.\/skills['"]/.test(readFileSync(tsup, 'utf8')) + !/cpSync\(\s*['"](?:\.\.\/){4}skills['"]/.test(readFileSync(tsup, 'utf8')) ) continue found.push(JSON.parse(readFileSync(pkgJson, 'utf8')).name) diff --git a/scripts/__tests__/wasm-core-contract-ci.test.mjs b/scripts/__tests__/wasm-core-contract-ci.test.mjs index d60f538ba..bb489bdfd 100644 --- a/scripts/__tests__/wasm-core-contract-ci.test.mjs +++ b/scripts/__tests__/wasm-core-contract-ci.test.mjs @@ -307,7 +307,7 @@ describe('the `browser` export-condition guard runs everywhere (#804)', () => { expect( existsSync(join(REPO_ROOT, pkg, relative)), `${pkg}/${relative} is missing.\n` + - `That file is the only thing stopping a \`browser\` export condition being added to quiet a bundler, which would ship a workspace secret to the browser. If it moved, move this expectation with it — and keep it somewhere \`pnpm --filter ${pkg.replace('packages/', '@cipherstash/')} test\` collects.`, + `That file is the only thing stopping a \`browser\` export condition being added to quiet a bundler, which would ship a workspace secret to the browser. If it moved, move this expectation with it — and keep it somewhere \`pnpm --filter ${pkg.replace(/^.*packages\//, '@cipherstash/')} test\` collects.`, ).toBe(true) expect( diff --git a/scripts/lint-no-dead-package-paths.mjs b/scripts/lint-no-dead-package-paths.mjs index 33f0a15ea..b3112d8a3 100644 --- a/scripts/lint-no-dead-package-paths.mjs +++ b/scripts/lint-no-dead-package-paths.mjs @@ -57,7 +57,15 @@ const TEXT_EXT = /\.(md|ya?ml|json|mjs|ts|txt)$/ // is admitted so a capitalised directory name is checked rather than silently // skipped; no package uses one today, which is exactly why nothing noticed // (#772 review, finding 15). -const PACKAGE_REF = /packages\/([a-zA-Z0-9](?:[a-zA-Z0-9._-]*[a-zA-Z0-9])?)/g +// +// Packages live under two roots: `packages/` (EQL's subtree, and later the +// Rust crates) and `languages/typescript/packages/` (every other npm package). The +// optional prefix is part of the match, so a reference is checked against the +// root it names: a leftover root-level path to a package that moved under +// `languages/typescript/` is reported dead, not excused by its new home. +const PACKAGE_ROOTS = ['packages', 'languages/typescript/packages'] +const PACKAGE_REF = + /(?:languages\/typescript\/)?packages\/([a-zA-Z0-9](?:[a-zA-Z0-9._-]*[a-zA-Z0-9])?)/g // Live packages come from git, not from what is on disk. // @@ -99,7 +107,7 @@ function gitPackagePaths(...args) { const livePackages = new Set( [ - ...gitPackagePaths('ls-files', '-z', 'packages'), + ...gitPackagePaths('ls-files', '-z', ...PACKAGE_ROOTS), // Untracked but not ignored. A package scaffolded a minute ago is live // even though nothing about it is staged yet, and reporting it as "does // not exist" is the sentence-final false alarm all over again, pointed the @@ -111,18 +119,22 @@ const livePackages = new Set( '--others', '--exclude-standard', '-z', - 'packages', + ...PACKAGE_ROOTS, ), ] - .map((file) => file.split('/')[1]) + .map((file) => { + const root = PACKAGE_ROOTS.findLast((r) => file.startsWith(`${r}/`)) + const name = file.slice(root.length + 1).split('/')[0] + return name && `${root}/${name}` + }) .filter(Boolean), ) if (livePackages.size === 0) { console.error( - 'git reported no packages at all under `packages/`. Refusing to run —\n' + - 'every reference would be flagged. Check that `packages/` is present and\n' + - 'not wholly ignored.', + 'git reported no packages at all under `packages/` or\n' + + '`languages/typescript/packages/`. Refusing to run — every reference\n' + + 'would be flagged. Check that both are present and not wholly ignored.', ) process.exit(2) } @@ -181,10 +193,8 @@ for (const target of TARGETS) { lines.forEach((line, idx) => { PACKAGE_REF.lastIndex = 0 for (const m of line.matchAll(PACKAGE_REF)) { - if (livePackages.has(m[1])) continue - offenders.push( - `${shown}:${idx + 1}: \`packages/${m[1]}\` does not exist`, - ) + if (livePackages.has(m[0])) continue + offenders.push(`${shown}:${idx + 1}: \`${m[0]}\` does not exist`) } }) } diff --git a/scripts/lint-no-hardcoded-runners.mjs b/scripts/lint-no-hardcoded-runners.mjs index cf1158b38..7df67dc20 100644 --- a/scripts/lint-no-hardcoded-runners.mjs +++ b/scripts/lint-no-hardcoded-runners.mjs @@ -12,10 +12,12 @@ const ALLOWLISTED_PATHS = new Set([ 'scripts/lint-no-hardcoded-runners.mjs', // this script's own docs ]) -// Default scan root; override with argv[2] for tests. +// Default scan roots; override with argv[2] for tests. Every npm package but +// EQL lives under `languages/typescript/packages`; EQL's subtree stays under +// `packages`. const TARGETS = process.argv.slice(2).length ? process.argv.slice(2) - : ['packages'] + : ['languages/typescript/packages', 'packages'] // Catches: // - `'npx'` / `"npx"` / `` `npx `` — bare-quoted, e.g. `?? 'npx'` or `runner = 'npx'` diff --git a/scripts/lint-typecheck-scope.mjs b/scripts/lint-typecheck-scope.mjs index 25ba01352..326d5a6c0 100644 --- a/scripts/lint-typecheck-scope.mjs +++ b/scripts/lint-typecheck-scope.mjs @@ -31,12 +31,12 @@ const REPO_ROOT = resolve(import.meta.dirname, '..') // with argv[2..] for tests / ad-hoc checks (each arg is a package directory). // // NESTED roots are listed separately because the walk below is one level deep, -// matching how pnpm globs `languages/typescript/packages/*`. Three sets of packages sit a level -// further down and need their own entry here for the same reason they need one -// in `pnpm-workspace.yaml`: +// matching how pnpm globs `languages/typescript/packages/*`. Three sets of +// packages sit a level further down and need their own entry here for the same +// reason they need one in `pnpm-workspace.yaml`: // // languages/typescript/packages/protect-ffi/platforms/* the six per-platform binary packages -// packages/eql/packages/* @cipherstash/eql, from the EQL subtree +// packages/eql/packages/* @cipherstash/eql, from the EQL subtree // languages/typescript/packages/protect-ffi/* the live integration suite // // The last is spelled as its PARENT rather than as the member, because the walk @@ -50,8 +50,9 @@ const REPO_ROOT = resolve(import.meta.dirname, '..') // package.json (the private workspace manifest was deleted with the import), so // the loop skips it and only the nested member is checked. const WORKSPACE_ROOTS = [ + 'languages/typescript/packages', + 'languages/typescript/examples', 'packages', - 'examples', 'languages/typescript/packages/protect-ffi', 'languages/typescript/packages/protect-ffi/platforms', 'packages/eql/packages', From ea5cf1a9de0daca431108679e9f7922c1b194abd Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 09:04:00 +1000 Subject: [PATCH 5/9] build: keep EQL in the root test and dev filters The JavaScript root stays at the repository root; only its member paths move. - Root test and dev filter both ./languages/typescript/packages/** and ./packages/**. The second filter is what runs @cipherstash/eql#test; a filter naming only languages/typescript drops it, as the one-level ./packages/* filter once did. build stays one level deep on ./languages/typescript/packages/*, and consumers pull EQL's build through ^build. - pnpm-workspace.yaml: the comments that explained the old packages/* glob in terms of EQL no longer described the file after the rewrite. - turbo.json: the comment quoting the tsup skills copy names the new four-level path. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- package.json | 4 ++-- pnpm-workspace.yaml | 21 ++++++++++++--------- turbo.json | 2 +- 3 files changed, 15 insertions(+), 12 deletions(-) diff --git a/package.json b/package.json index 3163f4ab4..6f22b42a0 100644 --- a/package.json +++ b/package.json @@ -25,7 +25,7 @@ "changeset": "changeset", "changeset:version": "pnpm run version", "changeset:publish": "pnpm run release", - "dev": "turbo dev --filter './languages/typescript/packages/**'", + "dev": "turbo dev --filter './languages/typescript/packages/**' --filter './packages/**'", "clean": "rimraf --glob **/.next **/.turbo **/dist **/node_modules", "code:fix": "biome check --write", "code:check": "biome check", @@ -37,7 +37,7 @@ "release:gate": "node scripts/release-gate.mjs", "version": "changeset version && node scripts/sync-lockstep-versions.mjs", "release": "pnpm run build && changeset publish", - "test": "turbo test --filter './languages/typescript/packages/**'", + "test": "turbo test --filter './languages/typescript/packages/**' --filter './packages/**'", "test:e2e": "turbo run test:e2e", "test:scripts": "vitest run --config scripts/vitest.config.mjs" }, diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 9f0419a8b..07b7bc054 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -1,21 +1,24 @@ packages: + # Every npm package except EQL lives under languages/typescript/. The root + # packages/ holds EQL's subtree, and later the Rust crates. - languages/typescript/packages/* # The six per-platform binary packages for @cipherstash/protect-ffi. The - # `languages/typescript/packages/*` glob above already covers the wrapper itself; these are nested - # a level deeper and need their own entry. + # glob above already covers the wrapper itself; these are nested a level + # deeper and need their own entry. - languages/typescript/packages/protect-ffi/platforms/* # @cipherstash/eql, from the encrypt-query-language subtree. The subtree is # imported at a VERBATIM prefix so its repo-root-relative paths keep resolving # (mise tasks, Doxyfile, sync-generated.mjs), which puts the npm package two - # levels down. `languages/typescript/packages/*` matches the subtree ROOT, which carries no - # package.json by design — the private @cipherstash/eql-workspace manifest was - # deleted so this glob contributes exactly one member. + # levels down. The subtree ROOT carries no package.json by design — the + # private @cipherstash/eql-workspace manifest was deleted so the subtree + # contributes exactly one member, through this glob. - packages/eql/packages/* # The protect-ffi live integration suite. Nested a level deeper than - # `languages/typescript/packages/*` reaches, like the two entries above, and named literally - # rather than globbed because `languages/typescript/packages/protect-ffi/*` would also select - # `crates/`, `docs/`, `lib/`, `scripts/` and `src/` — directories with no - # package.json, which pnpm rejects rather than skips. + # `languages/typescript/packages/*` reaches, like the platform entry above, + # and named literally rather than globbed because + # `languages/typescript/packages/protect-ffi/*` would also select `crates/`, + # `docs/`, `lib/`, `scripts/` and `src/` — directories with no package.json, + # which pnpm rejects rather than skips. # # It kept its own `package-lock.json` and installed with `npm ci` until # CIP-3744. That was the last registry pin of `@cipherstash/eql` in the tree: diff --git a/turbo.json b/turbo.json index a16e2ed75..ce949b44a 100644 --- a/turbo.json +++ b/turbo.json @@ -37,7 +37,7 @@ "dependsOn": ["^build"], "outputs": ["lib/**"] }, - // These two builds `cpSync('../../skills', 'dist/skills')` — they consume a + // These two builds `cpSync('../../../../skills', 'dist/skills')` — they consume a // directory OUTSIDE their own package, which `$TURBO_DEFAULT$` does not // cover. Without naming it here a skills-only edit does not invalidate the // build, and since `build` now declares `outputs: ["dist/**"]`, the cache From 1b18f0fba8ae7015e51d35fe9da0baf50cef4ca8 Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 09:04:21 +1000 Subject: [PATCH 6/9] docs: describe the languages/typescript layout in the current docs AGENTS.md gains a layout paragraph, and its notes on the root test filter name both package roots, since a filter naming only languages/typescript drops @cipherstash/eql#test. CONTRIBUTING.md, SECURITY.md, e2e/README.md and docs/query-api-walkthrough.md name examples/ and packages/ in prose the rewrite could not see, because the path ends at a backtick. Left alone on purpose: docs/plans/, docs/superpowers/, CHANGELOG.md files and pending changesets. They record history, and lint-no-dead-package-paths already exempts them for that reason. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- AGENTS.md | 27 +++++++++++++++++---------- CONTRIBUTING.md | 6 +++--- SECURITY.md | 2 +- docs/query-api-walkthrough.md | 2 +- e2e/README.md | 2 +- 5 files changed, 23 insertions(+), 16 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 2f918b550..68acaf158 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -71,6 +71,8 @@ If these variables are missing, tests that require live encryption will fail or ## Repository Layout +Every npm package except EQL lives under `languages/typescript/`: packages in `languages/typescript/packages/`, example apps in `languages/typescript/examples/`. The root `packages/` holds EQL's subtree (and, later, Rust crates). The JavaScript root stays at the repository root: `package.json`, `pnpm-lock.yaml`, `pnpm-workspace.yaml`, `turbo.json`, `.changeset/`, `biome.json`, `tsconfig.json` and `vitest.shared.ts`. + - `languages/typescript/packages/stack`: Main package (`@cipherstash/stack`) containing the encryption client and all integrations - Subpath exports: `@cipherstash/stack`, `@cipherstash/stack/identity`, `@cipherstash/stack/schema`, `@cipherstash/stack/eql/v3`, `@cipherstash/stack/v3`, `@cipherstash/stack/types`, `@cipherstash/stack/dynamodb`, `@cipherstash/stack/encryption`, `@cipherstash/stack/errors`, `@cipherstash/stack/adapter-kit`, `@cipherstash/stack/wasm-inline`, `@cipherstash/stack/diagnostics` (the Drizzle and Supabase integrations moved to their own packages — see below) - `languages/typescript/packages/cli`: The `stash` CLI — auth, init, encryption schema, and database setup (`stash eql install`). Has its own `AGENTS.md`. @@ -100,7 +102,8 @@ other is `packages/eql/crates`), and its scripts are split so a Rust toolchain stays optional for everyone else. - **The default `test` and `build` never invoke cargo.** Root `pnpm test` runs - `turbo test --filter './languages/typescript/packages/**'`, which reaches this package — so a cargo + `turbo test --filter './languages/typescript/packages/**' --filter + './packages/**'`, which reaches this package — so a cargo process on that path is a Rust toolchain on every contributor's machine. `test` is the JS chain; `build` is `tsc`. - **CI does build the binding, in the jobs that need it.** That is the limit of @@ -228,7 +231,8 @@ EQL versions installed** in the database. EMITS it — and it would have disagreed in a database, not in CI. The cost of membership: root `pnpm test` is `turbo test --filter - './languages/typescript/packages/**'`, which now reaches this package. It is kept out by **naming no + './languages/typescript/packages/**' --filter './packages/**'`, which now + reaches this package. It is kept out by **naming no live script after a turbo task** — the suite's runners are `vitest:live` and `vitest:live:coverage`, which `turbo.json` knows nothing about. `test` is the obvious trap and `test:integration` is the less obvious one (a real turbo task, @@ -299,14 +303,17 @@ monorepo, which is where the silent failures are. - **The package is at `packages/eql/packages/eql`, two levels down.** The subtree root has no `package.json` by design, so a tool that globs one level under `packages/` selects the root — a directory with no manifest and no - scripts — and not the package. That is why root `pnpm test` is - `turbo test --filter './languages/typescript/packages/**'` and not `'./languages/typescript/packages/*'`: under the - one-level filter the task graph contained `@cipherstash/eql#build` (pulled in - transitively by its consumers) and **no `#test` at all**, so its Vitest suite - ran nowhere while CI stayed green. `build` can stay one-level because - consumers pull it through `^build`. Anything else that walks `languages/typescript/packages/*` needs - the same treatment — `scripts/lint-typecheck-scope.mjs` already carries the - two nested roots explicitly. + scripts — and not the package. It is also outside `languages/typescript/`, + where every other npm package lives. That is why root `pnpm test` is + `turbo test --filter './languages/typescript/packages/**' --filter + './packages/**'`: under a one-level `./packages/*` filter the task graph + contained `@cipherstash/eql#build` (pulled in transitively by its consumers) + and **no `#test` at all**, so its Vitest suite ran nowhere while CI stayed + green, and a filter naming only `languages/typescript/` drops it the same + way. `build` can stay one-level because consumers pull it through `^build`. + Anything else that walks the package roots needs the same treatment — + `scripts/lint-typecheck-scope.mjs` already carries the nested roots + explicitly. - **Anything invoking a mise task must run with `working_directory: packages/eql`.** `packages/eql/mise.toml` is ~900 lines and its `[task_config].includes` pulls in `tasks/`, `tasks/postgres.toml` and diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 94634880f..e2056ca6d 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -31,9 +31,9 @@ See [AGENTS.md](./AGENTS.md) for a detailed layout, key APIs, environment variab **@cipherstash/stack** is the main package published to npm. It contains the encryption client and all integrations (Drizzle, Supabase, DynamoDB, secrets, identity). This is likely where you'll spend most of your time. -### `examples/` Directory +### `languages/typescript/examples/` Directory -The `examples/` directory contains applications demonstrating how to use `@cipherstash/stack`. They reference the local workspace packages, so you can verify your changes in a real application scenario. +The `languages/typescript/examples/` directory contains applications demonstrating how to use `@cipherstash/stack`. They reference the local workspace packages, so you can verify your changes in a real application scenario. ## Setup Instructions @@ -72,7 +72,7 @@ Start the dev script, which watches for changes to the packages and is picked up pnpm run dev ``` -Then navigate to one of the examples in `examples/` and follow its README. +Then navigate to one of the examples in `languages/typescript/examples/` and follow its README. ## Making Changes diff --git a/SECURITY.md b/SECURITY.md index 77851b70b..506e118e4 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -112,7 +112,7 @@ The following are **in scope**: The following are **out of scope**: -- Example applications in the `examples` dir (though we are still grateful for any relevant disclosures there) +- Example applications in the `languages/typescript/examples` dir (though we are still grateful for any relevant disclosures there) - Social engineering, physical attacks, or denial-of-service - Attacks requiring privileged access to developer machines or CI/CD infrastructure diff --git a/docs/query-api-walkthrough.md b/docs/query-api-walkthrough.md index 1c7419f90..5c82155ba 100644 --- a/docs/query-api-walkthrough.md +++ b/docs/query-api-walkthrough.md @@ -74,4 +74,4 @@ flowchart LR - **`cipherstashclient`** = the CipherStash Client **Rust SDK**, compiled via Neon into the platform `.node` binary inside `@cipherstash/protect-ffi`. It performs the actual crypto and talks to ZeroKMS. - **Result shape:** `EncryptedQueryResult` (`types.ts:175`); shaped by `formatEncryptedResult(..., returnType)` (`eql` vs raw). - **Version:** `languages/typescript/packages/stack/package.json` pins `@cipherstash/protect-ffi@0.30.0` (`stack-drizzle` and `stack-supabase` pin the same version — they must move in lockstep). -- **Paths:** rows 1–3 and the notes above are relative to `languages/typescript/packages/stack/src/`; row 1a is rooted at `packages/`; rows 4–5 are inside the installed `@cipherstash/protect-ffi`. Line numbers drift — search the symbol, don't trust the offset. +- **Paths:** rows 1–3 and the notes above are relative to `languages/typescript/packages/stack/src/`; row 1a is rooted at `languages/typescript/packages/`; rows 4–5 are inside the installed `@cipherstash/protect-ffi`. Line numbers drift — search the symbol, don't trust the offset. diff --git a/e2e/README.md b/e2e/README.md index 1565158d4..6333c56e5 100644 --- a/e2e/README.md +++ b/e2e/README.md @@ -1,6 +1,6 @@ # `@cipherstash/e2e` -End-to-end tests that exercise built CipherStash binaries and cross-package behaviour. Lives outside `packages/` because these tests are not tied to a single package — they verify how the published artefacts behave when a user actually runs them. +End-to-end tests that exercise built CipherStash binaries and cross-package behaviour. Lives outside `languages/typescript/packages/` because these tests are not tied to a single package — they verify how the published artefacts behave when a user actually runs them. ## Running From bafbfc728907f8487eda8481096269c8b1cd69af Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 09:05:28 +1000 Subject: [PATCH 7/9] test(e2e): point the synthetic Dependabot glob at languages/typescript supply-chain.e2e.test.ts exercises the `directories` glob branch with a synthetic `/packages/*` entry. After the move that glob matches only packages/eql, which has no package.json, so the assertion failed. Neither `pnpm test` nor `test:scripts` runs this suite; it fails only under `turbo run test:e2e --filter @cipherstash/e2e`. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- e2e/tests/supply-chain.e2e.test.ts | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/e2e/tests/supply-chain.e2e.test.ts b/e2e/tests/supply-chain.e2e.test.ts index 5e3b6abcc..af9ec5c25 100644 --- a/e2e/tests/supply-chain.e2e.test.ts +++ b/e2e/tests/supply-chain.e2e.test.ts @@ -657,9 +657,10 @@ const ignoresAllSemverMajor = (entry: DependabotUpdate): boolean => // this check exists to catch — and glob-expanding it here would hide it. // // A glob is satisfied by matching AT LEAST ONE directory holding the manifest, -// not all of them. `/packages/*` under the npm entry would fail an every-match -// rule against this very tree today: languages/typescript/packages/utils/ holds only config/ and -// logger/, with no package.json of its own. +// not all of them. `/languages/typescript/packages/*` under the npm entry +// would fail an every-match rule against this very tree today: +// languages/typescript/packages/utils/ holds only config/ and logger/, with no +// package.json of its own. // // Expanded with node:fs `globSync` (Node 22, which package.json engines already // require) rather than a glob library — this package has none, and a check on @@ -823,12 +824,15 @@ describe('supply chain — automated dependency updates (Dependabot)', () => { it('a `directories` glob is expanded; the same pattern under `directory` is not', () => { // No entry in .github/dependabot.yml uses `directories` today, so the glob // branch above ships with no live coverage — and the first person to write - // `directories: ["/packages/*"]` would otherwise be failed by a check + // `directories: ["/languages/typescript/packages/*"]` would otherwise be failed by a check // reporting "no package.json" at a path that was never meant to be literal. // Synthetic entries because this suite asserts against the real config as // committed; exercising a branch must not mean editing it. expect( - unmonitoredDirectories({ directories: ['/packages/*'] }, 'package.json'), + unmonitoredDirectories( + { directories: ['/languages/typescript/packages/*'] }, + 'package.json', + ), ).toEqual([]) // Literal paths remain valid under `directories` — globbing is an // extension of the key, not a requirement of it. @@ -853,7 +857,10 @@ describe('supply chain — automated dependency updates (Dependabot)', () => { // written there monitors nothing and must fail even though the identical // pattern passes above. expect( - unmonitoredDirectories({ directory: '/packages/*' }, 'package.json'), + unmonitoredDirectories( + { directory: '/languages/typescript/packages/*' }, + 'package.json', + ), ).toHaveLength(1) // An empty list fails too. It has no entry to be wrong about, so a // per-directory check reports nothing and the entry passes while From 7162d95757dac618bceec0c564e2340d7192d6e0 Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 09:15:12 +1000 Subject: [PATCH 8/9] docs: redraw the layout trees for languages/typescript The ASCII trees in CONTRIBUTING.md and docs/agents/domain.md draw packages/ and examples/ as tree branches, which no path rewrite matches. They now show languages/typescript/packages/, languages/typescript/examples/ and EQL at packages/eql/. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- CONTRIBUTING.md | 12 +++++++----- docs/agents/domain.md | 2 +- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index e2056ca6d..8297ecabe 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -14,11 +14,13 @@ This is a [Turborepo](https://turbo.build/) monorepo managed with [pnpm](https:/ ```text . -├── packages/ -│ ├── stack/ <-- Main package (@cipherstash/stack) -│ ├── cli/ <-- The `stash` CLI -│ └── ... <-- stack-drizzle, stack-supabase, stack-prisma, nextjs, migrate, wizard, ... -├── examples/ <-- Runnable example apps +├── languages/typescript/ +│ ├── packages/ +│ │ ├── stack/ <-- Main package (@cipherstash/stack) +│ │ ├── cli/ <-- The `stash` CLI +│ │ └── ... <-- stack-drizzle, stack-supabase, stack-prisma, nextjs, migrate, wizard, ... +│ └── examples/ <-- Runnable example apps +├── packages/eql/ <-- EQL (@cipherstash/eql and its Rust crates) ├── e2e/ <-- Cross-package end-to-end tests ├── skills/ <-- Agent skills ├── .changeset/ diff --git a/docs/agents/domain.md b/docs/agents/domain.md index bf188066c..48ebd3ccb 100644 --- a/docs/agents/domain.md +++ b/docs/agents/domain.md @@ -20,7 +20,7 @@ decisions are actually resolved. / ├── CONTEXT-MAP.md ├── docs/adr/ system-wide decisions -└── packages/ +└── languages/typescript/packages/ ├── stack/ │ ├── CONTEXT.md │ └── docs/adr/ stack-specific decisions From b3ffccd499142a1ccdf8a875093890b14131a09a Mon Sep 17 00:00:00 2001 From: Lindsay Holmwood Date: Fri, 2 Oct 2026 14:41:04 +1000 Subject: [PATCH 9/9] build(protect-ffi): name the wrapper's folder in repository.directory Every other published manifest, including the six protect-ffi platform packages, names its folder in repository.directory. The wrapper did not, so npm and GitHub could not link its package page to its source, and no test could check every published manifest at once. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a --- languages/typescript/packages/protect-ffi/package.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/languages/typescript/packages/protect-ffi/package.json b/languages/typescript/packages/protect-ffi/package.json index 7c6dccfa2..aec9d3d26 100644 --- a/languages/typescript/packages/protect-ffi/package.json +++ b/languages/typescript/packages/protect-ffi/package.json @@ -3,7 +3,8 @@ "version": "0.33.0", "repository": { "type": "git", - "url": "git+https://github.com/cipherstash/stack.git" + "url": "git+https://github.com/cipherstash/stack.git", + "directory": "languages/typescript/packages/protect-ffi" }, "bugs": { "url": "https://github.com/cipherstash/stack/issues"