# 019.0-DEV-FLAG-UN-LANDABLE-UPDATES

## User Story

So that one un-landable update doesn't poison my whole safe-update batch (and my
auto-update cron doesn't churn land/revert daily), as a CI/automation engineer, I
want `dry-aged-deps` to detect safe updates whose peer graph won't resolve
(ERESOLVE) and flag+skip them so the landable rest still applies.

## Context

Implements ADR-0022 / RFC-004 (traces P028). Detection uses npm's real resolver:
attempt an incremental `npm install --ignore-scripts --package-lock-only` of the
safe target set in an isolated copy; on ERESOLVE, isolate the culprit(s). Never
`--force` / `--legacy-peer-deps`.

## Requirements

- **REQ-UNLANDABLE-DETECT**: Given the safe target set, probe it with npm's
  resolver. If the whole batch resolves, all rows are landable. If it ERESOLVEs,
  isolate the un-landable package(s) and return them separately from the landable
  rows.
- **REQ-UNLANDABLE-ISOLATE**: An un-landable update is isolated so the rest of the
  batch still lands. When the landable remainder still fails to resolve as a set
  (a combination conflict that cannot be cleanly attributed), conservatively treat
  the remainder as un-landable rather than land a broken set.
- **REQ-UNLANDABLE-REASON**: Each un-landable row carries reason
  `incompatible-peers`.
- **REQ-UNLANDABLE-FAIL-LOUD**: A non-ERESOLVE npm error during the probe
  (offline, EACCES, registry failure) propagates (fail-loud) — it is NOT treated
  as un-landable (preserves ADR-0021).
- **REQ-UNLANDABLE-NO-FORCE**: The probe never passes `--force` /
  `--legacy-peer-deps`.
