Devlog week 5: naming close, T3 scaffold, rebrand, repo, Dependabot race, competitor research
Naming close-out
Verification ran four passes on the shortlist and two kills got legitimately pushed back — one had been killed on a discontinued, non-overlapping product, which sharpened the rule to active and same category or it's a demote. The final name never appeared on any list: One Good Coffee, landing Wednesday, with the reasoning filed in the project's decisions doc. Two evenings of verification produced three finalists and the session produced the winner — worth being honest about which part did the work.
Tech stack wayfinder, one Telegram thread
The stack decision ran start to finish from one Telegram thread: T3 signed off on portfolio-analogy grounds (two existing projects share the shape), Drizzle + SQLite for the directory, newsletter infra deferred. Four parallel subagents then built the scaffold, the data model, and the v1 pages in minutes; ten commits squashed to eight on master. One ticket failed honestly — the MDX post body rendered raw — and got parked as a follow-up rather than papered over.
Rebrand, three commits
The MDX fix went in directly rather than being re-dispatched, because a known rabbit hole doesn't get more tractable from a fresh context — execute the previously-debugged thing. Then the rebrand: config, then identifiers, ending with a grep audit that found no leaked brand strings. What the week taught about rebrands: code rebrand is mechanical, the docs sweep is editorial, and they are two operations that fail if bundled.
Repo, CI, and the Dependabot race
The private repo went live Saturday with CI green after five stacked fixes — the way CI mornings go, each fix revealing the next failure underneath. Five GitHub settings were blocked by the free plan; the YAGNI call was that four of them are collaborator-class defences for a solo project, and only the Dependabot security-update PRs were worth wanting.
Dependabot then opened a 14-dependency PR the same day, bundling six security bumps with three major-version upgrades. The bundle was the root cause of the CI failure — Next 16 transitive plus a TypeScript the lint toolchain can't parse. The fix: split during rebase, keep the security bumps, revert the majors, then group the config so future cycles open three small PRs instead of one mega-PR. CVEs dropped 20 to 5 immediately.
Vault lint, mostly false positives
The weekly lint flagged 65 broken wikilinks; triage put most of them in explained buckets — repo-shorthand references and a symlink the script doesn't walk. Nothing auto-fixed: lint identifies, humans decide, because auto-fixing links is the kind of damage that costs more to repair than to leave.
Competitor research
Six parallel research streams built a 46KB competitor landscape for One Good Coffee; two streams hit guardrails and were recovered in-session from their captured data. The headline: nobody pairs editorial coverage with a real-time deals feed — Sprudge is editorial-only, the deals apps are deals-only — so the pairing this project is built around is structurally unowned. The risk worth carrying: the biggest coffee newsletters grew from a person's TikTok audience, and a person is a single point of failure.
Next: the brief rewrite the rebrand unblocked, then deployment.