  ok  FACT: kimai-db mariadb:11.6 -> 12.3 (cross-major)    rc=1 (expected 1)
engine-major gate — range HEAD~1..HEAD: 1 compose file(s) changed, 1 engine pin(s) compared

ENGINE-MAJOR GATE FAILED: templates/kimai/docker-compose.yml service kimai-db moves mariadb 11 -> 12 (mariadb:11.6 -> mariadb:12.3).
RULE (app-catalog CLAUDE.md, operator ruling 2026-09-13): until the Update button takes a VERIFIED BACKUP as its precondition (Slice 4, felhom.eu OPEN-ITEMS.md R-448), no template may move a database-engine image across a MAJOR version.
WHY: MariaDB sidecars now carry MARIADB_AUTO_UPGRADE=1 and WILL convert the customer's datadir on the next Update; PostgreSQL's image refuses to start on an older major's datadir (R-463). Either way this is a customer-data event with no backup in front of it.
EXPIRY: this rule is removed DELIBERATELY when R-448 ships — the removal is its own register row, not a silent edit. Until then, keep the engine within its major.

  ok  FACT: docmost-postgres postgres:16-alpine -> 17-alpine rc=1 (expected 1)
  ok  FACT: kimai-db mariadb:11.6 -> mariadb:lts (major unreadable) rc=2 (expected 2)
  ok  GENUINE: kimai-db mariadb:11.6 -> 11.8 (within major) rc=0 (expected 0)
  ok  DECOY: major moves only in a comment + serverVersion env rc=0 (expected 0)
  ok  DECOY: the APP image crosses a major (kimai 2.57 -> 3.0) rc=0 (expected 0)
  ok  DECOY: 'mariadb:12.3' lands in README.md, not a template rc=0 (expected 0)

catalog gate decoys OK — 7 case(s), every label judged on its fact (R-421)
