.golangci.yml is now a byte-identical copy of the sneak/prompts next
copy: depguard is on with the test-support rule, and the gomodguard_v2
block list is in. keyfunc has no test-support packages of its own, so
the deny list is left as it is.
.gitignore and .dockerignore are the sneak/prompts next copies with this
repo's own entries added at the end: /keyfunc in both, and .gitea in
.dockerignore. .git stays in the Docker build context without
.git/config, for the version stamp.
The README TODO line for this issue is removed.
Model: opus-5-5
The module, the script entrypoints and Makefile, Docker-only linting, the mnemonic sources in the specified order with their refusals, the BIP-85 derivation, and keyfunc ssh pub and priv with the README test vectors as tests. Two review rounds; the second passed with no findings.
Model: opus-5 (implementation and review); fable-5-1 (landing)
The README is the specification sneak approved on 2026-09-07, moved
here from the hacks repository: deterministic SSH keys, age identities
with encrypt and decrypt, and child mnemonics, all derived from one
BIP-39 mnemonic and stored nowhere.
Model: fable-5-1