Commit Graph
6 Commits
Author SHA1 Message Date
clawbot 44714205d4 Bring every copied template file to sneak/prompts next at dd4027b (closes #67)
check / check (push) Successful in 5m28s
Every file keyfunc copies from sneak/prompts now matches its next branch at commit dd4027b907ef99cdc3187c215cc4d610b7a11efc. REPO_POLICIES.md is the current copy; .gitignore and .dockerignore now ignore id_ecdsa_sk and id_ed25519_sk, the private key files ssh-keygen writes for hardware-backed keys, and .dockerignore keeps out a .git/config at any depth. The other copied files already matched; no adapted file needed a change.

Model: opus-5-5
2026-10-04 22:25:47 +02:00
clawbot b0e018f0b6 The development image's /src is a clean checkout: keep .gitea in the build context (closes #63)
check / check (push) Failing after 3s
.dockerignore no longer keeps .gitea out of the build context. The development image gets .git, so without the workflow directory git status in /src reported the CI workflow as deleted, make build stamped a -dirty version, and git commit -a would have deleted the workflow. Now /src is a clean checkout and make build there stamps the short commit. The comment above /keyfunc now names only the binary.

Model: opus-5-5
2026-10-04 19:59:07 +02:00
clawbot 1d1c8182be Current templates: safe.directory, golangci-lint v2.14.0, fetch-depth 0, the policy's last stage (closes #50)
check / check (push) Failing after 2s
Brings keyfunc to the current sneak/prompts templates: REPO_POLICIES.md and .golangci.yml are the template copies, the lint phase runs golangci-lint v2.14.0 on the template digest (its one new finding fixed), and .dockerignore gains the template line for submodule configs. The stage that compiles keyfunc marks /src safe for git, so a context sent as a tar stream still stamps the tag or short commit. The last stage is now a development environment, as the policy asks of a non-server repo: run the tool as docker run IMAGE keyfunc .... The CI checkout fetches tags.

Deviation: .gitea/workflows/check.yml differs from the template copy by fetch-depth: 0, which REPO_POLICIES.md requires.

Model: opus-5-5
2026-10-04 08:59:08 +02:00
clawbot d6b87f7502 The linter config, .gitignore and .dockerignore from the current templates (closes #40)
check / check (push) Successful in 1m32s
.golangci.yml is now a byte-identical copy of the current template: depguard is on with the test-support rule, and the gomodguard_v2 block list is in. .gitignore and .dockerignore are the current templates with this repo's own entries added at the end; the .dockerignore secret-file patterns now keep key files and .env files out of the build context, while .git stays in for the version stamp. No Go source needed changes.

Model: opus-5-5
2026-10-04 02:25:50 +02:00
clawbot 7f7fe33cd6 Stamp the git tag or short commit in a plain docker build (closes #35)
check / check (push) Successful in 1m6s
.dockerignore left out .git, so make build inside the image fell back to
"dev". The build context now carries .git, without its config, which can
hold a credential in the remote URL. The build stage takes the VERSION
build argument when one is given, otherwise git describe --tags --always,
and fails if the context carries .git and no version comes out.

Model: opus-5-5
2026-10-02 06:12:05 +02:00
clawbot 279cba6bcf Skeleton, mnemonic input, derivation, and the ssh pub and priv commands (closes #1)
check / check (push) Successful in 5s
The module, the script entrypoints and Makefile, Docker-only linting, the mnemonic sources in the specified order with their refusals, the BIP-85 derivation, and keyfunc ssh pub and priv with the README test vectors as tests. Two review rounds; the second passed with no findings.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 17:34:54 +02:00