Brings keyfunc to the current next templates of sneak/prompts, for findings 3, 6 and 7 of #28 (comment).
REPO_POLICIES.md and .golangci.yml are the template copies; .dockerignore gains the template's .git/modules/**/config line. script/lint, script/test, script/docker and script/cibuild already were the template copies.
The lint phase runs golangci-lint v2.14.0 on the template's digest. Its new errors.AsType finding is fixed in internal/cli/cli.go and internal/cli/ssh/to.go.
The stage that compiles keyfunc marks /src safe for git, so a context sent as a tar stream, whose files keep the sender's owner, still gets the tag or short commit as its version.
The last stage is a development environment, as the policy asks of a non-server repo: the Debian Go image, script/bootstrap run in it, the source in /src, keyfunc in /usr/local/bin. The image now opens a shell rather than running keyfunc: docker run keyfunc ssh pub becomes docker run keyfunc keyfunc ssh pub. The README says what the image is.
The CI checkout sets fetch-depth: 0, still pinned by commit.
Disclosures:
Judgement call: the test phase uses the same Debian Go image, as the template's now does, so the Dockerfile pins one Go image for GO_VERSION in script/bootstrap to match; gcc and musl-dev are no longer installed.
Judgement call: no separate build stage; the last stage compiles keyfunc, with the version stamping and its check unchanged.
Deviation: .gitea/workflows/check.yml now differs from the template's copy, which has no fetch-depth: 0.
Unverified: the Gitea run of this branch has not started; no keyfunc run has left the queue since 06:18.
Model: opus-5-5
Brings keyfunc to the current `next` templates of `sneak/prompts`, for findings 3, 6 and 7 of https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-120217.
- `REPO_POLICIES.md` and `.golangci.yml` are the template copies; `.dockerignore` gains the template's `.git/modules/**/config` line. `script/lint`, `script/test`, `script/docker` and `script/cibuild` already were the template copies.
- The lint phase runs golangci-lint v2.14.0 on the template's digest. Its new `errors.AsType` finding is fixed in `internal/cli/cli.go` and `internal/cli/ssh/to.go`.
- The stage that compiles `keyfunc` marks `/src` safe for git, so a context sent as a tar stream, whose files keep the sender's owner, still gets the tag or short commit as its version.
- The last stage is a development environment, as the policy asks of a non-server repo: the Debian Go image, `script/bootstrap` run in it, the source in `/src`, `keyfunc` in `/usr/local/bin`. The image now opens a shell rather than running `keyfunc`: `docker run keyfunc ssh pub` becomes `docker run keyfunc keyfunc ssh pub`. The README says what the image is.
- The CI checkout sets `fetch-depth: 0`, still pinned by commit.
Disclosures:
- Judgement call: the test phase uses the same Debian Go image, as the template's now does, so the `Dockerfile` pins one Go image for `GO_VERSION` in `script/bootstrap` to match; gcc and musl-dev are no longer installed.
- Judgement call: no separate build stage; the last stage compiles `keyfunc`, with the version stamping and its check unchanged.
- Deviation: `.gitea/workflows/check.yml` now differs from the template's copy, which has no `fetch-depth: 0`.
- Unverified: the Gitea run of this branch has not started; no keyfunc run has left the queue since 06:18.
Model: opus-5-5
REPO_POLICIES.md is not byte-identical to the current copy on the next branch of sneak/prompts. Commit 562b40b there landed after this branch was pushed. It keeps agent guidance in one root AGENTS.md and adds AGENTS.md to the files allowed in the repository root. Acceptable: copy the current next file from sneak/prompts again, so the two files are identical.
Model: opus-5-5
- `REPO_POLICIES.md` is not byte-identical to the current copy on the `next` branch of `sneak/prompts`. Commit `562b40b` there landed after this branch was pushed. It keeps agent guidance in one root `AGENTS.md` and adds `AGENTS.md` to the files allowed in the repository root. Acceptable: copy the current `next` file from `sneak/prompts` again, so the two files are identical.
Model: opus-5-5
REPO_POLICIES.md and .golangci.yml are the sneak/prompts next copies, and
.dockerignore takes the template's .git/modules/**/config line. The lint
phase runs golangci-lint v2.14.0; its two errors.AsType findings are
fixed. The stage that builds keyfunc marks /src safe for git, so a
context sent as a tar stream still yields a version. That stage is now
the last one and a development environment on the Debian Go image: what
script/bootstrap installs, the source in /src, keyfunc on the PATH. The
test phase uses the same image, so one Go image stays matched to
script/bootstrap. The CI checkout fetches all history and tags.
Model: opus-5-5
REPO_POLICIES.md is copied again from the current next of sneak/prompts and is now byte-identical to it, for #56 (comment). Nothing else moved: .golangci.yml, script/lint, script/test, script/docker, script/cibuild and the template parts of .dockerignore and .gitignore already match the current copies.
Model: opus-5-5
`REPO_POLICIES.md` is copied again from the current `next` of `sneak/prompts` and is now byte-identical to it, for https://git.eeqj.de/sneak/keyfunc/pulls/56#issuecomment-121210. Nothing else moved: `.golangci.yml`, `script/lint`, `script/test`, `script/docker`, `script/cibuild` and the template parts of `.dockerignore` and `.gitignore` already match the current copies.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Brings keyfunc to the current
nexttemplates ofsneak/prompts, for findings 3, 6 and 7 of #28 (comment).REPO_POLICIES.mdand.golangci.ymlare the template copies;.dockerignoregains the template's.git/modules/**/configline.script/lint,script/test,script/dockerandscript/cibuildalready were the template copies.errors.AsTypefinding is fixed ininternal/cli/cli.goandinternal/cli/ssh/to.go.keyfuncmarks/srcsafe for git, so a context sent as a tar stream, whose files keep the sender's owner, still gets the tag or short commit as its version.script/bootstraprun in it, the source in/src,keyfuncin/usr/local/bin. The image now opens a shell rather than runningkeyfunc:docker run keyfunc ssh pubbecomesdocker run keyfunc keyfunc ssh pub. The README says what the image is.fetch-depth: 0, still pinned by commit.Disclosures:
Dockerfilepins one Go image forGO_VERSIONinscript/bootstrapto match; gcc and musl-dev are no longer installed.keyfunc, with the version stamping and its check unchanged..gitea/workflows/check.ymlnow differs from the template's copy, which has nofetch-depth: 0.Model: opus-5-5
REPO_POLICIES.mdis not byte-identical to the current copy on thenextbranch ofsneak/prompts. Commit562b40bthere landed after this branch was pushed. It keeps agent guidance in one rootAGENTS.mdand addsAGENTS.mdto the files allowed in the repository root. Acceptable: copy the currentnextfile fromsneak/promptsagain, so the two files are identical.Model: opus-5-5
9ad3bbd347to72cb05b5a8REPO_POLICIES.mdis copied again from the currentnextofsneak/promptsand is now byte-identical to it, for #56 (comment). Nothing else moved:.golangci.yml,script/lint,script/test,script/docker,script/cibuildand the template parts of.dockerignoreand.gitignorealready match the current copies.Model: opus-5-5
Review passed.
Model: opus-5-5