Current templates: safe.directory, golangci-lint v2.14.0, fetch-depth 0, the policy's last stage (closes #50) #56

Merged
clawbot merged 1 commits from issue-50-current-templates into next 2026-10-04 08:59:09 +02:00
Collaborator

Brings keyfunc to the current next templates of sneak/prompts, for findings 3, 6 and 7 of #28 (comment).

  • REPO_POLICIES.md and .golangci.yml are the template copies; .dockerignore gains the template's .git/modules/**/config line. script/lint, script/test, script/docker and script/cibuild already were the template copies.
  • The lint phase runs golangci-lint v2.14.0 on the template's digest. Its new errors.AsType finding is fixed in internal/cli/cli.go and internal/cli/ssh/to.go.
  • The stage that compiles keyfunc marks /src safe for git, so a context sent as a tar stream, whose files keep the sender's owner, still gets the tag or short commit as its version.
  • The last stage is a development environment, as the policy asks of a non-server repo: the Debian Go image, script/bootstrap run in it, the source in /src, keyfunc in /usr/local/bin. The image now opens a shell rather than running keyfunc: docker run keyfunc ssh pub becomes docker run keyfunc keyfunc ssh pub. The README says what the image is.
  • The CI checkout sets fetch-depth: 0, still pinned by commit.

Disclosures:

  • Judgement call: the test phase uses the same Debian Go image, as the template's now does, so the Dockerfile pins one Go image for GO_VERSION in script/bootstrap to match; gcc and musl-dev are no longer installed.
  • Judgement call: no separate build stage; the last stage compiles keyfunc, with the version stamping and its check unchanged.
  • Deviation: .gitea/workflows/check.yml now differs from the template's copy, which has no fetch-depth: 0.
  • Unverified: the Gitea run of this branch has not started; no keyfunc run has left the queue since 06:18.

Model: opus-5-5

Brings keyfunc to the current `next` templates of `sneak/prompts`, for findings 3, 6 and 7 of https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-120217. - `REPO_POLICIES.md` and `.golangci.yml` are the template copies; `.dockerignore` gains the template's `.git/modules/**/config` line. `script/lint`, `script/test`, `script/docker` and `script/cibuild` already were the template copies. - The lint phase runs golangci-lint v2.14.0 on the template's digest. Its new `errors.AsType` finding is fixed in `internal/cli/cli.go` and `internal/cli/ssh/to.go`. - The stage that compiles `keyfunc` marks `/src` safe for git, so a context sent as a tar stream, whose files keep the sender's owner, still gets the tag or short commit as its version. - The last stage is a development environment, as the policy asks of a non-server repo: the Debian Go image, `script/bootstrap` run in it, the source in `/src`, `keyfunc` in `/usr/local/bin`. The image now opens a shell rather than running `keyfunc`: `docker run keyfunc ssh pub` becomes `docker run keyfunc keyfunc ssh pub`. The README says what the image is. - The CI checkout sets `fetch-depth: 0`, still pinned by commit. Disclosures: - Judgement call: the test phase uses the same Debian Go image, as the template's now does, so the `Dockerfile` pins one Go image for `GO_VERSION` in `script/bootstrap` to match; gcc and musl-dev are no longer installed. - Judgement call: no separate build stage; the last stage compiles `keyfunc`, with the version stamping and its check unchanged. - Deviation: `.gitea/workflows/check.yml` now differs from the template's copy, which has no `fetch-depth: 0`. - Unverified: the Gitea run of this branch has not started; no keyfunc run has left the queue since 06:18. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 07:47:06 +02:00
clawbot self-assigned this 2026-10-04 07:47:06 +02:00
Author
Collaborator
  • REPO_POLICIES.md is not byte-identical to the current copy on the next branch of sneak/prompts. Commit 562b40b there landed after this branch was pushed. It keeps agent guidance in one root AGENTS.md and adds AGENTS.md to the files allowed in the repository root. Acceptable: copy the current next file from sneak/prompts again, so the two files are identical.

Model: opus-5-5

- `REPO_POLICIES.md` is not byte-identical to the current copy on the `next` branch of `sneak/prompts`. Commit `562b40b` there landed after this branch was pushed. It keeps agent guidance in one root `AGENTS.md` and adds `AGENTS.md` to the files allowed in the repository root. Acceptable: copy the current `next` file from `sneak/prompts` again, so the two files are identical. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 08:20:39 +02:00
clawbot added 1 commit 2026-10-04 08:30:33 +02:00
REPO_POLICIES.md and .golangci.yml are the sneak/prompts next copies, and
.dockerignore takes the template's .git/modules/**/config line. The lint
phase runs golangci-lint v2.14.0; its two errors.AsType findings are
fixed. The stage that builds keyfunc marks /src safe for git, so a
context sent as a tar stream still yields a version. That stage is now
the last one and a development environment on the Debian Go image: what
script/bootstrap installs, the source in /src, keyfunc on the PATH. The
test phase uses the same image, so one Go image stays matched to
script/bootstrap. The CI checkout fetches all history and tags.

Model: opus-5-5
clawbot force-pushed issue-50-current-templates from 9ad3bbd347 to 72cb05b5a8 2026-10-04 08:30:33 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-04 08:34:50 +02:00
Author
Collaborator

REPO_POLICIES.md is copied again from the current next of sneak/prompts and is now byte-identical to it, for #56 (comment). Nothing else moved: .golangci.yml, script/lint, script/test, script/docker, script/cibuild and the template parts of .dockerignore and .gitignore already match the current copies.

Model: opus-5-5

`REPO_POLICIES.md` is copied again from the current `next` of `sneak/prompts` and is now byte-identical to it, for https://git.eeqj.de/sneak/keyfunc/pulls/56#issuecomment-121210. Nothing else moved: `.golangci.yml`, `script/lint`, `script/test`, `script/docker`, `script/cibuild` and the template parts of `.dockerignore` and `.gitignore` already match the current copies. Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 1d1c8182be into next 2026-10-04 08:59:09 +02:00
clawbot deleted branch issue-50-current-templates 2026-10-04 08:59:09 +02:00
Sign in to join this conversation.