|
|
|
@@ -13,23 +13,49 @@
|
|
|
|
|
pre-1.0
|
|
|
|
|
|
|
|
|
|
No git tags. The site is live and now has the scripts-to-rule-them-all scaffold
|
|
|
|
|
(`Makefile`, `script/`, `Dockerfile`, `check.yml`) and the canonical policy
|
|
|
|
|
dotfiles; `LICENSE` is the only mandated file still missing. Every external
|
|
|
|
|
reference in the repo is now pinned by cryptographic hash (or, for the wrangler
|
|
|
|
|
CLI install, an exact version), and the Hugo that builds the published site is a
|
|
|
|
|
deliberate pinned version rather than whatever the base image's package repo
|
|
|
|
|
serves. The site now ships a Cloudflare Pages `_headers` file, so its response
|
|
|
|
|
security headers are declared in the repo instead of being whatever the edge
|
|
|
|
|
defaults to — unverified in production until the next deploy.
|
|
|
|
|
(`Makefile`, `script/`, `Dockerfile`, `check.yml`), the canonical policy
|
|
|
|
|
dotfiles and `LICENSE`, so the mandated minimum file list is complete. Every
|
|
|
|
|
external reference in the repo is now pinned by cryptographic hash (or, for the
|
|
|
|
|
wrangler CLI install, an exact version), and the Hugo that builds the published
|
|
|
|
|
site is a deliberate pinned version rather than whatever the base image's
|
|
|
|
|
package repo serves. The site now ships a Cloudflare Pages `_headers` file, so
|
|
|
|
|
its response security headers are declared in the repo instead of being whatever
|
|
|
|
|
the edge defaults to — unverified in production until the next deploy.
|
|
|
|
|
|
|
|
|
|
# Next Step
|
|
|
|
|
|
|
|
|
|
Add `LICENSE` (#10) and replace the README's "content is provided as-is" note
|
|
|
|
|
with the committed license. Blocked on the owner's choice of license — the
|
|
|
|
|
remaining policy scaffold is otherwise complete.
|
|
|
|
|
Move the artifact actions in `.gitea/workflows/deploy.yml` to v4 once this Gitea
|
|
|
|
|
Actions instance serves the v4 artifact protocol; they are pinned on the
|
|
|
|
|
deprecated v3 line because v4 fails here (#20). This touches the live deploy
|
|
|
|
|
path, so it needs a real workflow run to verify rather than a local check.
|
|
|
|
|
|
|
|
|
|
# Completed Steps
|
|
|
|
|
|
|
|
|
|
- 2026-08-10: added the `LICENSE` file and made the README say what it says
|
|
|
|
|
(closes #10). The repo is public (`private: false` on the Gitea API, verified
|
|
|
|
|
rather than assumed), so the owner's standing policy — MIT on any public repo
|
|
|
|
|
lacking a license — applies. `LICENSE` is byte-identical to the canonical
|
|
|
|
|
`sneak/homoicon` copy, confirmed by git blob hash rather than by eye
|
|
|
|
|
(`3274443`), and its body is word-for-word the SPDX MIT text with only the
|
|
|
|
|
line wrapping differing. The README's "Content is provided as-is for community
|
|
|
|
|
use." — which granted nothing and matched no committed file — is replaced by
|
|
|
|
|
`MIT. See [LICENSE](LICENSE).` plus an explicit statement that the licence
|
|
|
|
|
covers the content in `content/` as well as the code, since this repo carries
|
|
|
|
|
both and MIT names only "the Software". The Description first line now carries
|
|
|
|
|
the licence, which `REPO_POLICIES.md` requires and which was the one field it
|
|
|
|
|
was missing. Nothing published contradicts the choice: the built `public/`
|
|
|
|
|
tree carries no copyright, all-rights-reserved or terms-of-use string
|
|
|
|
|
anywhere, in `index.html`, `css/style.css`, `index.xml` or `sitemap.xml` — the
|
|
|
|
|
footer `baseof.html` renders names `@sneak` and links the repo but asserts no
|
|
|
|
|
reservation of rights, and the content is factual mesh channel data with no
|
|
|
|
|
licence claim of its own. The fmt gate cannot reach `LICENSE` and needed no
|
|
|
|
|
`.prettierignore` entry: `script/fmt` passes prettier the explicit globs
|
|
|
|
|
`'**/*.md'` and `'**/*.css'`, and an extensionless root file matches neither.
|
|
|
|
|
Measured, not assumed — a `script/fmt` run leaves the file's hash unchanged,
|
|
|
|
|
and a counterfactual `LICENSE.md` copy was reflowed by the same run, which is
|
|
|
|
|
the direct evidence that it is the extension and not an ignore rule doing the
|
|
|
|
|
excluding. Deliberately not done, per the issue: per-file licence headers and
|
|
|
|
|
SPDX identifiers, which no org standard mandates
|
|
|
|
|
- 2026-08-09: added `static/_headers` so Cloudflare Pages serves baseline
|
|
|
|
|
response security headers (closes #14). Hugo copies `static/` verbatim into
|
|
|
|
|
`public/`, which is the deploy root Pages reads the file from; this is the
|
|
|
|
@@ -200,9 +226,6 @@ remaining policy scaffold is otherwise complete.
|
|
|
|
|
|
|
|
|
|
# Future Steps
|
|
|
|
|
|
|
|
|
|
- Move the artifact actions to v4 once this Gitea Actions instance serves the v4
|
|
|
|
|
artifact protocol; they are pinned on the deprecated v3 line because v4 fails
|
|
|
|
|
here (#20)
|
|
|
|
|
- Move the deploy container to a pinned node 22 so the wrangler pin can advance
|
|
|
|
|
past 4.86.0 (#21)
|
|
|
|
|
- After the next deploy, confirm the `_headers` file actually took effect, on
|
|
|
|
|