# Workflow - branch (from `main`) - do the work in Next Step - move Next Step to the top of Completed Steps - move the top item of Future Steps into Next Step - commit (`TODO.md` changes in the same commit as the work) - merge to `main` if the branch is not protected, otherwise open a PR - push # Status pre-1.0 No git tags. The site is live and now has the scripts-to-rule-them-all scaffold (`Makefile`, `script/`, `Dockerfile`, `check.yml`) and the canonical policy dotfiles; `LICENSE` is the only mandated file still missing. Every external reference in the repo is now pinned by cryptographic hash (or, for the wrangler CLI install, an exact version), and the Hugo that builds the published site is a deliberate pinned version rather than whatever the base image's package repo serves. The site now ships a Cloudflare Pages `_headers` file, so its response security headers are declared in the repo instead of being whatever the edge defaults to — unverified in production until the next deploy. # Next Step Add `LICENSE` (#10) and replace the README's "content is provided as-is" note with the committed license. Blocked on the owner's choice of license — the remaining policy scaffold is otherwise complete. # Completed Steps - 2026-08-09: added `static/_headers` so Cloudflare Pages serves baseline response security headers (closes #14). Hugo copies `static/` verbatim into `public/`, which is the deploy root Pages reads the file from; this is the first root-level `static/` in the repo, and the built tree confirms it unions with the theme's rather than shadowing it — `public/css/style.css` and `public/index.html` are byte-identical to the previous build and the static file count goes 1 to 2. The live "before" was measured, not assumed: Cloudflare already sends `X-Content-Type-Options` and `Referrer-Policy` by default, so the substance here is `Strict-Transport-Security`, `Content-Security-Policy`, `X-Frame-Options` and `Permissions-Policy`. The CSP is `default-src 'none'` with `style-src 'unsafe-inline'`, which the built page supports exactly: it has no script, img, link, iframe, form or media element and no `style=`/`on*=` attribute, only the one inline `<style>` block `baseof.html` fills by `readFile`. Verified in a headless Chrome against a local server that parses the committed `_headers` and applies it as real response headers: zero CSP violations, the inlined stylesheet parses to 17 rules and the computed body padding, tagline colour and link colour all come from the theme CSS, framing the page from another origin is refused by `frame-ancestors 'none'` (consistent with `X-Frame-Options: DENY`), and all five named outbound links still navigate with status 200. HSTS carries neither `preload` nor `includeSubDomains`: `www.lora.vegas` is the only other name in DNS and it is served by this same Pages project, so this file sets HSTS on its responses directly, and `includeSubDomains` would instead bind every future subdomain for a year with no way to walk it back inside the max-age window - 2026-08-09: restructured `README.md` into the canonical section set (closes #11): a Description first line, then Getting Started, Entrypoints, Rationale, Design, TODO, License, Author. The non-standard About / Contributing / Technical Details headings are gone, but nothing they held was dropped — the bullet list of what the site publishes moved under the Description, the contribute contact and the local-preview instructions moved into Getting Started. Getting Started was written against the current `Makefile` rather than the old prose: there is no `make build` target, so the former "Build: `hugo`" instruction is now `make test`, and the former "Local Development: `hugo server`" is `make setup` then `make serve`. Two stale claims fixed: the site is deployed by Gitea Actions to Cloudflare Pages, not "GitHub Actions", and the Entrypoints bullet for `script/fmt` still described the top-level-markdown-only scope that #12 replaced with `'**/*.md'` and `'**/*.css'`. The License section body is deliberately untouched — it is owned by #10, which is blocked on the owner's choice of license, and the Description sentence is likewise missing the license clause the policy calls for until #10 lands. Design section claims were verified against the tree, not assumed - 2026-08-09: widened the prettier gate from top-level markdown to `'**/*.md'` and `'**/*.css'` (closes #12). `themes/loravega/static/css/style.css` was never formatted or gated even though it is inlined into every page; it is now both, and the reformat landed as its own commit ahead of the script change so no commit in the branch is red. `content/` is excluded in `.prettierignore`, and that exclusion is measured rather than assumed: with `content/` in scope, prettier re-wrapped one list item in `content/_index.md` and the rendered `public/index.html` changed with it (the wrap became a literal newline between `7 PM at` and the following ``). HTML collapses that newline to a space so the page looks identical, but the published bytes are not, and this content carries raw HTML that goldmark passes through verbatim under `unsafe = true`. `themes/loravega/layouts/` is excluded too, with the reason recorded: those files are Go templates, not HTML, and prettier has no parser for `{{ ... }}` — covering them would need a plugin and therefore a `package.json`. Verified by extracting `public/` from the built image before and after: with the final scope, `index.html`, `index.xml` and `sitemap.xml` are byte-identical and only the verbatim-copied `public/css/style.css` changes, in whitespace only — the minified `