# Workflow - branch (from `main`) - do the work in Next Step - move Next Step to the top of Completed Steps - move the top item of Future Steps into Next Step - commit (`TODO.md` changes in the same commit as the work) - merge to `main` if the branch is not protected, otherwise open a PR - push # Status pre-1.0 No git tags. The site is live and now has the scripts-to-rule-them-all scaffold (`Makefile`, `script/`, `Dockerfile`, `check.yml`); still missing `LICENSE` and policy files. Every external reference in the repo is now pinned by cryptographic hash (or, for the wrangler CLI install, an exact version), and the Hugo that builds the published site is a deliberate pinned version rather than whatever the base image's package repo serves. # Next Step Add the remaining policy scaffold: `LICENSE`, `REPO_POLICIES.md`, `.editorconfig`, and prettier config files (`.prettierrc`, `.prettierignore`). Update `README.md` accordingly. # Completed Steps - 2026-08-09: replaced `hugo.toml`'s deprecated `languageCode` key with `locale` (closes #18). Hugo deprecated `languageCode` in v0.158.0, so the Hugo pinned in the preceding commit warns about it; left alone it would become a third routinely-ignored warning, and a latent breakage when the key is removed. Deliberately sequenced **after** the Hugo version move and in the same branch: under the apk hugo 0.139.0 that CI ran until now, `locale` is an unknown key that is silently ignored, which downgrades the generated RSS from `en-us` to `en` with no warning and exit 0. Verified on hugo v0.164.0 that the RSS `` still reads `en-us`, the `lang` attribute is unchanged, and `public/` is byte-identical to the preceding commit's output - 2026-08-09: installed Hugo at a deliberate, hash-verified version instead of taking whatever alpine ships (closes #26). `script/bootstrap` no longer does `pkg_install hugo`; it installs `github.com/gohugoio/hugo@v0.164.0` with `go install`, which verifies the module against `sum.golang.org`. The version is a commented constant, as is the Go toolchain (`go1.26.5`) — hugo v0.164.0 requires go >= 1.26.0 and alpine 3.21 ships go 1.23.9 with `GOTOOLCHAIN=local`, so a bare `go install` refuses to run. `CGO_ENABLED=0` is deliberate: standard Hugo, not extended, because this site has no SCSS, no `resources.ToCSS`, no PostCSS and no image processing. This moves the build off apk's hugo 0.139.0, about two years behind, onto the current stable. Rendered output across the whole `public/` tree is unchanged except the `meta name=generator` version string - 2026-08-09: made `script/check` run `script/lint` (closes #9). It previously ran only `fmt-check` then `test`, so `script/lint` executed nowhere — not in `make check`, not in the pre-commit hook, and not in CI, even though the `Dockerfile` runs `make check` and `script/cibuild` builds it. It now runs `test`, `lint`, `fmt-check` in the canonical order, so the `hugo --printPathWarnings` render-target-collision signal is no longer discarded. `README.md`'s Entrypoints line was corrected to match - 2026-08-09: hash-pinned every external reference in `.gitea/workflows/deploy.yml` (closes #7): both job container images are pinned by digest, all three `uses:` are pinned by 40-hex commit SHA, and the wrangler install is pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is gone: the build job now runs on the same pinned `alpine` digest the `Dockerfile` uses, with a pre-checkout `apk add nodejs git tar` step (the Actions runner needs `node` inside the job container to execute JavaScript actions), an explicit `shell: sh` default, then `script/bootstrap` and `script/test`. The `deploy` job is guarded with `if: github.ref_name == 'main'` so it can never publish from a branch. Also dropped the dead `feat/initial-site` push trigger and reindented the file to 4-space YAML to match `check.yml`. This is the second attempt; the first broke the deploy and was reverted, so this one was verified by temporarily triggering the workflow on the PR branch and iterating until the `build` job ran green for real - 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/` entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus `.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running `script/cibuild`, and a README Entrypoints section. `test`/`lint` are a clean `hugo --minify` build; `fmt`/`fmt-check` run prettier over the repo's own top-level markdown only - 2026-02-10: design pass: minimal light theme with inline CSS, grey wells for mesh channels and signal groups, horizontal overflow fix, body width tuning, map link update - 2026-02-10: added README and footer contribute link - 2026-02-10: added Gitea workflow that builds the site and deploys to Cloudflare Pages - 2026-02-08: initial Hugo static site for lora.vegas # Future Steps - Move the artifact actions to v4 once this Gitea Actions instance serves the v4 artifact protocol; they are pinned on the deprecated v3 line because v4 fails here (#20) - Move the deploy container to a pinned node 22 so the wrangler pin can advance past 4.86.0 (#21) - Rework README.md into the standard sections: Description, Getting Started, Rationale, Design, TODO, License, Author (currently About, Contributing, Technical Details, License) - Replace the "content is provided as-is" README note with the text of the committed LICENSE - Expand .gitignore beyond Hugo outputs (OS and editor files) - Verify the Cloudflare Pages deploy still works after the workflow changes - Keep mesh channel and signal group listings current