2026-07-18 - 2026-08-18
Overview
2 Pull requests merged by 1 user
Merged
#88 Configure prettier and make fmt-check cover markdown (closes #69)
Merged
#59 Update golangci-lint to v2.12.2 with canonical config (closes #60)
1 Pull request proposed by 1 user
Proposed
#92 1.0.0 milestone
2 Issues closed from 1 user
Closed
#69 Add .prettierrc/.prettierignore, stop reformatting REPO_POLICIES.md, and make fmt-check cover markdown
Closed
#60 Adopt golangci-lint v2.12.2 and the canonical .golangci.yml
32 Issues created by 1 user
Opened
#60 Adopt golangci-lint v2.12.2 and the canonical .golangci.yml
Opened
#61 Validate manifest paths on read, not only on write (path traversal in Checker)
Opened
#62 Enforce real timeouts on gpg subprocess calls
Opened
#63 Harden fetch: client timeout, retry with backoff, url.JoinPath
Opened
#64 Fix -v flag collision between --verbose and --version
Opened
#65 Add fuzz coverage for NewManifestFromReader
Opened
#66 Add real end-to-end tests for the freshen and fetch commands
Opened
#67 Rewrite script/test to the canonical pattern (30s timeout, -race -cover, conditional verbose rerun)
Opened
#68 Pin every developer tool install by hash; make local lint match CI
Opened
#69 Add .prettierrc/.prettierignore, stop reformatting REPO_POLICIES.md, and make fmt-check cover markdown
Opened
#70 Verify Go formatting with gofumpt, not gofmt, so fmt and check agree
Opened
#71 make check must not modify tracked files (ensure_pb regenerates mf.pb.go on mtime)
Opened
#72 Add .editorconfig and make .gitignore comprehensive
Opened
#73 Clean up the Makefile: add make build, remove superseded targets
Opened
#74 Repo root hygiene: move FORMAT.md to docs/, contrib/ to bin/, fix bash script style
Opened
#75 Add the required README sections (Getting Started, Rationale, Design, Author)
Opened
#76 Rewrite the stale TODO tracking in README.md and TODO.md to match reality
Opened
#77 Migrate internal/log from apex/log to log/slog
Opened
#78 Change NewChecker to take a Params struct instead of positional arguments
Opened
#79 DECISION: canonical Go module path for 1.0
Opened
#80 Release mechanics for v1.0.0: version single-sourcing and tag
Opened
#81 DECISION: wire format questions blocking the 1.0 format freeze
Opened
#82 DECISION: signature scheme questions blocking 1.0
Opened
#83 DECISION: public API surface and determinism defaults for 1.0
Opened
#84 Make docs/FORMAT.md a complete, independently-implementable specification
Opened
#85 Stale branch cleanup: three unmerged branches, none worth keeping as-is
Opened
#86 fetch: sanitizePath is purely lexical and does not prevent symlink escape
Opened
#87 Pin CLI error messages through their real call sites, not reconstructed format strings
Opened
#89 script/cibuild reports a green it did not earn: make check is served from Docker cache
Opened
#90 Run all linting in Docker via Dockerfile.lint + script/lint
Opened
#91 TOP PRIORITY: consolidate all open PRs onto one next branch, one PR
Opened
#93 Gitea Actions runner is not picking up jobs: every run since 2026-08-09 is stuck "Waiting to run"