|
|
|
|
@@ -1,6 +1,6 @@
|
|
|
|
|
---
|
|
|
|
|
title: Repository Policies
|
|
|
|
|
last_modified: 2026-09-03
|
|
|
|
|
last_modified: 2026-08-20
|
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
This document covers repository structure, tooling, and workflow standards. Code
|
|
|
|
|
@@ -69,8 +69,15 @@ style conventions are in separate documents:
|
|
|
|
|
outputs the project's name. Scripts that need the name call
|
|
|
|
|
`script/projectname` — e.g. `script/docker` assembles its image tag from it —
|
|
|
|
|
so those scripts stay byte-identical across all repos. Repo-type-specific
|
|
|
|
|
pre-commit extras (e.g. `go mod tidy` verification in Go repos) belong in
|
|
|
|
|
`script/precommit`, not in the hook itself. Model scripts are at
|
|
|
|
|
verifications (e.g. `go mod tidy` verification in Go repos) belong in
|
|
|
|
|
`script/check`, which is the gate the other entrypoints funnel through: it
|
|
|
|
|
runs in the Dockerfile build step and therefore in CI, and `script/precommit`
|
|
|
|
|
inherits it by calling `script/check`. In `script/precommit` alone such a
|
|
|
|
|
check binds only the contributors who installed the hook, and the hook file
|
|
|
|
|
itself stays a shim that carries no checks of its own. Anything added to
|
|
|
|
|
`script/check` must be read-only, since `make check` must not modify files, so
|
|
|
|
|
use a verify or diff mode (`go mod tidy -diff`) rather than a command that
|
|
|
|
|
rewrites the tree. Model scripts are at
|
|
|
|
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/script/<name>`. The README
|
|
|
|
|
must document the provided scripts in an **Entrypoints** section (see the
|
|
|
|
|
README requirements below).
|
|
|
|
|
@@ -214,16 +221,11 @@ style conventions are in separate documents:
|
|
|
|
|
|
|
|
|
|
```makefile
|
|
|
|
|
test:
|
|
|
|
|
@go test -count=1 -timeout 90s -race -cover ./... || \
|
|
|
|
|
@go test -timeout 90s -race -cover ./... || \
|
|
|
|
|
{ echo "--- Rerunning with -v for details ---"; \
|
|
|
|
|
go test -count=1 -timeout 90s -race -v ./...; exit 1; }
|
|
|
|
|
go test -timeout 90s -race -v ./...; exit 1; }
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
`-count=1` is required on both invocations: it defeats Go's test _result_
|
|
|
|
|
cache, so the target cannot report a pass it did not earn, and the rerun
|
|
|
|
|
reproduces a failure instead of replaying it. It leaves the build cache
|
|
|
|
|
alone, so it costs the runtime of the suite and no recompilation.
|
|
|
|
|
|
|
|
|
|
Python example:
|
|
|
|
|
|
|
|
|
|
```makefile
|
|
|
|
|
@@ -268,14 +270,11 @@ style conventions are in separate documents:
|
|
|
|
|
- Make all changes on a feature branch. You can do whatever you want on a
|
|
|
|
|
feature branch.
|
|
|
|
|
|
|
|
|
|
- `.golangci.yml` is standardized. The vendored copy in a consuming repo must
|
|
|
|
|
_NEVER_ be modified by an agent: fetch it from
|
|
|
|
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml` and keep it
|
|
|
|
|
byte-identical, so that no repo can quietly loosen its own linting. Linter
|
|
|
|
|
configuration changes are made to the canonical copy in the `prompts` repo and
|
|
|
|
|
reach consuming repos by re-vendoring; an agent may open a PR against
|
|
|
|
|
canonical, which only the user merges. The canonical golangci-lint version is
|
|
|
|
|
v2.12.2 (released 2026-05-06), installed commit-pinned via
|
|
|
|
|
- `.golangci.yml` is standardized and must _NEVER_ be modified by an agent, only
|
|
|
|
|
manually by the user. Fetch from
|
|
|
|
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`. The
|
|
|
|
|
canonical golangci-lint version is v2.12.2 (released 2026-05-06), installed
|
|
|
|
|
commit-pinned via
|
|
|
|
|
`go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5`.
|
|
|
|
|
|
|
|
|
|
- When pinning images or packages by hash, add a comment above the reference
|
|
|
|
|
@@ -395,9 +394,7 @@ style conventions are in separate documents:
|
|
|
|
|
language-specific config). Everything else goes in a subdirectory. Canonical
|
|
|
|
|
subdirectory names:
|
|
|
|
|
- `bin/` — executable scripts and tools
|
|
|
|
|
- `cmd/` — Go command entrypoints; thin only: one `main.go` per binary whose
|
|
|
|
|
body is a single call into `internal/` or `pkg/`, no project logic in
|
|
|
|
|
`cmd/`
|
|
|
|
|
- `cmd/` — Go command entrypoints
|
|
|
|
|
- `configs/` — configuration templates and examples
|
|
|
|
|
- `deploy/` — deployment manifests (k8s, compose, terraform)
|
|
|
|
|
- `docs/` — documentation and markdown (README.md stays in root)
|
|
|
|
|
|