Replaces #35, #39 and #60. Their per-repo steps were written against canonical files that have since changed, and following them now would undo current policy:
CHECK_EPOCH is gone: every docker build in script/ passes --no-cache.
golangci-lint runs only in the Docker lint phase. Nothing installs it on the host, so the bootstrap version check and the lint cache isolation for a host linter no longer apply.
.dockerignore sends .git without its config, and the version comes from git describe inside the build unless a VERSION build argument is given. The old rule excluded .git and passed the version in from the host.
The canonical .golangci.yml changes again with #65, so its sha256 in issue 60 is out of date.
When to start
Start a repository only once #65 has reached main, so each repository re-vendors once.
Per-repo definition of done
Fetch every canonical file the repository vendors from https://git.eeqj.de/sneak/prompts/raw/branch/main/<path>, never by hand-editing the old copy: REPO_POLICIES.md, .golangci.yml (Go repositories), .dockerignore, .gitignore, .editorconfig, .prettierrc, and any checklist or styleguide it carries.
Bring Dockerfile, Makefile and script/ in line with what REPO_POLICIES.md on main says, including the gate phases and the version step.
Carry forward the repository's own entries, the only parts exempt from byte-identity: its deny entries in the test-support depguard rule of .golangci.yml, its anchored host-built artifacts in .dockerignore, and its language's entries in .gitignore and .editorconfig (for Go, at least *.log, *.out, *.test and its binaries, per prompts/CODE_STYLEGUIDE_GO.md, and tabs for *.go), kept after the canonical content.
Land green. If the new files produce findings, the same PR fixes the code; never loosen a vendored file (sneak's ruling of 2026-09-09 on issue 60). Stop and ask only for a judgement an implementer cannot make.
make lint runs with zero deprecation warnings.
Repositories
Each repository's manager confirms applicability first; a repository that vendors nothing ticks with a note.
homoicon's vendored .golangci.yml carries a header comment for the owner-approved edit under sneak/homoicon#4; carry it forward.
Model: opus-5-5
Replaces https://git.eeqj.de/sneak/prompts/issues/35, https://git.eeqj.de/sneak/prompts/issues/39 and https://git.eeqj.de/sneak/prompts/issues/60. Their per-repo steps were written against canonical files that have since changed, and following them now would undo current policy:
- `CHECK_EPOCH` is gone: every `docker build` in `script/` passes `--no-cache`.
- golangci-lint runs only in the Docker lint phase. Nothing installs it on the host, so the bootstrap version check and the lint cache isolation for a host linter no longer apply.
- `.dockerignore` sends `.git` without its config, and the version comes from `git describe` inside the build unless a `VERSION` build argument is given. The old rule excluded `.git` and passed the version in from the host.
- The canonical `.golangci.yml` changes again with https://git.eeqj.de/sneak/prompts/issues/65, so its sha256 in issue 60 is out of date.
## When to start
Start a repository only once https://git.eeqj.de/sneak/prompts/issues/65 has reached `main`, so each repository re-vendors once.
## Per-repo definition of done
1. Fetch every canonical file the repository vendors from `https://git.eeqj.de/sneak/prompts/raw/branch/main/<path>`, never by hand-editing the old copy: `REPO_POLICIES.md`, `.golangci.yml` (Go repositories), `.dockerignore`, `.gitignore`, `.editorconfig`, `.prettierrc`, and any checklist or styleguide it carries.
2. Bring `Dockerfile`, `Makefile` and `script/` in line with what `REPO_POLICIES.md` on `main` says, including the gate phases and the version step.
3. Carry forward the repository's own entries, the only parts exempt from byte-identity: its `deny` entries in the `test-support` depguard rule of `.golangci.yml`, its anchored host-built artifacts in `.dockerignore`, and its language's entries in `.gitignore` and `.editorconfig` (for Go, at least `*.log`, `*.out`, `*.test` and its binaries, per `prompts/CODE_STYLEGUIDE_GO.md`, and tabs for `*.go`), kept after the canonical content.
4. Land green. If the new files produce findings, the same PR fixes the code; never loosen a vendored file (sneak's ruling of 2026-09-09 on issue 60). Stop and ask only for a judgement an implementer cannot make.
5. `make lint` runs with zero deprecation warnings.
## Repositories
Each repository's manager confirms applicability first; a repository that vendors nothing ticks with a note.
- [ ] api: https://git.eeqj.de/sneak/api/issues/13
- [ ] attrsum: https://git.eeqj.de/sneak/attrsum/issues/13
- [x] AutistMask: https://git.eeqj.de/sneak/AutistMask/issues/472
- [x] bsfirehose: https://git.eeqj.de/sneak/bsfirehose/issues/67
- [ ] cattbox: https://git.eeqj.de/sneak/cattbox/issues/55
- [ ] clawhook: https://git.eeqj.de/sneak/clawhook/issues/9
- [ ] clawpub: https://git.eeqj.de/sneak/clawpub/issues/9
- [ ] currentstat.us: https://git.eeqj.de/sneak/currentstat.us/issues/65
- [x] dnswatcher: https://git.eeqj.de/sneak/dnswatcher/issues/257
- [ ] gohttpserver: https://git.eeqj.de/sneak/gohttpserver/issues/27
- [ ] homoicon: https://git.eeqj.de/sneak/homoicon/issues/1484
- [ ] imaptagger: https://git.eeqj.de/sneak/imaptagger/issues/31
- [x] jekyllsitebuilder: vendors none of the canonical files
- [ ] lora.vegas: https://git.eeqj.de/sneak/lora.vegas/issues/45
- [x] mfer: https://git.eeqj.de/sneak/mfer/issues/159
- [ ] neoirc: https://git.eeqj.de/sneak/neoirc/issues/112
- [ ] netwatch: https://git.eeqj.de/sneak/netwatch/issues/113
- [ ] pixa: https://git.eeqj.de/sneak/pixa/issues/221
- [ ] quak: https://git.eeqj.de/sneak/quak/issues/171
- [ ] rfscan: https://git.eeqj.de/sneak/rfscan/issues/78
- [ ] rgoue: https://git.eeqj.de/sneak/rgoue/issues/50
- [ ] routewatch: https://git.eeqj.de/sneak/routewatch/issues/52
- [ ] rtnetmon: https://git.eeqj.de/sneak/rtnetmon/issues/17
- [ ] secret: https://git.eeqj.de/sneak/secret/issues/121
- [ ] sfdupes: https://git.eeqj.de/sneak/sfdupes/issues/95
- [ ] simplelog: https://git.eeqj.de/sneak/simplelog/issues/33
- [x] smallwebwaf: https://git.eeqj.de/sneak/smallwebwaf/issues/65
- [ ] smartconfig: https://git.eeqj.de/sneak/smartconfig/issues/2
- [ ] sneak.berlin: https://git.eeqj.de/sneak/sneak.berlin/issues/244
- [ ] upaas: https://git.eeqj.de/sneak/upaas/issues/277
- [ ] vaultik: https://git.eeqj.de/sneak/vaultik/issues/213
- [x] webhooker: https://git.eeqj.de/sneak/webhooker/issues/504
`homoicon`'s vendored `.golangci.yml` carries a header comment for the owner-approved edit under https://git.eeqj.de/sneak/homoicon/issues/4; carry it forward.
Model: opus-5-5
Plan. Every repository re-vendors once, from sneak/prompts commit dd4027b (dd4027b907), which holds every canonical change reviewed so far. Each fetches https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>, so every repository ends up with the same bytes.
One issue per consuming repository, filed now in that repository: this issue's definition of done, the list of canonical files it vendors, and what changed that matters to it. That repository's manager runs it as one reviewed PR. The list above links each issue; a repository is ticked when its issue closes.
bsfirehose already has sneak/bsfirehose#67; it is pointed at the same commit.
jekyllsitebuilder vendors none of the canonical files: ticked now with that note.
Trap, written into every issue: the root REPO_POLICIES.md here is a symlink, and its raw URL returns only the link's target path. The file comes from prompts/REPO_POLICIES.md. This repository's .gitattributes and TODO.md are its own, not canonical.
Deviation from the body above: the source is a fixed commit rather than a branch URL, and work starts now.
This issue closes when every repository is ticked.
Model: opus-5-5
Plan. Every repository re-vendors once, from `sneak/prompts` commit `dd4027b` (https://git.eeqj.de/sneak/prompts/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc), which holds every canonical change reviewed so far. Each fetches `https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>`, so every repository ends up with the same bytes.
- One issue per consuming repository, filed now in that repository: this issue's definition of done, the list of canonical files it vendors, and what changed that matters to it. That repository's manager runs it as one reviewed PR. The list above links each issue; a repository is ticked when its issue closes.
- `bsfirehose` already has https://git.eeqj.de/sneak/bsfirehose/issues/67; it is pointed at the same commit.
- `jekyllsitebuilder` vendors none of the canonical files: ticked now with that note.
- Trap, written into every issue: the root `REPO_POLICIES.md` here is a symlink, and its raw URL returns only the link's target path. The file comes from `prompts/REPO_POLICIES.md`. This repository's `.gitattributes` and `TODO.md` are its own, not canonical.
Deviation from the body above: the source is a fixed commit rather than a branch URL, and work starts now.
This issue closes when every repository is ticked.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 01:28:40 +02:00
Corrections from the first re-vendors (smallwebwaf, bsfirehose, dnswatcher), applied to item 3 of every per-repository issue and to the body above:
.gitignore and .editorconfig are a base each repository extends: a re-vendor keeps the repository's own entries after the canonical content (for Go, at least *.log, *.out, *.test, its binaries, and tabs for *.go). Canonical wording: #103.
Where a repository's copy of a canonical file has a setting the canonical copy lacks and dropping it would weaken a check or a security setting, the repository keeps it as a disclosed deviation and reports it here, so the canonical copy gets it. Found so far: the workflow's concurrency block and persist-credentials: false (#107).
Not a re-vendor change but found during one: canonicalheader misses findings at random (#105). Repositories vendor .golangci.yml from the commit above as it is.
Model: opus-5-5
Corrections from the first re-vendors (`smallwebwaf`, `bsfirehose`, `dnswatcher`), applied to item 3 of every per-repository issue and to the body above:
- `.gitignore` and `.editorconfig` are a base each repository extends: a re-vendor keeps the repository's own entries after the canonical content (for Go, at least `*.log`, `*.out`, `*.test`, its binaries, and tabs for `*.go`). Canonical wording: https://git.eeqj.de/sneak/prompts/issues/103.
- Where a repository's copy of a canonical file has a setting the canonical copy lacks and dropping it would weaken a check or a security setting, the repository keeps it as a disclosed deviation and reports it here, so the canonical copy gets it. Found so far: the workflow's `concurrency` block and `persist-credentials: false` (https://git.eeqj.de/sneak/prompts/issues/107).
- Not a re-vendor change but found during one: `canonicalheader` misses findings at random (https://git.eeqj.de/sneak/prompts/issues/105). Repositories vendor `.golangci.yml` from the commit above as it is.
Model: opus-5-5
webhooker re-vendored in sneak/webhooker#505 (closes sneak/webhooker#504). One kept deviation, per the correction in comment 127511: .dockerignore keeps **/*.db, **/*.sqlite and **/*.sqlite3 after the shared content, since the canonical copy lacks them and without them a SQLite database in the checkout (here one holds the session key and webhook payloads) is sent into the build context.
Model: opus-5-5
webhooker re-vendored in https://git.eeqj.de/sneak/webhooker/pulls/505 (closes https://git.eeqj.de/sneak/webhooker/issues/504). One kept deviation, per the correction in comment 127511: `.dockerignore` keeps `**/*.db`, `**/*.sqlite` and `**/*.sqlite3` after the shared content, since the canonical copy lacks them and without them a SQLite database in the checkout (here one holds the session key and webhook payloads) is sent into the build context.
Model: opus-5-5
Every unit in sneak/prompts that this re-vendor raised has landed, so the sneak/prompts manager stops here. From now on each repository's manager ticks its own line above when its re-vendor PR merges. Repositories that re-vendor after these landed may take the newer canonical files from the current head of this repository's development branch instead of dd4027b: they add the .gitignore and .editorconfig sections for a repository's own entries, the disabled canonicalheader, the workflow's concurrency, persist-credentials: false and fetch-depth: 0, and the apt-get update in script/bootstrap.
Model: opus-5-5
Every unit in `sneak/prompts` that this re-vendor raised has landed, so the `sneak/prompts` manager stops here. From now on each repository's manager ticks its own line above when its re-vendor PR merges. Repositories that re-vendor after these landed may take the newer canonical files from the current head of this repository's development branch instead of `dd4027b`: they add the `.gitignore` and `.editorconfig` sections for a repository's own entries, the disabled `canonicalheader`, the workflow's `concurrency`, `persist-credentials: false` and `fetch-depth: 0`, and the `apt-get update` in `script/bootstrap`.
Model: opus-5-5
For repositories that have not re-vendored yet: with uncached builds, larger Go repositories go over the 60-second make test limit before any test runs (homoicon about three minutes, bsfirehose 158 s). That conflict is with the owner on #113. Meanwhile:
If make test (and in homoicon make check) stays under 60 seconds on this host after the re-vendor, land it as usual.
If it goes over, keep the PR open and say so in its body, and go on with other work until that issue is answered. Do not drop -race or other checks, add caching, or change the vendored build files to get under the limit; that gets fixed here.
#123 stops the lint and test builds writing an image, which saves about 16 s per build. Once it is on next here, take script/lint, script/test and REPO_POLICIES.md from next.
Model: opus-5-5
For repositories that have not re-vendored yet: with uncached builds, larger Go repositories go over the 60-second `make test` limit before any test runs (homoicon about three minutes, bsfirehose 158 s). That conflict is with the owner on https://git.eeqj.de/sneak/prompts/issues/113. Meanwhile:
- If `make test` (and in homoicon `make check`) stays under 60 seconds on this host after the re-vendor, land it as usual.
- If it goes over, keep the PR open and say so in its body, and go on with other work until that issue is answered. Do not drop `-race` or other checks, add caching, or change the vendored build files to get under the limit; that gets fixed here.
- https://git.eeqj.de/sneak/prompts/issues/123 stops the lint and test builds writing an image, which saves about 16 s per build. Once it is on `next` here, take `script/lint`, `script/test` and `REPO_POLICIES.md` from `next`.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Replaces #35, #39 and #60. Their per-repo steps were written against canonical files that have since changed, and following them now would undo current policy:
CHECK_EPOCHis gone: everydocker buildinscript/passes--no-cache..dockerignoresends.gitwithout its config, and the version comes fromgit describeinside the build unless aVERSIONbuild argument is given. The old rule excluded.gitand passed the version in from the host..golangci.ymlchanges again with #65, so its sha256 in issue 60 is out of date.When to start
Start a repository only once #65 has reached
main, so each repository re-vendors once.Per-repo definition of done
https://git.eeqj.de/sneak/prompts/raw/branch/main/<path>, never by hand-editing the old copy:REPO_POLICIES.md,.golangci.yml(Go repositories),.dockerignore,.gitignore,.editorconfig,.prettierrc, and any checklist or styleguide it carries.Dockerfile,Makefileandscript/in line with whatREPO_POLICIES.mdonmainsays, including the gate phases and the version step.denyentries in thetest-supportdepguard rule of.golangci.yml, its anchored host-built artifacts in.dockerignore, and its language's entries in.gitignoreand.editorconfig(for Go, at least*.log,*.out,*.testand its binaries, perprompts/CODE_STYLEGUIDE_GO.md, and tabs for*.go), kept after the canonical content.make lintruns with zero deprecation warnings.Repositories
Each repository's manager confirms applicability first; a repository that vendors nothing ticks with a note.
homoicon's vendored.golangci.ymlcarries a header comment for the owner-approved edit under sneak/homoicon#4; carry it forward.Model: opus-5-5
Plan. Every repository re-vendors once, from
sneak/promptscommitdd4027b(dd4027b907), which holds every canonical change reviewed so far. Each fetcheshttps://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>, so every repository ends up with the same bytes.bsfirehosealready has sneak/bsfirehose#67; it is pointed at the same commit.jekyllsitebuildervendors none of the canonical files: ticked now with that note.REPO_POLICIES.mdhere is a symlink, and its raw URL returns only the link's target path. The file comes fromprompts/REPO_POLICIES.md. This repository's.gitattributesandTODO.mdare its own, not canonical.Deviation from the body above: the source is a fixed commit rather than a branch URL, and work starts now.
This issue closes when every repository is ticked.
Model: opus-5-5
Corrections from the first re-vendors (
smallwebwaf,bsfirehose,dnswatcher), applied to item 3 of every per-repository issue and to the body above:.gitignoreand.editorconfigare a base each repository extends: a re-vendor keeps the repository's own entries after the canonical content (for Go, at least*.log,*.out,*.test, its binaries, and tabs for*.go). Canonical wording: #103.concurrencyblock andpersist-credentials: false(#107).canonicalheadermisses findings at random (#105). Repositories vendor.golangci.ymlfrom the commit above as it is.Model: opus-5-5
webhooker re-vendored in sneak/webhooker#505 (closes sneak/webhooker#504). One kept deviation, per the correction in comment 127511:
.dockerignorekeeps**/*.db,**/*.sqliteand**/*.sqlite3after the shared content, since the canonical copy lacks them and without them a SQLite database in the checkout (here one holds the session key and webhook payloads) is sent into the build context.Model: opus-5-5
Every unit in
sneak/promptsthat this re-vendor raised has landed, so thesneak/promptsmanager stops here. From now on each repository's manager ticks its own line above when its re-vendor PR merges. Repositories that re-vendor after these landed may take the newer canonical files from the current head of this repository's development branch instead ofdd4027b: they add the.gitignoreand.editorconfigsections for a repository's own entries, the disabledcanonicalheader, the workflow'sconcurrency,persist-credentials: falseandfetch-depth: 0, and theapt-get updateinscript/bootstrap.Model: opus-5-5
For repositories that have not re-vendored yet: with uncached builds, larger Go repositories go over the 60-second
make testlimit before any test runs (homoicon about three minutes, bsfirehose 158 s). That conflict is with the owner on #113. Meanwhile:make test(and in homoiconmake check) stays under 60 seconds on this host after the re-vendor, land it as usual.-raceor other checks, add caching, or change the vendored build files to get under the limit; that gets fixed here.nexthere, takescript/lint,script/testandREPO_POLICIES.mdfromnext.Model: opus-5-5