# Workflow - branch (from `main`) - do the work in Next Step - move Next Step to the top of Completed Steps - move the top item of Future Steps into Next Step - commit (`TODO.md` changes in the same commit as the work) - merge to `main` if the branch is not protected, otherwise open a PR - push # Status pre-1.0 # Next Step Finish the two draft prompt documents in the working tree and commit them: prompts/FIXUP_CLEAN.md (currently a near-empty stub) and prompts/FIXUP_REPORT.md (a rough draft). Write the missing content, run `make fmt` so they pass fmt-check, and commit. # Completed Steps - 2026-08-09: Closed the secret exposure in the canonical `.dockerignore`: a developer's local `.env`, `*.pem` or `*.key` was reaching the Docker build context under `COPY . .`, invisible to every git-based check because `.gitignore` covers it. The patterns are written to `.dockerignore`'s own `filepath.Match` semantics — `**/`-prefixed so they hold at every depth, which also fixes nested `node_modules` — rather than transplanted from `.gitignore`, whose unprefixed form protects only the repository root while reading as solved. `REPO_POLICIES.md` and both repo checklists now state that asymmetry and require verification by enumerating the image rather than by reading the patterns. Verified with a probe image before, against the naive unprefixed form, and after. - 2026-08-09: Made the pinned golangci-lint actually propagate: REPO_POLICIES.md now carries the canonical `script/bootstrap` snippet for Go repos, which installs when the installed version does not match the pin (the old `if missing` guard tested PATH presence only, so pins were inert on any provisioned machine and CI silently disagreed with local) and then re-resolves the binary through `PATH` and fails loudly, naming the shadowing path, when the install did not take effect — the failure mode the naive compare-then-install fix leaves behind while reporting success. - 2026-08-09: Fixed the false green in the canonical CI gate: `script/cibuild` and `script/docker` now pass a per-invocation `CHECK_EPOCH` nonce, and the `Dockerfile` (plus the Go multistage template in REPO_POLICIES.md, in both its lint and builder stages) declares `ARG CHECK_EPOCH` with a guard that makes a bare `docker build .` fail closed. Corrected the org-canonical text that asserted a successful build implies all checks pass, across every document carrying it: `REPO_POLICIES.md`, both repo checklists (which still told agents to write the pre-fix `script/cibuild` and ended on an acceptance item the guard makes unsatisfiable), and the Go styleguide. - 2026-08-07: Set the canonical `.golangci.yml` to the org-standard v2-schema config already deployed byte-identical across the org's Go repos (settings under `linters.settings` so thresholds like lll/funlen/cyclop/dupl actually apply under golangci-lint v2). Recorded the canonical golangci-lint version (v2.12.2, commit-pinned) in REPO_POLICIES.md. - 2026-03-20: Strengthened constructor naming and Params struct rules in the Go styleguide. - 2026-03-18: Documented fail-fast Dockerfile lint stage and conditional -v test rerun patterns in REPO_POLICIES.md. - 2026-03-11: Added HTTP service hardening policy for 1.0 releases. - 2026-03-10: Added policy: no build artifacts in repos. - 2026-03-04: Added LLM prose tells reference and copyediting checklist, then several self-applied revision passes. - 2026-02-28: Expanded the pre-1.0 schema migration rule; added clawpub reference. - 2026-02-23: Added Go style rules (no type-only packages, Stringer for string-based types); template repos section in README. - 2026-02-22: Initial policy corpus: REPO_POLICIES.md, code styleguides (general, Go, JS, Python), repo checklists, CI policy, hash pinning, Go HTTP server conventions, repo scaffolding. # Future Steps - Finish, format, and commit FIXUP_CLEAN.md and FIXUP_REPORT.md (the Next Step). - Commit this TODO.md at the repo root; it is the last missing policy file. - Decide the fate of untracked resume.sh: commit it or delete it. - Add more prompt templates for common development tasks (from README TODO).