Files
prompts/TODO.md
sneak a8905f5fe7 Keep secrets out of the Docker build context at every depth (closes #29)
The canonical .dockerignore was three lines while the canonical
Dockerfile does `COPY . .`, so a local .env, *.pem or *.key shipped into
the build context and could land in an image layer, invisible to every
git-based check. Copying .gitignore's patterns across is not the repair:
.dockerignore anchors an unprefixed pattern at the context root, so that
form protects only the repository root while reading as solved. Every
depth-independent pattern here carries `**/`, and secret names are
character ranges because matching is case-sensitive and an ALL-CAPS twin
still misses `Server.Key`. Public certificates are deliberately left in
as a legitimate build input. Verified by enumerating a probe image.

Model: opus-5
2026-09-08 04:58:31 +00:00

3.2 KiB

Workflow

  • branch (from main)
  • do the work in Next Step
  • move Next Step to the top of Completed Steps
  • move the top item of Future Steps into Next Step
  • commit (TODO.md changes in the same commit as the work)
  • merge to main if the branch is not protected, otherwise open a PR
  • push

Status

pre-1.0

Next Step

Finish the two draft prompt documents in the working tree and commit them: prompts/FIXUP_CLEAN.md (currently a near-empty stub) and prompts/FIXUP_REPORT.md (a rough draft). Write the missing content, run make fmt so they pass fmt-check, and commit.

Completed Steps

  • 2026-09-08: Closed the secret exposure in the canonical .dockerignore: a local .env, *.pem or *.key was reaching the build context under COPY . ., invisible to every git-based check. The patterns are now written to .dockerignore's own semantics — **/-prefixed so they hold at every depth, case-folded with character ranges — and REPO_POLICIES.md requires verifying by enumerating the image rather than by reading the file.
  • 2026-09-08: Made a pinned tool in script/bootstrap actually reach the host. REPO_POLICIES.md now requires comparing the installed version against the pin rather than testing PATH presence, and re-resolving the binary through PATH after installing, so a version bump cannot be a silent no-op and a shadowed install cannot report success.
  • 2026-09-08: Closed the false green in the canonical CI gate: script/cibuild and script/docker now build with --no-cache, so the Dockerfile's check layers cannot be served from cache on an unchanged tree, and the text claiming a bare docker build . proves the checks ran is corrected in REPO_POLICIES.md, both checklists and the Go styleguide.
  • 2026-08-07: Set the canonical .golangci.yml to the org-standard v2-schema config already deployed byte-identical across the org's Go repos (settings under linters.settings so thresholds like lll/funlen/cyclop/dupl actually apply under golangci-lint v2). Recorded the canonical golangci-lint version (v2.12.2, commit-pinned) in REPO_POLICIES.md.
  • 2026-03-20: Strengthened constructor naming and Params struct rules in the Go styleguide.
  • 2026-03-18: Documented fail-fast Dockerfile lint stage and conditional -v test rerun patterns in REPO_POLICIES.md.
  • 2026-03-11: Added HTTP service hardening policy for 1.0 releases.
  • 2026-03-10: Added policy: no build artifacts in repos.
  • 2026-03-04: Added LLM prose tells reference and copyediting checklist, then several self-applied revision passes.
  • 2026-02-28: Expanded the pre-1.0 schema migration rule; added clawpub reference.
  • 2026-02-23: Added Go style rules (no type-only packages, Stringer for string-based types); template repos section in README.
  • 2026-02-22: Initial policy corpus: REPO_POLICIES.md, code styleguides (general, Go, JS, Python), repo checklists, CI policy, hash pinning, Go HTTP server conventions, repo scaffolding.

Future Steps

  • Finish, format, and commit FIXUP_CLEAN.md and FIXUP_REPORT.md (the Next Step).
  • Commit this TODO.md at the repo root; it is the last missing policy file.
  • Decide the fate of untracked resume.sh: commit it or delete it.
  • Add more prompt templates for common development tasks (from README TODO).