Add the standard scaffold and bring the tree to a clean lint under the vendored `default: all` config. New: `script/` Scripts-to-Rule-Them-All entrypoints with the `Makefile` reduced to thin shims; a `Dockerfile` whose `lint` and `test` phases gate the build (final stage depends on both); a `.gitea/workflows/` CI running `script/cibuild`; the vendored `.golangci.yml`; `REPO_POLICIES.md`; `.editorconfig`; `.dockerignore`; a `LICENSE` (WTFPL) and `TODO.md`; and a comprehensive `.gitignore`. The 211 lint findings were fixed, not suppressed: package-level state became functions/fields/a command constructor, magic numbers became named constants, `ctx` is threaded into the probes, the loop functions were split to cut complexity, and the deprecated `+build` tags were dropped. Behavior is unchanged. The only annotations are justified `//nolint:gosec` on the `ping`/`curl` subprocess calls (G204, fixed argv) and the operator-chosen log file (G304), matching the reference repos. `make check` is green (lint and tests run in Docker). Model: opus-4-8
1.8 KiB
Workflow
One issue per unit of work, one branch and one PR per issue:
- ensure a tracked issue exists with a definition of done
- branch from
next(never frommain) - do the work; open a PR based on
next(never onmain) - pass an independent review, then the change is squash-merged into
next - push; nothing stays local-only
next is the branch for the next milestone and must stay green and
mergeable to main without notice. Only sneak merges next into
main, and for now only sneak merges into next. No commits land
directly on main or next — only merges via PRs.
Issue branches do NOT touch this file — it is maintained on next.
Every branch editing TODO.md conflicts with every other.
Status
The repository has been brought up to current repo standards: script/
Scripts to Rule Them All entrypoints with the Makefile reduced to thin
shims, a Dockerfile whose lint and test phases gate the build, a
.gitea/workflows/ CI workflow running script/cibuild, the vendored
.golangci.yml, REPO_POLICIES.md, .editorconfig, .dockerignore, a
LICENSE file, and a comprehensive .gitignore.
Lint is clean under the standard default: all configuration, with the
findings fixed rather than suppressed. The only annotations are
justified //nolint:gosec on the ping/curl subprocess calls (G204)
and on opening the operator-chosen log file (G304): fixed argv with no
shell, so these are false positives, annotated as the reference repos do.
Next Step
Feature work, each on its own branch and PR from next: