# Workflow * branch (from `main`) * do the work in Next Step * move Next Step to the top of Completed Steps * move the top item of Future Steps into Next Step * commit (`TODO.md` changes in the same commit as the work) * merge to `main` if the branch is not protected, otherwise open a PR * push # Status pre-1.0. No git tags. TODO.md carries open 1.0 security blockers. Work in flight on branch secure-enclave-unlocker (clean tree as of 2026-07-06). # Next Step Bring the repo into policy compliance in one commit: - Add fmt-check and hooks targets to the Makefile (test/lint/fmt/check/ docker already exist). - Add REPO_POLICIES.md and .editorconfig. - Add .gitea/workflows/check.yml running make check. - Verify Dockerfile base images are pinned by sha256. # Completed Steps - 2026-10-04: The next command that takes the state directory lock deletes what commands killed part-way left under a `.tmp-` name (https://git.eeqj.de/sneak/secret/issues/75): the temporary directories of `secret.TempDirFor` and the temporary files of `secret.WriteFileAtomic`, in the state directory, each vault, each secret and each version, the only directories those make them in. Before, they stayed, encrypted keys included, until deleted by hand. A command that only reads takes no lock and deletes nothing. A failure to delete is warned about and the command goes on. An unlocker directory with no metadata file was already removed by `secret unlocker remove` given its directory name; a test now shows it. - 2026-10-04: A crash while an unlocker is being replaced no longer leaves a current unlocker that cannot open the vault (https://git.eeqj.de/sneak/secret/issues/71). Every new unlocker gets a directory of its own, named with the time to the nanosecond: `passphrase-