Check off completed repo policy compliance items in TODO.md

This commit is contained in:
2026-07-23 07:59:12 +07:00
parent 5b20171dbd
commit 3391207f8d

37
TODO.md
View File

@@ -14,18 +14,18 @@
# Next Step
- bring the repo into full policy compliance (work the Repo Policy
Compliance checklist below)
- add a remote on git.eeqj.de and push (`main` plus tags)
# Completed Steps
- bring the repo into full policy compliance (2026-07-23, branch
`repo-policy-compliance`; checklist below)
- `git init` with README-only first commit; code baseline committed on
`main` (2026-07-22)
- implement `scan`, `report`, and `trees` subcommands (pre-git history)
# Future Steps
- add a remote on git.eeqj.de and push (`main` plus tags)
- convert Makefile targets to scripts-to-rule-them-all `script/`
entrypoints like the other managed repos
- tag `v0.0.1` once the compliance branch is merged
@@ -38,33 +38,34 @@ Audited 2026-07-22 against `REPO_POLICIES.md` (2026-07-06), the existing
repo checklist, and the Go styleguide. Code is already gofmt-clean, so no
standalone formatting commit is needed.
- [ ] `.gitignore` missing — the compiled `sfdupes` binary and
- [x] `.gitignore` missing — the compiled `sfdupes` binary and
`files.dat` sit untracked in the tree; needs OS/editor/Go
artifacts plus secrets patterns
- [ ] `.editorconfig` missing
- [ ] `LICENSE` missing and README has no License section (MIT assumed
- [x] `.editorconfig` missing
- [x] `LICENSE` missing and README has no License section (MIT assumed
from house convention — user to confirm)
- [ ] `REPO_POLICIES.md` missing from repo root
- [ ] `.golangci.yml` missing (install canonical copy); code must then
pass `make lint`
- [ ] `Makefile` lacks required targets `test`, `lint`, `fmt`,
- [x] `REPO_POLICIES.md` missing from repo root
- [x] `.golangci.yml` missing (install canonical copy); code must then
pass `make lint` (150 findings fixed; `make lint` is clean)
- [x] `Makefile` lacks required targets `test`, `lint`, `fmt`,
`fmt-check`, `docker`, `hooks`; `check` currently depends on
`build`, which writes the binary (`make check` must not modify
files)
- [ ] no tests — `go test ./...` has nothing to run; policy requires
- [x] no tests — `go test ./...` has nothing to run; policy requires
real tests with a 30-second timeout and the conditional `-v`
rerun pattern
- [ ] `Dockerfile` missing — Go multistage with hash-pinned images:
rerun pattern (suite covers parsing, grouping, digests,
suppression, hashing, and the scan pipeline; 64% coverage)
- [x] `Dockerfile` missing — Go multistage with hash-pinned images:
fail-fast lint stage, build stage running `make check`
- [ ] `.dockerignore` missing
- [ ] `.gitea/workflows/check.yml` missing (`docker build .` on push,
- [x] `.dockerignore` missing
- [x] `.gitea/workflows/check.yml` missing (`docker build .` on push,
checkout action pinned by commit SHA)
- [ ] README lacks required sections: Description first line
- [x] README lacks required sections: Description first line
(name/purpose/category/license/author), Getting Started,
Rationale, TODO, License, Author
- [ ] README non-goal "no git repository setup and no CI" is stale now
- [x] README non-goal "no git repository setup and no CI" is stale now
that the repo is under git with CI
- [ ] pre-commit hook not installed (`make hooks` once the target
- [x] pre-commit hook not installed (`make hooks` once the target
exists)
Accepted divergences (no action):