diff --git a/TODO.md b/TODO.md new file mode 100644 index 0000000..6633b6e --- /dev/null +++ b/TODO.md @@ -0,0 +1,76 @@ +# Workflow + +- branch (from `main`) +- do the work in Next Step +- move Next Step to the top of Completed Steps +- move the top item of Future Steps into Next Step +- commit (`TODO.md` changes in the same commit as the work) +- merge to `main` if the branch is not protected, otherwise open a PR +- push + +# Status + +- pre-1.0 + +# Next Step + +- bring the repo into full policy compliance (work the Repo Policy + Compliance checklist below) + +# Completed Steps + +- `git init` with README-only first commit; code baseline committed on + `main` (2026-07-22) +- implement `scan`, `report`, and `trees` subcommands (pre-git history) + +# Future Steps + +- add a remote on git.eeqj.de and push (`main` plus tags) +- convert Makefile targets to scripts-to-rule-them-all `script/` + entrypoints like the other managed repos +- tag `v0.0.1` once the compliance branch is merged +- possible later features (explicitly out of scope per README): + full-content verification of candidates, removal-script helpers + +# Repo Policy Compliance + +Audited 2026-07-22 against `REPO_POLICIES.md` (2026-07-06), the existing +repo checklist, and the Go styleguide. Code is already gofmt-clean, so no +standalone formatting commit is needed. + +- [ ] `.gitignore` missing — the compiled `sfdupes` binary and + `files.dat` sit untracked in the tree; needs OS/editor/Go + artifacts plus secrets patterns +- [ ] `.editorconfig` missing +- [ ] `LICENSE` missing and README has no License section (MIT assumed + from house convention — user to confirm) +- [ ] `REPO_POLICIES.md` missing from repo root +- [ ] `.golangci.yml` missing (install canonical copy); code must then + pass `make lint` +- [ ] `Makefile` lacks required targets `test`, `lint`, `fmt`, + `fmt-check`, `docker`, `hooks`; `check` currently depends on + `build`, which writes the binary (`make check` must not modify + files) +- [ ] no tests — `go test ./...` has nothing to run; policy requires + real tests with a 30-second timeout and the conditional `-v` + rerun pattern +- [ ] `Dockerfile` missing — Go multistage with hash-pinned images: + fail-fast lint stage, build stage running `make check` +- [ ] `.dockerignore` missing +- [ ] `.gitea/workflows/check.yml` missing (`docker build .` on push, + checkout action pinned by commit SHA) +- [ ] README lacks required sections: Description first line + (name/purpose/category/license/author), Getting Started, + Rationale, TODO, License, Author +- [ ] README non-goal "no git repository setup and no CI" is stale now + that the repo is under git with CI +- [ ] pre-commit hook not installed (`make hooks` once the target + exists) + +Accepted divergences (no action): + +- flat single-package layout with `.go` files in the repo root — fine + for a small single-binary tool per the Go styleguide; the tracker + audit agrees +- `go test` runs without `-race` — the repo mandates `CGO_ENABLED=0` + (pure-Go builds) and the race detector requires cgo