Add TODO.md with repo policy compliance audit
This commit is contained in:
76
TODO.md
Normal file
76
TODO.md
Normal file
@@ -0,0 +1,76 @@
|
||||
# Workflow
|
||||
|
||||
- branch (from `main`)
|
||||
- do the work in Next Step
|
||||
- move Next Step to the top of Completed Steps
|
||||
- move the top item of Future Steps into Next Step
|
||||
- commit (`TODO.md` changes in the same commit as the work)
|
||||
- merge to `main` if the branch is not protected, otherwise open a PR
|
||||
- push
|
||||
|
||||
# Status
|
||||
|
||||
- pre-1.0
|
||||
|
||||
# Next Step
|
||||
|
||||
- bring the repo into full policy compliance (work the Repo Policy
|
||||
Compliance checklist below)
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- `git init` with README-only first commit; code baseline committed on
|
||||
`main` (2026-07-22)
|
||||
- implement `scan`, `report`, and `trees` subcommands (pre-git history)
|
||||
|
||||
# Future Steps
|
||||
|
||||
- add a remote on git.eeqj.de and push (`main` plus tags)
|
||||
- convert Makefile targets to scripts-to-rule-them-all `script/`
|
||||
entrypoints like the other managed repos
|
||||
- tag `v0.0.1` once the compliance branch is merged
|
||||
- possible later features (explicitly out of scope per README):
|
||||
full-content verification of candidates, removal-script helpers
|
||||
|
||||
# Repo Policy Compliance
|
||||
|
||||
Audited 2026-07-22 against `REPO_POLICIES.md` (2026-07-06), the existing
|
||||
repo checklist, and the Go styleguide. Code is already gofmt-clean, so no
|
||||
standalone formatting commit is needed.
|
||||
|
||||
- [ ] `.gitignore` missing — the compiled `sfdupes` binary and
|
||||
`files.dat` sit untracked in the tree; needs OS/editor/Go
|
||||
artifacts plus secrets patterns
|
||||
- [ ] `.editorconfig` missing
|
||||
- [ ] `LICENSE` missing and README has no License section (MIT assumed
|
||||
from house convention — user to confirm)
|
||||
- [ ] `REPO_POLICIES.md` missing from repo root
|
||||
- [ ] `.golangci.yml` missing (install canonical copy); code must then
|
||||
pass `make lint`
|
||||
- [ ] `Makefile` lacks required targets `test`, `lint`, `fmt`,
|
||||
`fmt-check`, `docker`, `hooks`; `check` currently depends on
|
||||
`build`, which writes the binary (`make check` must not modify
|
||||
files)
|
||||
- [ ] no tests — `go test ./...` has nothing to run; policy requires
|
||||
real tests with a 30-second timeout and the conditional `-v`
|
||||
rerun pattern
|
||||
- [ ] `Dockerfile` missing — Go multistage with hash-pinned images:
|
||||
fail-fast lint stage, build stage running `make check`
|
||||
- [ ] `.dockerignore` missing
|
||||
- [ ] `.gitea/workflows/check.yml` missing (`docker build .` on push,
|
||||
checkout action pinned by commit SHA)
|
||||
- [ ] README lacks required sections: Description first line
|
||||
(name/purpose/category/license/author), Getting Started,
|
||||
Rationale, TODO, License, Author
|
||||
- [ ] README non-goal "no git repository setup and no CI" is stale now
|
||||
that the repo is under git with CI
|
||||
- [ ] pre-commit hook not installed (`make hooks` once the target
|
||||
exists)
|
||||
|
||||
Accepted divergences (no action):
|
||||
|
||||
- flat single-package layout with `.go` files in the repo root — fine
|
||||
for a small single-binary tool per the Go styleguide; the tracker
|
||||
audit agrees
|
||||
- `go test` runs without `-race` — the repo mandates `CGO_ENABLED=0`
|
||||
(pure-Go builds) and the race detector requires cgo
|
||||
Reference in New Issue
Block a user