The shared files are the copies at sneak/prompts commit dd4027b, with this
repository's own entries kept after them. script/lint, script/test and
REPO_POLICIES.md come from its next at c55a0cb, so the lint and test
builds write no image. golangci-lint is v2.14.0 and raises no findings.
Lint and test are phases of the Dockerfile; the tests run under the race
detector as nobody, so Dockerfile.lint, script/verify-lint-image-pin and
make test-race are gone. Every docker build in script/ passes --no-cache.
Formatting runs on the host: script/bootstrap installs the pinned node and
yarn, and the prettier and markdown stages are gone. .claude/settings.json
is deleted.
Deviation: the workflow keeps fetch-depth: 0.
Deviation: .gitignore keeps the scan database patterns.
Over the cap: make test takes 82 to 100 seconds on this host.
Model: opus-5-5
The vendored copy had drifted to 368 lines against the canonical 408
while still declaring `last_modified: 2026-07-06`, so nothing about the
file signalled that it was stale. Agents working in this repo read the
vendored copy to learn the rules, which makes a silent 40-line gap a
source of real defects rather than untidiness: two have already been
traced to exactly this drift, `script/fmt` having dropped the prettier
Markdown pass (#19, still open) and the README having no Entrypoints
section (#21, since fixed).
Restored by copying the canonical file wholesale — no hand-editing, no
partial merge, no local adaptation, because it is a vendored copy and
its value comes from matching upstream byte for byte. What comes back:
- the entire Scripts to Rule Them All section, including the POSIX sh
requirement, the repo-root discovery idiom, and the division between
the standard's canonical scripts and our four extensions
- `bootstrap`, `setup` and `hooks` in the required Makefile target list
- the `script/precommit` paragraph and how the pre-commit hook is wired
through `script/install-precommit`
- the README **Entrypoints** section requirement
- the Dockerfile bootstrap-layer guidance and the `script/cibuild`
wording in the Gitea Actions bullet
Verified: `diff` against the canonical file is empty, sha256 is
117dde7f148ed3cd693b333312f6345a0a0ee84fadbbe5cca559ca6fed4a1775, and
`REPO_POLICIES.md` is the only changed path. `make check` is green.
No `TODO.md` entry accompanies this commit. The repo convention is to
record the work in the same commit, but the issue's definition of done
restricts the change to `REPO_POLICIES.md` alone; that scope discipline
is what lets a docs-only change skip adversarial review.