# Workflow - branch (from `main`) - do the work in Next Step - move Next Step to the top of Completed Steps - move the top item of Future Steps into Next Step - commit (`docs/TODO.md` changes in the same commit as the work) - merge to `main` if the branch is not protected, otherwise open a PR - push # Status pre-1.0. No git tags exist. `main` is a working HTTP service that builds, tests and lints clean: cobra command tree, `fx` object graph, viper configuration that aborts on an unparseable value, sqlite with an embedded schema and a migration runner, embedded templates and static assets, the full middleware chain (request id, logging, metrics, panic recovery, request timeout, body cap, security headers, CSRF), Sentry, and Prometheus `/metrics` behind optional basic auth. This repository is a template. A project seeded from it should replace this Status section and everything below it, keeping the Workflow section above unchanged. # Next Step Replace `gomodguard` with `gomodguard_v2` in `.golangci.yml`. golangci-lint v2.12.2 emits a deprecation warning for it on every run (`the linter 'gomodguard' is deprecated (since v2.12.0) ... Replaced by gomodguard_v2`). Neither is configured with rules here, so the change is to the `linters` block only; done when `make lint` runs clean with no deprecation warning in the output. # Completed Steps - 2026-08-22 Built the template out from an empty repository: STRTA `script/` entrypoints with `Makefile` shims, `Dockerfile` and `Dockerfile.lint` on digest-pinned bases, Gitea workflow running `script/cibuild`, `.golangci.yml`, `.editorconfig`, `.prettierrc`, `docs/REPO_POLICIES.md`, `AGENTS.md`, the HTTP service and its tests, and `script/rename` for seeding # Future Steps - Add a `docker-compose.yml` showing the service behind a TLS-terminating reverse proxy with `X-Forwarded-Proto` set, since that is the deployment shape the CSRF middleware is written for and the one an operator is most likely to get wrong - Add a `script/release` that tags, builds with `VERSION` set, and pushes the image, so `globals.Version` is something other than `dev` in a real deployment - Decide whether the template should ship a session/auth layer or stay deliberately without one