Vendor pinned prettier/format toolchain from prompts scaffold (closes #203)
Check / check (pull_request) Skipped
Check / check (pull_request) Skipped
Replace the unpinned `npx prettier --tab-width 4` in `script/fmt` with the canonical toolchain vendored from `sneak/prompts`: `.prettierrc` (tabWidth 4, proseWrap always), pinned `package.json` + `yarn.lock` (prettier 3.8.1), and a `.prettierignore` that unions the scaffold entries with the repo's `*.min.js` line. `script/bootstrap` now installs a pinned node/yarn via a hash-verified nvm release archive (never curl-pipe-sh), so prettier stops being an unpinned host tool. `script/fmt` runs the pinned prettier via `.prettierrc` over `static/js/*.js` and `**/*.md`, keeping gofmt/goimports. All existing markdown is reflowed to house style; `static/js/alpine.min.js` stays byte-identical. Model: opus-4-8
This commit is contained in:
@@ -1,70 +1,75 @@
|
||||
# Workflow
|
||||
|
||||
* branch (from `main`)
|
||||
* do the work in Next Step
|
||||
* move Next Step to the top of Completed Steps
|
||||
* move the top item of Future Steps into Next Step
|
||||
* commit (`TODO.md` changes in the same commit as the work)
|
||||
* merge to `main` if the branch is not protected, otherwise open a PR
|
||||
* push
|
||||
- branch (from `main`)
|
||||
- do the work in Next Step
|
||||
- move Next Step to the top of Completed Steps
|
||||
- move the top item of Future Steps into Next Step
|
||||
- commit (`TODO.md` changes in the same commit as the work)
|
||||
- merge to `main` if the branch is not protected, otherwise open a PR
|
||||
- push
|
||||
|
||||
# Status
|
||||
|
||||
1.0+. Tagged 1.0.0 on 2026-02-26; 8 commits on main since. `make check`
|
||||
is green as of the golangci-lint v2.12.2 update.
|
||||
1.0+. Tagged 1.0.0 on 2026-02-26; 8 commits on main since. `make check` is green
|
||||
as of the golangci-lint v2.12.2 update.
|
||||
|
||||
# Next Step
|
||||
|
||||
Confirm `.gitea/workflows/check.yml` gates merges on `make check` so
|
||||
main cannot regress.
|
||||
Confirm `.gitea/workflows/check.yml` gates merges on `make check` so main cannot
|
||||
regress.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-22: Vendored the canonical prettier/format toolchain from the
|
||||
`sneak/prompts` scaffold: added `.prettierrc` (tabWidth 4, proseWrap always),
|
||||
pinned `package.json` + `yarn.lock` (prettier 3.8.1), taught
|
||||
`script/bootstrap` to install a pinned node/yarn via a hash-verified nvm
|
||||
archive, and switched `script/fmt` to the pinned prettier reading
|
||||
`.prettierrc` (no inline flags) over `static/js/*.js` and `**/*.md`. Reflowed
|
||||
all markdown to house style; `alpine.min.js` stays byte-identical (#203).
|
||||
- 2026-09-22: Fixed the flaky `t.TempDir` cleanup race in
|
||||
`internal/service/webhook` by tracking the async deployment goroutine
|
||||
in a `sync.WaitGroup` and exposing `WaitForDeployments`; tests now
|
||||
synchronize on completion instead of sleeping (#198).
|
||||
- 2026-09-22: Linting now runs only in Docker. Added `Dockerfile.lint`
|
||||
(pinned golangci-lint v2.12.2, cache-busted via a `GATE_RUN` build arg
|
||||
so the linter always executes), reduced `script/lint` to building it,
|
||||
dropped the golangci-lint install from `script/bootstrap`, and switched
|
||||
the `Dockerfile` lint stage to invoke `golangci-lint` directly instead
|
||||
of `make lint` to avoid docker-in-docker (#188).
|
||||
- 2026-09-22: Added `.prettierignore` so `make fmt` no longer rewrites
|
||||
the vendored `static/js/alpine.min.js` bundle (#185).
|
||||
- 2026-09-22: Fixed the gosec G703 path-traversal finding in the deploy
|
||||
log download handler by verifying the resolved path stays within the
|
||||
deploy log directory before serving, returning 404 on escape (#177).
|
||||
`internal/service/webhook` by tracking the async deployment goroutine in a
|
||||
`sync.WaitGroup` and exposing `WaitForDeployments`; tests now synchronize on
|
||||
completion instead of sleeping (#198).
|
||||
- 2026-09-22: Linting now runs only in Docker. Added `Dockerfile.lint` (pinned
|
||||
golangci-lint v2.12.2, cache-busted via a `GATE_RUN` build arg so the linter
|
||||
always executes), reduced `script/lint` to building it, dropped the
|
||||
golangci-lint install from `script/bootstrap`, and switched the `Dockerfile`
|
||||
lint stage to invoke `golangci-lint` directly instead of `make lint` to avoid
|
||||
docker-in-docker (#188).
|
||||
- 2026-09-22: Added `.prettierignore` so `make fmt` no longer rewrites the
|
||||
vendored `static/js/alpine.min.js` bundle (#185).
|
||||
- 2026-09-22: Fixed the gosec G703 path-traversal finding in the deploy log
|
||||
download handler by verifying the resolved path stays within the deploy log
|
||||
directory before serving, returning 404 on escape (#177).
|
||||
- 2026-09-22: `script/bootstrap` now installs a pinned `goimports`
|
||||
(`golang.org/x/tools` v0.49.0) into `/usr/local/bin`, so `make fmt`
|
||||
succeeds on a fresh machine after `make bootstrap` (#184).
|
||||
- 2026-09-09: Fixed four deployability blockers found by QA: CSRF origin
|
||||
check over plain HTTP (`UPAAS_PLAINTEXT_HTTP`, #189), pulling the git
|
||||
image when absent (#190), the env-var editor CSRF token lookup (#191),
|
||||
and the port-mapping delete form's CSRF field (#192).
|
||||
- 2026-08-07: Updated golangci-lint to v2.12.2 (canonical
|
||||
`.golangci.yml`, `Dockerfile` lint stage pin, `script/bootstrap`
|
||||
release-archive pins) and fixed all resulting lint findings (noctx,
|
||||
gosec, goconst, lll, dupl, nolintlint); `make check` green.
|
||||
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
|
||||
Makefile shims, README Entrypoints section
|
||||
(`golang.org/x/tools` v0.49.0) into `/usr/local/bin`, so `make fmt` succeeds
|
||||
on a fresh machine after `make bootstrap` (#184).
|
||||
- 2026-09-09: Fixed four deployability blockers found by QA: CSRF origin check
|
||||
over plain HTTP (`UPAAS_PLAINTEXT_HTTP`, #189), pulling the git image when
|
||||
absent (#190), the env-var editor CSRF token lookup (#191), and the
|
||||
port-mapping delete form's CSRF field (#192).
|
||||
- 2026-08-07: Updated golangci-lint to v2.12.2 (canonical `.golangci.yml`,
|
||||
`Dockerfile` lint stage pin, `script/bootstrap` release-archive pins) and
|
||||
fixed all resulting lint findings (noctx, gosec, goconst, lll, dupl,
|
||||
nolintlint); `make check` green.
|
||||
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile
|
||||
shims, README Entrypoints section
|
||||
- 2026-03-11: Monolithic env var editing with bulk save (#158).
|
||||
- 2026-03-10: Webhook event history UI page (#164); added missing
|
||||
Makefile docker and hooks targets plus test timeout (#159);
|
||||
notification settings passed from create form (#160).
|
||||
- 2026-03-10: Webhook event history UI page (#164); added missing Makefile
|
||||
docker and hooks targets plus test timeout (#159); notification settings
|
||||
passed from create form (#160).
|
||||
- 2026-03-03: REPO_POLICIES compliance file set added (#155).
|
||||
- 2026-03-01: Module path changed to sneak.berlin/go/upaas (#143);
|
||||
Dockerfile split into lint and build stages with forced lint
|
||||
execution (#152, #154).
|
||||
- 2026-03-01: Module path changed to sneak.berlin/go/upaas (#143); Dockerfile
|
||||
split into lint and build stages with forced lint execution (#152, #154).
|
||||
- 2026-02-26: 1.0.0 tagged; dashboard CSRFField crash fixed (#146).
|
||||
- 1.0 audit bug fixes (#120-#125): deferred rollback on commit error,
|
||||
deployment log size cap, error path rendering, docker-compose bind
|
||||
mount, domain type refactor.
|
||||
- 1.0 audit bug fixes (#120-#125): deferred rollback on commit error, deployment
|
||||
log size cap, error path rendering, docker-compose bind mount, domain type
|
||||
refactor.
|
||||
- CI simplified to docker build only (#130).
|
||||
- 2025-12-29 onward: core PaaS built out: deploys with real-time build
|
||||
log streaming, container start/stop/restart and logs, TCP/UDP port
|
||||
mapping, Alpine.js UI, Slack notifications, ULID app IDs, session
|
||||
handling.
|
||||
- 2025-12-29 onward: core PaaS built out: deploys with real-time build log
|
||||
streaming, container start/stop/restart and logs, TCP/UDP port mapping,
|
||||
Alpine.js UI, Slack notifications, ULID app IDs, session handling.
|
||||
|
||||
# Future Steps
|
||||
|
||||
|
||||
Reference in New Issue
Block a user