# Workflow - branch (from `main`) - do the work in Next Step - move Next Step to the top of Completed Steps - move the top item of Future Steps into Next Step - commit (`TODO.md` changes in the same commit as the work) - merge to `main` if the branch is not protected, otherwise open a PR - push # Status 1.0+. Tagged 1.0.0 on 2026-02-26; 8 commits on main since. `make check` is green as of the golangci-lint v2.12.2 update. # Next Step Confirm `.gitea/workflows/check.yml` gates merges on `make check` so main cannot regress. # Completed Steps - 2026-09-23: Fixed the flaky `t.TempDir` cleanup race in `internal/handlers` (the one fixed in `internal/service/webhook` by #198): `TestHandleWebhookProcessesValidWebhook` now waits with the webhook service's `WaitForDeployments` instead of sleeping (#211). - 2026-09-22: Vendored the canonical prettier/format toolchain from the `sneak/prompts` scaffold: added `.prettierrc` (tabWidth 4, proseWrap always), pinned `package.json` + `yarn.lock` (prettier 3.8.1), taught `script/bootstrap` to install a pinned node/yarn via a hash-verified nvm archive, and switched `script/fmt` to the pinned prettier reading `.prettierrc` (no inline flags) over `static/js/*.js` and `**/*.md`. Reflowed all markdown to house style; `alpine.min.js` stays byte-identical (#203). - 2026-09-22: Fixed the flaky `t.TempDir` cleanup race in `internal/service/webhook` by tracking the async deployment goroutine in a `sync.WaitGroup` and exposing `WaitForDeployments`; tests now synchronize on completion instead of sleeping (#198). - 2026-09-22: Linting now runs only in Docker. Added `Dockerfile.lint` (pinned golangci-lint v2.12.2, cache-busted via a `GATE_RUN` build arg so the linter always executes), reduced `script/lint` to building it, dropped the golangci-lint install from `script/bootstrap`, and switched the `Dockerfile` lint stage to invoke `golangci-lint` directly instead of `make lint` to avoid docker-in-docker (#188). - 2026-09-22: Added `.prettierignore` so `make fmt` no longer rewrites the vendored `static/js/alpine.min.js` bundle (#185). - 2026-09-22: Fixed the gosec G703 path-traversal finding in the deploy log download handler by verifying the resolved path stays within the deploy log directory before serving, returning 404 on escape (#177). - 2026-09-22: `script/bootstrap` now installs a pinned `goimports` (`golang.org/x/tools` v0.49.0) into `/usr/local/bin`, so `make fmt` succeeds on a fresh machine after `make bootstrap` (#184). - 2026-09-09: Fixed four deployability blockers found by QA: CSRF origin check over plain HTTP (`UPAAS_PLAINTEXT_HTTP`, #189), pulling the git image when absent (#190), the env-var editor CSRF token lookup (#191), and the port-mapping delete form's CSRF field (#192). - 2026-08-07: Updated golangci-lint to v2.12.2 (canonical `.golangci.yml`, `Dockerfile` lint stage pin, `script/bootstrap` release-archive pins) and fixed all resulting lint findings (noctx, gosec, goconst, lll, dupl, nolintlint); `make check` green. - 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile shims, README Entrypoints section - 2026-03-11: Monolithic env var editing with bulk save (#158). - 2026-03-10: Webhook event history UI page (#164); added missing Makefile docker and hooks targets plus test timeout (#159); notification settings passed from create form (#160). - 2026-03-03: REPO_POLICIES compliance file set added (#155). - 2026-03-01: Module path changed to sneak.berlin/go/upaas (#143); Dockerfile split into lint and build stages with forced lint execution (#152, #154). - 2026-02-26: 1.0.0 tagged; dashboard CSRFField crash fixed (#146). - 1.0 audit bug fixes (#120-#125): deferred rollback on commit error, deployment log size cap, error path rendering, docker-compose bind mount, domain type refactor. - CI simplified to docker build only (#130). - 2025-12-29 onward: core PaaS built out: deploys with real-time build log streaming, container start/stop/restart and logs, TCP/UDP port mapping, Alpine.js UI, Slack notifications, ULID app IDs, session handling. # Future Steps - Resume feature work only after main is green.