sneak/prompts#78: sneak/prompts has changed the canonical files this repository vendors. Re-vendor them once, from sneak/prompts commit dd4027b (dd4027b907), fetching each file from https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>.
Files this repository vendors now: .dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml REPO_POLICIES.md. REPO_POLICIES.md comes from prompts/REPO_POLICIES.md at that commit: the root REPO_POLICIES.md there is a symlink, and its raw URL returns only the link's target path. That repository's own .gitattributes and TODO.md are not canonical.
What changed that matters here:
golangci-lint is v2.14.0 (golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f). The lint phase digest and .golangci.yml change in one commit, since v2.12.2 rejects the new file; the go directive may name at most Go 1.27.
The Go Dockerfile example: the test phase uses the Debian Go image so -race works; the stage that compiles installs git, trusts /src with git config --system --add safe.directory /src, and fails when .git is present but no version comes out.
Host Go tools are installed with go install pinned to a commit, never as go.mod tool dependencies.
The image version comes from git describe inside the build: .dockerignore sends .git without its own or any submodule's config. CHECK_EPOCH is gone; every docker build in script/ passes --no-cache.
.gitignore and .dockerignore keep out more secret files, hardware-backed SSH keys included.
Agent guidance lives in one root AGENTS.md; a committed file or directory named for one agent tool has its content moved there and is deleted.
Definition of done
Every vendored canonical file is its copy at that commit, fetched rather than hand-edited, plus only the entries item 3 keeps. A canonical file the policies require and this repository lacks is added the same way.
Dockerfile, Makefile and script/ follow REPO_POLICIES.md as of that commit, including the gate phases and the version step.
This repository's own entries are carried forward: the deny entries of the test-support depguard rule in .golangci.yml, anchored host-built artifacts in .dockerignore, and its language's entries in .gitignore and .editorconfig, kept after the canonical content. .gitignore is a base each repository extends for its language: a Go repository keeps at least *.log, *.out, *.test and its binaries (prompts/CODE_STYLEGUIDE_GO.md), and its .editorconfig keeps tabs for *.go. (Corrected 2026-10-06: the first version of this item dropped those entries.)
Findings the new files raise are fixed in the code in the same PR; no vendored file is loosened.
make lint runs with no deprecation warnings, and make check passes.
One reviewed PR against next. Closing this issue ticks this repository on sneak/prompts#78.
Model: opus-5-5
https://git.eeqj.de/sneak/prompts/issues/78: `sneak/prompts` has changed the canonical files this repository vendors. Re-vendor them once, from `sneak/prompts` commit `dd4027b` (https://git.eeqj.de/sneak/prompts/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc), fetching each file from `https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>`.
Files this repository vendors now: `.dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml REPO_POLICIES.md`. `REPO_POLICIES.md` comes from `prompts/REPO_POLICIES.md` at that commit: the root `REPO_POLICIES.md` there is a symlink, and its raw URL returns only the link's target path. That repository's own `.gitattributes` and `TODO.md` are not canonical.
What changed that matters here:
- golangci-lint is v2.14.0 (`golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f`). The lint phase digest and `.golangci.yml` change in one commit, since v2.12.2 rejects the new file; the `go` directive may name at most Go 1.27.
- The Go `Dockerfile` example: the test phase uses the Debian Go image so `-race` works; the stage that compiles installs `git`, trusts `/src` with `git config --system --add safe.directory /src`, and fails when `.git` is present but no version comes out.
- Host Go tools are installed with `go install` pinned to a commit, never as `go.mod` tool dependencies.
- The image version comes from `git describe` inside the build: `.dockerignore` sends `.git` without its own or any submodule's `config`. `CHECK_EPOCH` is gone; every `docker build` in `script/` passes `--no-cache`.
- `.gitignore` and `.dockerignore` keep out more secret files, hardware-backed SSH keys included.
- Agent guidance lives in one root `AGENTS.md`; a committed file or directory named for one agent tool has its content moved there and is deleted.
## Definition of done
1. Every vendored canonical file is its copy at that commit, fetched rather than hand-edited, plus only the entries item 3 keeps. A canonical file the policies require and this repository lacks is added the same way.
2. `Dockerfile`, `Makefile` and `script/` follow `REPO_POLICIES.md` as of that commit, including the gate phases and the version step.
3. This repository's own entries are carried forward: the `deny` entries of the `test-support` depguard rule in `.golangci.yml`, anchored host-built artifacts in `.dockerignore`, and its language's entries in `.gitignore` and `.editorconfig`, kept after the canonical content. `.gitignore` is a base each repository extends for its language: a Go repository keeps at least `*.log`, `*.out`, `*.test` and its binaries (`prompts/CODE_STYLEGUIDE_GO.md`), and its `.editorconfig` keeps tabs for `*.go`. (Corrected 2026-10-06: the first version of this item dropped those entries.)
4. Findings the new files raise are fixed in the code in the same PR; no vendored file is loosened.
5. `make lint` runs with no deprecation warnings, and `make check` passes.
6. One reviewed PR against `next`. Closing this issue ticks this repository on https://git.eeqj.de/sneak/prompts/issues/78.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 01:31:03 +02:00
Plan. The issue body is the brief; what follows is what the new policy changes in this repo specifically.
The six vendored files are fetched byte-identical from dd4027b. Carried forward: the deny entries of the test-support depguard rule, and this repo's anchored host-built artifacts in .dockerignore (the binary vaultik, dist, coverage files).
Linting becomes the lint phase of Dockerfile, and Dockerfile.lint is deleted. The policy now settles the layout that #113 chose: there is one golangci-lint pin, in the FROM of the lint phase. Tests become the test phase, built on the Debian Go image. The build stage depends on both phases through COPY --from.
CHECK_EPOCH is removed everywhere. Every docker build in script/ is tagged and passes --no-cache. script/lint, script/test, script/check, script/cibuild and script/docker follow the policy, and script/cibuild runs script/bootstrap first.
The test timeout becomes the policy's 90s. The comment recording the 120s divergence goes, because the policy text it diverged from has changed (#101).
cmd/vaultik/lintdocker_test.go checks the CHECK_EPOCH and Dockerfile.lint machinery. Those checks are deleted along with the machinery; TestPhonyTargetsAllHaveRules stays.
The version step takes the policy's form but keeps the three values this repo stamps: internal/globals.Version, Commit and CommitDate.
The rules in CLAUDE.md move into AGENTS.md, and CLAUDE.md is deleted.
Every README, Makefile and Dockerfile comment that describes Dockerfile.lint or CHECK_EPOCH is corrected. The TODO.md history entries stay as they are.
New golangci-lint v2.14.0 findings are fixed in the code. The go directive stays at 1.26.x.
No .prettierrc is added: the policy asks for one only in documentation repos. The release workflow is out of scope.
Model: opus-5-5
Plan. The issue body is the brief; what follows is what the new policy changes in this repo specifically.
- The six vendored files are fetched byte-identical from `dd4027b`. Carried forward: the `deny` entries of the `test-support` depguard rule, and this repo's anchored host-built artifacts in `.dockerignore` (the binary `vaultik`, `dist`, coverage files).
- Linting becomes the `lint` phase of `Dockerfile`, and `Dockerfile.lint` is deleted. The policy now settles the layout that https://git.eeqj.de/sneak/vaultik/issues/113 chose: there is one golangci-lint pin, in the `FROM` of the lint phase. Tests become the `test` phase, built on the Debian Go image. The build stage depends on both phases through `COPY --from`.
- `CHECK_EPOCH` is removed everywhere. Every `docker build` in `script/` is tagged and passes `--no-cache`. `script/lint`, `script/test`, `script/check`, `script/cibuild` and `script/docker` follow the policy, and `script/cibuild` runs `script/bootstrap` first.
- The test timeout becomes the policy's 90s. The comment recording the 120s divergence goes, because the policy text it diverged from has changed (https://git.eeqj.de/sneak/vaultik/issues/101).
- `cmd/vaultik/lintdocker_test.go` checks the `CHECK_EPOCH` and `Dockerfile.lint` machinery. Those checks are deleted along with the machinery; `TestPhonyTargetsAllHaveRules` stays.
- The version step takes the policy's form but keeps the three values this repo stamps: `internal/globals.Version`, `Commit` and `CommitDate`.
- The rules in `CLAUDE.md` move into `AGENTS.md`, and `CLAUDE.md` is deleted.
- Every README, Makefile and Dockerfile comment that describes `Dockerfile.lint` or `CHECK_EPOCH` is corrected. The `TODO.md` history entries stay as they are.
- New golangci-lint v2.14.0 findings are fixed in the code. The `go` directive stays at 1.26.x.
- No `.prettierrc` is added: the policy asks for one only in documentation repos. The release workflow is out of scope.
Model: opus-5-5
Implemented in #236. Two changes go beyond the plan above. script/bootstrap now runs apt-get update before an apt install: the CI runner image has neither Go nor package lists, so the bootstrap that script/cibuild now runs first could not install Go. And IsDevVersion counts unknown, the version the canonical script/docker stamps outside a git checkout.
Model: opus-5-5
Implemented in https://git.eeqj.de/sneak/vaultik/pulls/236. Two changes go beyond the plan above. `script/bootstrap` now runs `apt-get update` before an apt install: the CI runner image has neither Go nor package lists, so the bootstrap that `script/cibuild` now runs first could not install Go. And `IsDevVersion` counts `unknown`, the version the canonical `script/docker` stamps outside a git checkout.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
sneak/prompts#78:
sneak/promptshas changed the canonical files this repository vendors. Re-vendor them once, fromsneak/promptscommitdd4027b(dd4027b907), fetching each file fromhttps://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>.Files this repository vendors now:
.dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml REPO_POLICIES.md.REPO_POLICIES.mdcomes fromprompts/REPO_POLICIES.mdat that commit: the rootREPO_POLICIES.mdthere is a symlink, and its raw URL returns only the link's target path. That repository's own.gitattributesandTODO.mdare not canonical.What changed that matters here:
golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f). The lint phase digest and.golangci.ymlchange in one commit, since v2.12.2 rejects the new file; thegodirective may name at most Go 1.27.Dockerfileexample: the test phase uses the Debian Go image so-raceworks; the stage that compiles installsgit, trusts/srcwithgit config --system --add safe.directory /src, and fails when.gitis present but no version comes out.go installpinned to a commit, never asgo.modtool dependencies.git describeinside the build:.dockerignoresends.gitwithout its own or any submodule'sconfig.CHECK_EPOCHis gone; everydocker buildinscript/passes--no-cache..gitignoreand.dockerignorekeep out more secret files, hardware-backed SSH keys included.AGENTS.md; a committed file or directory named for one agent tool has its content moved there and is deleted.Definition of done
Dockerfile,Makefileandscript/followREPO_POLICIES.mdas of that commit, including the gate phases and the version step.denyentries of thetest-supportdepguard rule in.golangci.yml, anchored host-built artifacts in.dockerignore, and its language's entries in.gitignoreand.editorconfig, kept after the canonical content..gitignoreis a base each repository extends for its language: a Go repository keeps at least*.log,*.out,*.testand its binaries (prompts/CODE_STYLEGUIDE_GO.md), and its.editorconfigkeeps tabs for*.go. (Corrected 2026-10-06: the first version of this item dropped those entries.)make lintruns with no deprecation warnings, andmake checkpasses.next. Closing this issue ticks this repository on sneak/prompts#78.Model: opus-5-5
Plan. The issue body is the brief; what follows is what the new policy changes in this repo specifically.
dd4027b. Carried forward: thedenyentries of thetest-supportdepguard rule, and this repo's anchored host-built artifacts in.dockerignore(the binaryvaultik,dist, coverage files).lintphase ofDockerfile, andDockerfile.lintis deleted. The policy now settles the layout that #113 chose: there is one golangci-lint pin, in theFROMof the lint phase. Tests become thetestphase, built on the Debian Go image. The build stage depends on both phases throughCOPY --from.CHECK_EPOCHis removed everywhere. Everydocker buildinscript/is tagged and passes--no-cache.script/lint,script/test,script/check,script/cibuildandscript/dockerfollow the policy, andscript/cibuildrunsscript/bootstrapfirst.cmd/vaultik/lintdocker_test.gochecks theCHECK_EPOCHandDockerfile.lintmachinery. Those checks are deleted along with the machinery;TestPhonyTargetsAllHaveRulesstays.internal/globals.Version,CommitandCommitDate.CLAUDE.mdmove intoAGENTS.md, andCLAUDE.mdis deleted.Dockerfile.lintorCHECK_EPOCHis corrected. TheTODO.mdhistory entries stay as they are.godirective stays at 1.26.x..prettierrcis added: the policy asks for one only in documentation repos. The release workflow is out of scope.Model: opus-5-5
Implemented in #236. Two changes go beyond the plan above.
script/bootstrapnow runsapt-get updatebefore an apt install: the CI runner image has neither Go nor package lists, so the bootstrap thatscript/cibuildnow runs first could not install Go. AndIsDevVersioncountsunknown, the version the canonicalscript/dockerstamps outside a git checkout.Model: opus-5-5