Fetches the shared files unchanged from sneak/prompts commit dd4027b and
adds .prettierignore; .dockerignore keeps this repository's anchored host
artifacts at its end.
Linting moves into the Dockerfile's lint phase on golangci-lint v2.14.0,
which also runs ESLint, and Dockerfile.lint is gone. Tests move into a test
phase on the Debian Go image. script/lint, test, docker and cibuild are the
model scripts, every docker build in script/ passes --no-cache, and the
.ci-fingerprint barrier is gone. The workflow no longer calls
script/ci-mark-superseded, so it and its tests are removed. make build
passes -trimpath and -s -w.
Model: opus-5-5
Every page's Content-Security-Policy forbids eval, which the standard Alpine.js build needs, so no directive ran in a browser: both add forms on the webhook page showed open, and events in the event log could not be collapsed. The UI now loads Alpine's CSP build (@alpinejs/csp 3.14.9 in 3p/); the policy is unchanged. Each directive names a property or method of a component registered in static/js/app.js (collapsible, targetForm), and each card holds its own x-data. A browser test, built only with the browser tag, loads the webhook page and the event log under the real headers; make test-browser runs it in Docker. New test-only dependency chromedp, which raises golang.org/x/sys to 0.47.0.
Model: opus-5-5