sneak/prompts#78: sneak/prompts has changed the canonical files this repository vendors. Re-vendor them once, from sneak/prompts commit dd4027b (dd4027b907), fetching each file from https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>.
Files this repository vendors now: .dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml .prettierrc REPO_POLICIES.md. REPO_POLICIES.md comes from prompts/REPO_POLICIES.md at that commit: the root REPO_POLICIES.md there is a symlink, and its raw URL returns only the link's target path. That repository's own .gitattributes and TODO.md are not canonical.
What changed that matters here:
golangci-lint is v2.14.0 (golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f). The lint phase digest and .golangci.yml change in one commit, since v2.12.2 rejects the new file; the go directive may name at most Go 1.27.
The Go Dockerfile example: the test phase uses the Debian Go image so -race works; the stage that compiles installs git, trusts /src with git config --system --add safe.directory /src, and fails when .git is present but no version comes out.
Host Go tools are installed with go install pinned to a commit, never as go.mod tool dependencies.
The image version comes from git describe inside the build: .dockerignore sends .git without its own or any submodule's config. CHECK_EPOCH is gone; every docker build in script/ passes --no-cache.
.gitignore and .dockerignore keep out more secret files, hardware-backed SSH keys included.
Agent guidance lives in one root AGENTS.md; a committed file or directory named for one agent tool has its content moved there and is deleted.
Definition of done
Every vendored canonical file is its copy at that commit, fetched rather than hand-edited, plus only the entries item 3 keeps. A canonical file the policies require and this repository lacks is added the same way.
Dockerfile, Makefile and script/ follow REPO_POLICIES.md as of that commit, including the gate phases and the version step.
This repository's own entries are carried forward: the deny entries of the test-support depguard rule in .golangci.yml, anchored host-built artifacts in .dockerignore, and its language's entries in .gitignore and .editorconfig, kept after the canonical content. .gitignore is a base each repository extends for its language: a Go repository keeps at least *.log, *.out, *.test and its binaries (prompts/CODE_STYLEGUIDE_GO.md), and its .editorconfig keeps tabs for *.go. (Corrected 2026-10-06: the first version of this item dropped those entries.)
Findings the new files raise are fixed in the code in the same PR; no vendored file is loosened.
make lint runs with no deprecation warnings, and make check passes.
One reviewed PR against next. Closing this issue ticks this repository on sneak/prompts#78.
Model: opus-5-5
https://git.eeqj.de/sneak/prompts/issues/78: `sneak/prompts` has changed the canonical files this repository vendors. Re-vendor them once, from `sneak/prompts` commit `dd4027b` (https://git.eeqj.de/sneak/prompts/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc), fetching each file from `https://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>`.
Files this repository vendors now: `.dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml .prettierrc REPO_POLICIES.md`. `REPO_POLICIES.md` comes from `prompts/REPO_POLICIES.md` at that commit: the root `REPO_POLICIES.md` there is a symlink, and its raw URL returns only the link's target path. That repository's own `.gitattributes` and `TODO.md` are not canonical.
What changed that matters here:
- golangci-lint is v2.14.0 (`golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f`). The lint phase digest and `.golangci.yml` change in one commit, since v2.12.2 rejects the new file; the `go` directive may name at most Go 1.27.
- The Go `Dockerfile` example: the test phase uses the Debian Go image so `-race` works; the stage that compiles installs `git`, trusts `/src` with `git config --system --add safe.directory /src`, and fails when `.git` is present but no version comes out.
- Host Go tools are installed with `go install` pinned to a commit, never as `go.mod` tool dependencies.
- The image version comes from `git describe` inside the build: `.dockerignore` sends `.git` without its own or any submodule's `config`. `CHECK_EPOCH` is gone; every `docker build` in `script/` passes `--no-cache`.
- `.gitignore` and `.dockerignore` keep out more secret files, hardware-backed SSH keys included.
- Agent guidance lives in one root `AGENTS.md`; a committed file or directory named for one agent tool has its content moved there and is deleted.
## Definition of done
1. Every vendored canonical file is its copy at that commit, fetched rather than hand-edited, plus only the entries item 3 keeps. A canonical file the policies require and this repository lacks is added the same way.
2. `Dockerfile`, `Makefile` and `script/` follow `REPO_POLICIES.md` as of that commit, including the gate phases and the version step.
3. This repository's own entries are carried forward: the `deny` entries of the `test-support` depguard rule in `.golangci.yml`, anchored host-built artifacts in `.dockerignore`, and its language's entries in `.gitignore` and `.editorconfig`, kept after the canonical content. `.gitignore` is a base each repository extends for its language: a Go repository keeps at least `*.log`, `*.out`, `*.test` and its binaries (`prompts/CODE_STYLEGUIDE_GO.md`), and its `.editorconfig` keeps tabs for `*.go`. (Corrected 2026-10-06: the first version of this item dropped those entries.)
4. Findings the new files raise are fixed in the code in the same PR; no vendored file is loosened.
5. `make lint` runs with no deprecation warnings, and `make check` passes.
6. One reviewed PR against `next`. Closing this issue ticks this repository on https://git.eeqj.de/sneak/prompts/issues/78.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 01:31:07 +02:00
Plan: one PR against next, as the definition of done says. Notes specific to this repository:
Replaces #98 and #265, both closed into this issue, and #503, closed unmerged because it copied the older shared .golangci.yml.
From 265: -trimpath and -s -w follow the Go Dockerfile example at dd4027b; if the binary build here cannot take one of them, the PR body says why.
Carried forward: this repository has no test-support packages of its own, so its depguard deny list adds nothing (checked again in the PR). The .dockerignore entries specific to this repository (bin/, static/js/alpine.min.js, node_modules/) stay, anchored as the canonical file asks.
The .ci-fingerprint cache barrier goes once every docker build in script/ passes --no-cache; the README and Dockerfile comments that describe it go with it.
go 1.26.1 in go.mod is within the Go 1.27 limit; the lint stage moves to golangci-lint v2.14.0 in the same commit as .golangci.yml.
The README's Entrypoints section and its version notes describe the scripts and the version step as they end up.
Model: opus-5-5
Plan: one PR against `next`, as the definition of done says. Notes specific to this repository:
- Replaces https://git.eeqj.de/sneak/webhooker/issues/98 and https://git.eeqj.de/sneak/webhooker/issues/265, both closed into this issue, and https://git.eeqj.de/sneak/webhooker/pulls/503, closed unmerged because it copied the older shared `.golangci.yml`.
- From 265: `-trimpath` and `-s -w` follow the Go `Dockerfile` example at `dd4027b`; if the binary build here cannot take one of them, the PR body says why.
- Carried forward: this repository has no test-support packages of its own, so its `depguard` deny list adds nothing (checked again in the PR). The `.dockerignore` entries specific to this repository (`bin/`, `static/js/alpine.min.js`, `node_modules/`) stay, anchored as the canonical file asks.
- The `.ci-fingerprint` cache barrier goes once every `docker build` in `script/` passes `--no-cache`; the README and `Dockerfile` comments that describe it go with it.
- `go 1.26.1` in `go.mod` is within the Go 1.27 limit; the lint stage moves to golangci-lint v2.14.0 in the same commit as `.golangci.yml`.
- The README's Entrypoints section and its version notes describe the scripts and the version step as they end up.
Model: opus-5-5
The shared files are the copies at sneak/prompts commit dd4027b, fetched and written unchanged. sha256 of each as fetched:
.dockerignore5ac21268c72605e56463c078a81ba118765c84fda6bfd64d155774ab34275081; the committed file is this plus this repository's anchored entries at its end: /bin, /static/js/alpine.min.js, /data
.golangci.yml3ed73ffd561691e565c5c89a994dd8cfeb3faf06a1f87638ca9ab4dde4fecfa2; its depguard deny list adds nothing, as this repository has no test-support packages
.prettierignore (new: the policies ask for it in a repository with package.json) dbe0186431d09e741fe0ccddf3ac97451575ab88f94fe89353dc2e3ecb83d64b
REPO_POLICIES.md, from prompts/REPO_POLICIES.md6d31d1a5d6d7d0022323a26305b0de33c4b455237fa8eb7d8640aa96a6967840
Linting and testing are now the lint and test phases of the Dockerfile, and the image build depends on both. The lint phase is the golangci-lint v2.14.0 image at the policy's digest and also runs the js-lint stage; Dockerfile.lint is gone. The test phase is the golang bookworm image and keeps the -p 4 -parallel 8 cap. script/lint, script/test, script/docker and script/cibuild are the model scripts; every docker build in script/ passes --no-cache, and the .ci-fingerprint barrier is gone. The version check also refuses an empty version and dev, and make build passes -trimpath and -s -w. The README describes the new layout.
Judgement call: the shared workflow no longer calls script/ci-mark-superseded, so it and its tests are removed.
Judgement call: /data, where the README's dev run writes its databases, is left out of the build context.
Judgement call: the test phase reruns only the failed tests with -v, as script/test did, not the whole suite, which passes the build's 2 MiB log limit.
Consequence: with .gitignore the shared copy, git no longer ignores bin/, data/ or the extracted static/js/alpine.min.js.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/webhooker/pulls/505.
The shared files are the copies at `sneak/prompts` commit `dd4027b`, fetched and written unchanged. sha256 of each as fetched:
- `.dockerignore` `5ac21268c72605e56463c078a81ba118765c84fda6bfd64d155774ab34275081`; the committed file is this plus this repository's anchored entries at its end: `/bin`, `/static/js/alpine.min.js`, `/data`
- `.editorconfig` `14903ff7b0eb82bc2b3581af6e4f42c3f457a23fa4b9283efe99b6acd0971ce3`
- `.gitea/workflows/check.yml` `ea57b499d7257d7c1b16cf02132c98b98fd7d9ff6a414fb23da6974d366e1cab`
- `.gitignore` `97cff2f8942cbce265bad478ea9024e8e2d80c1571cf4348aa978bb6a04469e9`
- `.golangci.yml` `3ed73ffd561691e565c5c89a994dd8cfeb3faf06a1f87638ca9ab4dde4fecfa2`; its `depguard` deny list adds nothing, as this repository has no test-support packages
- `.prettierrc` `1a709149f32ac4adf4004017cf30d8f5482ccf263f414081ae8c499037691133`
- `.prettierignore` (new: the policies ask for it in a repository with `package.json`) `dbe0186431d09e741fe0ccddf3ac97451575ab88f94fe89353dc2e3ecb83d64b`
- `REPO_POLICIES.md`, from `prompts/REPO_POLICIES.md` `6d31d1a5d6d7d0022323a26305b0de33c4b455237fa8eb7d8640aa96a6967840`
Linting and testing are now the `lint` and `test` phases of the `Dockerfile`, and the image build depends on both. The `lint` phase is the `golangci-lint` v2.14.0 image at the policy's digest and also runs the `js-lint` stage; `Dockerfile.lint` is gone. The `test` phase is the `golang` bookworm image and keeps the `-p 4 -parallel 8` cap. `script/lint`, `script/test`, `script/docker` and `script/cibuild` are the model scripts; every `docker build` in `script/` passes `--no-cache`, and the `.ci-fingerprint` barrier is gone. The version check also refuses an empty version and `dev`, and `make build` passes `-trimpath` and `-s -w`. The README describes the new layout.
- Judgement call: the shared workflow no longer calls `script/ci-mark-superseded`, so it and its tests are removed.
- Judgement call: `/data`, where the README's dev run writes its databases, is left out of the build context.
- Judgement call: the `test` phase reruns only the failed tests with `-v`, as `script/test` did, not the whole suite, which passes the build's 2 MiB log limit.
- Consequence: with `.gitignore` the shared copy, git no longer ignores `bin/`, `data/` or the extracted `static/js/alpine.min.js`.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
sneak/prompts#78:
sneak/promptshas changed the canonical files this repository vendors. Re-vendor them once, fromsneak/promptscommitdd4027b(dd4027b907), fetching each file fromhttps://git.eeqj.de/sneak/prompts/raw/commit/dd4027b907ef99cdc3187c215cc4d610b7a11efc/<path>.Files this repository vendors now:
.dockerignore .editorconfig .gitea/workflows/check.yml .gitignore .golangci.yml .prettierrc REPO_POLICIES.md.REPO_POLICIES.mdcomes fromprompts/REPO_POLICIES.mdat that commit: the rootREPO_POLICIES.mdthere is a symlink, and its raw URL returns only the link's target path. That repository's own.gitattributesandTODO.mdare not canonical.What changed that matters here:
golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f). The lint phase digest and.golangci.ymlchange in one commit, since v2.12.2 rejects the new file; thegodirective may name at most Go 1.27.Dockerfileexample: the test phase uses the Debian Go image so-raceworks; the stage that compiles installsgit, trusts/srcwithgit config --system --add safe.directory /src, and fails when.gitis present but no version comes out.go installpinned to a commit, never asgo.modtool dependencies.git describeinside the build:.dockerignoresends.gitwithout its own or any submodule'sconfig.CHECK_EPOCHis gone; everydocker buildinscript/passes--no-cache..gitignoreand.dockerignorekeep out more secret files, hardware-backed SSH keys included.AGENTS.md; a committed file or directory named for one agent tool has its content moved there and is deleted.Definition of done
Dockerfile,Makefileandscript/followREPO_POLICIES.mdas of that commit, including the gate phases and the version step.denyentries of thetest-supportdepguard rule in.golangci.yml, anchored host-built artifacts in.dockerignore, and its language's entries in.gitignoreand.editorconfig, kept after the canonical content..gitignoreis a base each repository extends for its language: a Go repository keeps at least*.log,*.out,*.testand its binaries (prompts/CODE_STYLEGUIDE_GO.md), and its.editorconfigkeeps tabs for*.go. (Corrected 2026-10-06: the first version of this item dropped those entries.)make lintruns with no deprecation warnings, andmake checkpasses.next. Closing this issue ticks this repository on sneak/prompts#78.Model: opus-5-5
Plan: one PR against
next, as the definition of done says. Notes specific to this repository:.golangci.yml.-trimpathand-s -wfollow the GoDockerfileexample atdd4027b; if the binary build here cannot take one of them, the PR body says why.depguarddeny list adds nothing (checked again in the PR). The.dockerignoreentries specific to this repository (bin/,static/js/alpine.min.js,node_modules/) stay, anchored as the canonical file asks..ci-fingerprintcache barrier goes once everydocker buildinscript/passes--no-cache; the README andDockerfilecomments that describe it go with it.go 1.26.1ingo.modis within the Go 1.27 limit; the lint stage moves to golangci-lint v2.14.0 in the same commit as.golangci.yml.Model: opus-5-5
Built in #505.
The shared files are the copies at
sneak/promptscommitdd4027b, fetched and written unchanged. sha256 of each as fetched:.dockerignore5ac21268c72605e56463c078a81ba118765c84fda6bfd64d155774ab34275081; the committed file is this plus this repository's anchored entries at its end:/bin,/static/js/alpine.min.js,/data.editorconfig14903ff7b0eb82bc2b3581af6e4f42c3f457a23fa4b9283efe99b6acd0971ce3.gitea/workflows/check.ymlea57b499d7257d7c1b16cf02132c98b98fd7d9ff6a414fb23da6974d366e1cab.gitignore97cff2f8942cbce265bad478ea9024e8e2d80c1571cf4348aa978bb6a04469e9.golangci.yml3ed73ffd561691e565c5c89a994dd8cfeb3faf06a1f87638ca9ab4dde4fecfa2; itsdepguarddeny list adds nothing, as this repository has no test-support packages.prettierrc1a709149f32ac4adf4004017cf30d8f5482ccf263f414081ae8c499037691133.prettierignore(new: the policies ask for it in a repository withpackage.json)dbe0186431d09e741fe0ccddf3ac97451575ab88f94fe89353dc2e3ecb83d64bREPO_POLICIES.md, fromprompts/REPO_POLICIES.md6d31d1a5d6d7d0022323a26305b0de33c4b455237fa8eb7d8640aa96a6967840Linting and testing are now the
lintandtestphases of theDockerfile, and the image build depends on both. Thelintphase is thegolangci-lintv2.14.0 image at the policy's digest and also runs thejs-lintstage;Dockerfile.lintis gone. Thetestphase is thegolangbookworm image and keeps the-p 4 -parallel 8cap.script/lint,script/test,script/dockerandscript/cibuildare the model scripts; everydocker buildinscript/passes--no-cache, and the.ci-fingerprintbarrier is gone. The version check also refuses an empty version anddev, andmake buildpasses-trimpathand-s -w. The README describes the new layout.script/ci-mark-superseded, so it and its tests are removed./data, where the README's dev run writes its databases, is left out of the build context.testphase reruns only the failed tests with-v, asscript/testdid, not the whole suite, which passes the build's 2 MiB log limit..gitignorethe shared copy, git no longer ignoresbin/,data/or the extractedstatic/js/alpine.min.js.Model: opus-5-5