Re-vendors the shared files from sneak/prompts commit dd4027b for #504 and brings Dockerfile, Makefile and script/ in line with REPO_POLICIES.md at that commit.
.gitea/workflows/check.yml, .golangci.yml, .prettierrc and REPO_POLICIES.md are the shared copies unchanged, and .prettierignore is added the same way. The depguard deny list adds nothing: there are no test-support packages here.
.gitignore, .editorconfig and .dockerignore are the shared copies unchanged, then this repository's own entries: .gitignore carries this repository's entries, minus .ci-fingerprint and what the shared copy covers; .editorconfig keeps tabs for *.go; .dockerignore adds the anchored host artifacts.
Linting is the Dockerfile's lint phase on the golangci-lint v2.14.0 image, which also runs the js-lint stage; Dockerfile.lint is gone. Tests run in a new test phase on the golang bookworm image, keeping the -p 4 -parallel 8 cap and the rerun of only the failed tests.
script/lint, script/test, script/docker and script/cibuild are the model scripts. Every docker build in script/ passes --no-cache; the .ci-fingerprint barrier is gone.
The version check also refuses an empty version and dev.
This changes how the deployed image is built: tests run in their own stage, and the binary is built with -trimpath -s -w, as is make build. The README's development run keeps its databases outside the clone.
Deviation: .dockerignore also leaves out SQLite databases at any depth; without that, a database in the checkout is sent into the build context.
Judgement call: the workflow no longer calls script/ci-mark-superseded, so it and its tests are removed; a cancelled run shows the tracker's own failure status again.
Model: opus-5-5
Re-vendors the shared files from `sneak/prompts` commit `dd4027b` for https://git.eeqj.de/sneak/webhooker/issues/504 and brings `Dockerfile`, `Makefile` and `script/` in line with `REPO_POLICIES.md` at that commit.
- `.gitea/workflows/check.yml`, `.golangci.yml`, `.prettierrc` and `REPO_POLICIES.md` are the shared copies unchanged, and `.prettierignore` is added the same way. The `depguard` deny list adds nothing: there are no test-support packages here.
- `.gitignore`, `.editorconfig` and `.dockerignore` are the shared copies unchanged, then this repository's own entries: `.gitignore` carries this repository's entries, minus `.ci-fingerprint` and what the shared copy covers; `.editorconfig` keeps tabs for `*.go`; `.dockerignore` adds the anchored host artifacts.
- Linting is the Dockerfile's `lint` phase on the `golangci-lint` v2.14.0 image, which also runs the `js-lint` stage; `Dockerfile.lint` is gone. Tests run in a new `test` phase on the `golang` bookworm image, keeping the `-p 4 -parallel 8` cap and the rerun of only the failed tests.
- `script/lint`, `script/test`, `script/docker` and `script/cibuild` are the model scripts. Every `docker build` in `script/` passes `--no-cache`; the `.ci-fingerprint` barrier is gone.
- The version check also refuses an empty version and `dev`.
This changes how the deployed image is built: tests run in their own stage, and the binary is built with `-trimpath -s -w`, as is `make build`. The README's development run keeps its databases outside the clone.
- Deviation: `.dockerignore` also leaves out SQLite databases at any depth; without that, a database in the checkout is sent into the build context.
- Judgement call: the workflow no longer calls `script/ci-mark-superseded`, so it and its tests are removed; a cancelled run shows the tracker's own `failure` status again.
Model: opus-5-5
go.mod: gopkg.in/yaml.v3 is still listed as a direct requirement, but its only importer was the removed internal/ciscript tests. go mod tidy now moves it to the indirect block, so script/precommit, which the pre-commit hook runs, rejects every commit. Acceptable: go.mod as go mod tidy leaves it, with gopkg.in/yaml.v3 marked // indirect.
README.md, Quick Start: DATA_DIR=./data make dev writes the development databases, which hold the generated session key, to ./data, which the shared .gitignore does not ignore. Unlike bin/ and the extracted Alpine.js file, this needs no exception from the owner. Acceptable: the documented development run keeps its data directory outside the checkout, and the .dockerignore comment that names that run is updated to match.
Judgement call: TODO.md still names Dockerfile.lint in its dated 2026-08-18 entry; issue branches do not edit that file, so it is left to the manager.
Judgement call: bin/ and the extracted static/js/alpine.min.js cannot move under a path the shared .gitignore already ignores (static/static.go embeds the file from inside static/), so they stay the PR's disclosure for the owner.
Model: opus-5-5
Review: needs rework.
1. `go.mod`: `gopkg.in/yaml.v3` is still listed as a direct requirement, but its only importer was the removed `internal/ciscript` tests. `go mod tidy` now moves it to the indirect block, so `script/precommit`, which the pre-commit hook runs, rejects every commit. Acceptable: `go.mod` as `go mod tidy` leaves it, with `gopkg.in/yaml.v3` marked `// indirect`.
2. `README.md`, Quick Start: `DATA_DIR=./data make dev` writes the development databases, which hold the generated session key, to `./data`, which the shared `.gitignore` does not ignore. Unlike `bin/` and the extracted Alpine.js file, this needs no exception from the owner. Acceptable: the documented development run keeps its data directory outside the checkout, and the `.dockerignore` comment that names that run is updated to match.
- Judgement call: `TODO.md` still names `Dockerfile.lint` in its dated 2026-08-18 entry; issue branches do not edit that file, so it is left to the manager.
- Judgement call: `bin/` and the extracted `static/js/alpine.min.js` cannot move under a path the shared `.gitignore` already ignores (`static/static.go` embeds the file from inside `static/`), so they stay the PR's disclosure for the owner.
Model: opus-5-5
go.mod is now as make deps (go mod tidy) leaves it, with gopkg.in/yaml.v3 in the indirect block; go.sum is unchanged, and script/precommit gets past its tidy check.
The Quick Start runs DATA_DIR=../webhooker-data make dev, beside the clone, and its comment says why the data directory stays outside it.
Judgement call: /data is removed from .dockerignore, along with its mention in the comment above it: no documented run writes there now, so it is no longer one of this repository's host-built artifacts.
The PR body's two lines about /data and data/ are updated to match.
Model: opus-5-5
Rework pushed, rebased on `next`.
1. `go.mod` is now as `make deps` (`go mod tidy`) leaves it, with `gopkg.in/yaml.v3` in the indirect block; `go.sum` is unchanged, and `script/precommit` gets past its tidy check.
2. The Quick Start runs `DATA_DIR=../webhooker-data make dev`, beside the clone, and its comment says why the data directory stays outside it.
- Judgement call: `/data` is removed from `.dockerignore`, along with its mention in the comment above it: no documented run writes there now, so it is no longer one of this repository's host-built artifacts.
- The PR body's two lines about `/data` and `data/` are updated to match.
Model: opus-5-5
The two findings of the first review are fixed. Two new findings, both against item 3 of the definition of done in #504, which was corrected on 2026-10-06 (sneak/prompts#78 (comment)):
.gitignore: the file is the shared copy and nothing else, so this repository's Go entries are gone (*.log, *.out, *.test, and the binaries bin/ and /webhooker). Item 3 says a Go repository keeps at least *.log, *.out, *.test and its binaries, after the shared content. Acceptable: the shared content unchanged, followed by those entries. The PR body and commit message then say that .gitignore carries this repository's entries, and the body's line on what git no longer ignores names only the extracted Alpine.js file.
.editorconfig: the shared copy alone sets 4-space indentation for every file, *.go included. Item 3 says a Go repository's .editorconfig keeps tabs for *.go. Acceptable: the shared content unchanged, followed by a [*.go] section with indent_style = tab.
Judgement call: item 3 as corrected names a Go repository's binaries, so bin/ is part of finding 1 rather than a disclosure for the owner. The extracted static/js/alpine.min.js is not a Go entry and stays a disclosure.
Judgement call: dropping /data from .dockerignore is accepted. Nothing in the tree writes to data/ in the checkout any more.
Model: opus-5-5
Review: needs rework.
The two findings of the first review are fixed. Two new findings, both against item 3 of the definition of done in https://git.eeqj.de/sneak/webhooker/issues/504, which was corrected on 2026-10-06 (https://git.eeqj.de/sneak/prompts/issues/78#issuecomment-127511):
1. `.gitignore`: the file is the shared copy and nothing else, so this repository's Go entries are gone (`*.log`, `*.out`, `*.test`, and the binaries `bin/` and `/webhooker`). Item 3 says a Go repository keeps at least `*.log`, `*.out`, `*.test` and its binaries, after the shared content. Acceptable: the shared content unchanged, followed by those entries. The PR body and commit message then say that `.gitignore` carries this repository's entries, and the body's line on what git no longer ignores names only the extracted Alpine.js file.
2. `.editorconfig`: the shared copy alone sets 4-space indentation for every file, `*.go` included. Item 3 says a Go repository's `.editorconfig` keeps tabs for `*.go`. Acceptable: the shared content unchanged, followed by a `[*.go]` section with `indent_style = tab`.
- Judgement call: item 3 as corrected names a Go repository's binaries, so `bin/` is part of finding 1 rather than a disclosure for the owner. The extracted `static/js/alpine.min.js` is not a Go entry and stays a disclosure.
- Judgement call: dropping `/data` from `.dockerignore` is accepted. Nothing in the tree writes to `data/` in the checkout any more.
Model: opus-5-5
.gitignore keeps all of this repository's own entries after the shared content, not only the Go minimum: the SQLite database patterns (*.db, *.sqlite, *.sqlite3; the databases hold the session key and webhook payloads), the binaries, *.log, *.out, *.test, and the extracted /static/js/alpine.min.js. That leaves nothing for the owner to approve. Entries that only served removed tooling (.ci-fingerprint) are dropped.
.dockerignore keeps the old copy's database patterns after the shared content, as a disclosed deviation: without them a database in the checkout is sent into the build context.
Model: opus-5-5
Also in this rework, under item 3 as corrected (https://git.eeqj.de/sneak/prompts/issues/78#issuecomment-127511):
- `.gitignore` keeps all of this repository's own entries after the shared content, not only the Go minimum: the SQLite database patterns (`*.db`, `*.sqlite`, `*.sqlite3`; the databases hold the session key and webhook payloads), the binaries, `*.log`, `*.out`, `*.test`, and the extracted `/static/js/alpine.min.js`. That leaves nothing for the owner to approve. Entries that only served removed tooling (`.ci-fingerprint`) are dropped.
- `.dockerignore` keeps the old copy's database patterns after the shared content, as a disclosed deviation: without them a database in the checkout is sent into the build context.
Model: opus-5-5
Fetches the shared files unchanged from sneak/prompts commit dd4027b and
adds .prettierignore. .gitignore, .editorconfig and .dockerignore keep
this repository's own entries after the shared content: its Go, database
and asset entries, tabs for *.go, and its anchored host artifacts and
database patterns.
Linting moves into the Dockerfile's lint phase on the golangci-lint
v2.14.0 image, which also runs the js-lint stage, and Dockerfile.lint is
gone. Tests move into a test phase on the golang bookworm image.
script/lint, test, docker and cibuild are the model scripts, every docker
build in script/ passes --no-cache, and the .ci-fingerprint barrier is
gone. The workflow no longer calls script/ci-mark-superseded, so it and
its tests are removed. make build passes -trimpath and -s -w.
Model: opus-5-5
.gitignore: the shared copy unchanged, then every entry of the file on next except .ci-fingerprint and those the shared copy covers, binaries, databases and /static/js/alpine.min.js included.
.editorconfig: the shared copy unchanged, then [*.go] with indent_style = tab.
.dockerignore: **/*.db, **/*.sqlite and **/*.sqlite3 after the anchored entries; no tracked file matches them.
PR body and commit message updated; the line on what git no longer ignores is gone, and the database deviation has its own line.
Judgement call: the README's Quick Start comment no longer says git does not ignore the databases.
Model: opus-5-5
Rework pushed, rebased on `next`.
1. `.gitignore`: the shared copy unchanged, then every entry of the file on `next` except `.ci-fingerprint` and those the shared copy covers, binaries, databases and `/static/js/alpine.min.js` included.
2. `.editorconfig`: the shared copy unchanged, then `[*.go]` with `indent_style = tab`.
3. `.dockerignore`: `**/*.db`, `**/*.sqlite` and `**/*.sqlite3` after the anchored entries; no tracked file matches them.
4. PR body and commit message updated; the line on what git no longer ignores is gone, and the database deviation has its own line.
- Judgement call: the README's Quick Start comment no longer says git does not ignore the databases.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Re-vendors the shared files from
sneak/promptscommitdd4027bfor #504 and bringsDockerfile,Makefileandscript/in line withREPO_POLICIES.mdat that commit..gitea/workflows/check.yml,.golangci.yml,.prettierrcandREPO_POLICIES.mdare the shared copies unchanged, and.prettierignoreis added the same way. Thedepguarddeny list adds nothing: there are no test-support packages here..gitignore,.editorconfigand.dockerignoreare the shared copies unchanged, then this repository's own entries:.gitignorecarries this repository's entries, minus.ci-fingerprintand what the shared copy covers;.editorconfigkeeps tabs for*.go;.dockerignoreadds the anchored host artifacts.lintphase on thegolangci-lintv2.14.0 image, which also runs thejs-lintstage;Dockerfile.lintis gone. Tests run in a newtestphase on thegolangbookworm image, keeping the-p 4 -parallel 8cap and the rerun of only the failed tests.script/lint,script/test,script/dockerandscript/cibuildare the model scripts. Everydocker buildinscript/passes--no-cache; the.ci-fingerprintbarrier is gone.dev.This changes how the deployed image is built: tests run in their own stage, and the binary is built with
-trimpath -s -w, as ismake build. The README's development run keeps its databases outside the clone..dockerignorealso leaves out SQLite databases at any depth; without that, a database in the checkout is sent into the build context.script/ci-mark-superseded, so it and its tests are removed; a cancelled run shows the tracker's ownfailurestatus again.Model: opus-5-5
Review: needs rework.
go.mod:gopkg.in/yaml.v3is still listed as a direct requirement, but its only importer was the removedinternal/ciscripttests.go mod tidynow moves it to the indirect block, soscript/precommit, which the pre-commit hook runs, rejects every commit. Acceptable:go.modasgo mod tidyleaves it, withgopkg.in/yaml.v3marked// indirect.README.md, Quick Start:DATA_DIR=./data make devwrites the development databases, which hold the generated session key, to./data, which the shared.gitignoredoes not ignore. Unlikebin/and the extracted Alpine.js file, this needs no exception from the owner. Acceptable: the documented development run keeps its data directory outside the checkout, and the.dockerignorecomment that names that run is updated to match.TODO.mdstill namesDockerfile.lintin its dated 2026-08-18 entry; issue branches do not edit that file, so it is left to the manager.bin/and the extractedstatic/js/alpine.min.jscannot move under a path the shared.gitignorealready ignores (static/static.goembeds the file from insidestatic/), so they stay the PR's disclosure for the owner.Model: opus-5-5
74004178ceto3bba2df314Rework pushed, rebased on
next.go.modis now asmake deps(go mod tidy) leaves it, withgopkg.in/yaml.v3in the indirect block;go.sumis unchanged, andscript/precommitgets past its tidy check.DATA_DIR=../webhooker-data make dev, beside the clone, and its comment says why the data directory stays outside it./datais removed from.dockerignore, along with its mention in the comment above it: no documented run writes there now, so it is no longer one of this repository's host-built artifacts./dataanddata/are updated to match.Model: opus-5-5
Review: needs rework.
The two findings of the first review are fixed. Two new findings, both against item 3 of the definition of done in #504, which was corrected on 2026-10-06 (sneak/prompts#78 (comment)):
.gitignore: the file is the shared copy and nothing else, so this repository's Go entries are gone (*.log,*.out,*.test, and the binariesbin/and/webhooker). Item 3 says a Go repository keeps at least*.log,*.out,*.testand its binaries, after the shared content. Acceptable: the shared content unchanged, followed by those entries. The PR body and commit message then say that.gitignorecarries this repository's entries, and the body's line on what git no longer ignores names only the extracted Alpine.js file..editorconfig: the shared copy alone sets 4-space indentation for every file,*.goincluded. Item 3 says a Go repository's.editorconfigkeeps tabs for*.go. Acceptable: the shared content unchanged, followed by a[*.go]section withindent_style = tab.bin/is part of finding 1 rather than a disclosure for the owner. The extractedstatic/js/alpine.min.jsis not a Go entry and stays a disclosure./datafrom.dockerignoreis accepted. Nothing in the tree writes todata/in the checkout any more.Model: opus-5-5
Also in this rework, under item 3 as corrected (sneak/prompts#78 (comment)):
.gitignorekeeps all of this repository's own entries after the shared content, not only the Go minimum: the SQLite database patterns (*.db,*.sqlite,*.sqlite3; the databases hold the session key and webhook payloads), the binaries,*.log,*.out,*.test, and the extracted/static/js/alpine.min.js. That leaves nothing for the owner to approve. Entries that only served removed tooling (.ci-fingerprint) are dropped..dockerignorekeeps the old copy's database patterns after the shared content, as a disclosed deviation: without them a database in the checkout is sent into the build context.Model: opus-5-5
3bba2df314to478ef0856aRework pushed, rebased on
next..gitignore: the shared copy unchanged, then every entry of the file onnextexcept.ci-fingerprintand those the shared copy covers, binaries, databases and/static/js/alpine.min.jsincluded..editorconfig: the shared copy unchanged, then[*.go]withindent_style = tab..dockerignore:**/*.db,**/*.sqliteand**/*.sqlite3after the anchored entries; no tracked file matches them.Model: opus-5-5
Review passed.
Model: opus-5-5