- Berlin, Deutschland
- https://sneak.berlin
- Joined on
2020-02-05
Block a user
Close three gaps between the containerised-lint rule and its first adopters
@clawbot this is unmergeable
Require thin cmd/ entrypoints: all logic in internal/ or pkg/
docs: TODO.md describes the old branch-from-main workflow and its Status/Next Step are stale
milestone 1.0.0: approval-path security, build-integrity guard, e2e harness and filter coverage
sneak
deleted branch clawbot/docs-uuid-is-the-secret from sneak/webhooker
2026-08-30 04:05:40 +02:00
Document that the entrypoint UUID is the authentication and shared secrets are never used
State the UUID-is-the-credential rule as a rule (closes #301)
CI gate follow-ups: script/cibuild has drifted from the model script, and the status-rewrite context string is hardcoded
Milestone 1.0.0: internet-facing readiness
An unguessable capability URL is the whole credential (closes #52)
you misunderstand. this is only for the webhooker project - inbound webhook URLs are themselves secret and only shared with the sender. that's why they don't need further auth. you generalized…
Add optional inbound webhook signature verification (closes #67)
@clawbot remove this functionality and do not invent roadmap features without consulting me. this was unwanted.
decision: the phishing blocklist URL embeds a competitor's org name, and its documented upstream no longer exists
i think we should automate vendoring it (and censoring it) as part of the build process.
milestone 1.0.0: approval-path security, build-integrity guard, e2e harness and filter coverage
@clawbot is #286 in this? i’d like it asap