S02 gave the Go in chat on 2026-10-08 and waived the PlantUML render check
(no PlantUML server is configured). Add the review record RC-032, set the
latest Version History rows of MIL-009 and the changed documents to Accepted
and the rows before them to Deprecated, and record the review in the
traceability matrix.
Add the phase MIL-009 (proposed 2026-12-21 to 2026-12-23): after the
framework is installed, the new project excludes .claude, .agents and
AGENTS.md through its own .git/info/exclude, so no tracked file changes.
The analysis and design documents agree with it: Business Case objective 5,
US-001.03, UC-001 (postcondition, step 9, extension 9f, a rule), OC-001 (P15
and two exceptions), SD-001, DCD-001 and DCD-002 (excludeFromGit,
trackedPaths), and the Framework Setup and Template definitions in DM-001,
DM-002 and the dictionary.
Refs #65
Refs #66
Refs #67
Refs #68
Refs #69
The `.env` (credentials) section now points to howto/create-access-tokens.md
next to the Token permissions reference, so a reader who needs a token finds
the step-by-step guide where the credentials are described.
howto/create-access-tokens.md walks through creating the Gitea access token
and the GitHub classic personal access token that RepoFoundry needs, with nine
illustrations in howto/img/, how to hand the tokens to the script, how to keep
them safe and what the script's token errors mean.
The README's Token permissions section now links to it.
- RC-031 is Accepted with a Go verdict and no open action items
- MIL-008 and the documents it changes are set to Accepted (previous rows
Deprecated): BC-001, US-001, UC-001, OC-001, SD-001, DCD-001, DCD-002,
DM-001, DM-002, MIL-003, PP-001 and TM-001
The version is raised to 0.3.1 and release v0.3.1 is tagged on Gitea from the
merge commit once the pull request is merged. MIL-008 gets task 4 and
criterion 7; RC-031 counts seven criteria.
create_local_project no longer adds a github remote, with or without GitHub:
a push to origin reaches GitHub through the push mirror. A github remote that
already exists, such as one made by an earlier version, is left as it is, and
a different origin is still refused.
- Remove github_remote_url, which nothing else used
- README describes the one remote and how to remove an old github remote
- Tests: origin is the only remote with and without GitHub, no GitHub address
in .git/config, and an existing github remote is kept
Task: MIL-008#1
Task: MIL-008#2
Task: MIL-008#3
A project created by the script had two remotes, origin (Gitea) and github.
Gitea already pushes to GitHub through the push mirror, so the second remote
is not needed and invites a push that goes around the mirror.
- MIL-008 and its review record RC-031
- Objective 4, US-001.03, UC-001 step 8, OC-001 P9, SD-001, DCD-001, DCD-002,
DM-001 and DM-002 describe one remote; MIL-003 criterion 1 and task 1 follow
- Project plan and traceability matrix list MIL-008 and RC-031
- Review records RC-022 to RC-030 are Accepted
- The documents they review are set to Accepted (previous rows Deprecated)
- RC-028 and RC-029: Go-with-conditions becomes Go; the two action items are closed
- OC-001, SD-001 and DCD-001 carry a note that the UC-002 documents supersede the startProjectCreation signature
- README: start from the folder where the project is created, make the script a global command, where config.env and .env are read from and the confirmation
- Tests: qc tests set up the temp directory and force a real failure; the default-files test runs from a folder without files of its own; the link test allows for path aliases; the work directory cleanup deletes links
Task: MIL-007#3
Task: MIL-007#4
Refs #49
Refs #51
- git submodule update --init --recursive after adding or reusing the framework
- Follow links to the script so SCRIPT_DIR and the checkout are the real ones
- config.env and .env: --config/--env, else ./ in the working folder, else the checkout's
- Name the files used; a file from the working folder needs a yes before any request
- MIL-007 accepted; test fixtures for the qc checklists; tests/test-launch.sh
Work in progress: the README section is not written yet, and four tests of
test-launch.sh fail and two shellcheck warnings remain; they are fixed next.
Task: MIL-007#1
Task: MIL-007#2
Refs #47
Refs #48
Refs #51
- PROJECT_LICENSE (a Gitea license key, or none) is read, checked and never asked
- Without it AGPL-3.0 applies only when GitHub is chosen and the project is public
- The license is applied on Gitea with or without GitHub, and checked against the server first
- Plan and summary name the license and where it came from
- MIL-006 accepted; README and config.env.example document the key
- Tests: new test-license.sh; existing tests use a public project where they expect AGPL-3.0
Task: MIL-006#1
Task: MIL-006#2
Task: MIL-006#3
Task: MIL-006#4
Refs #44
Refs #45
Refs #46
Refs #50
- --config and --env, else ./config.env and ./.env, else the checkout's
- Files named before any request; a file from the working folder needs a yes
- UC-002, US-002, MIL-007 criteria 9 and 10, models and contracts updated
- Review record RC-029
- MIL-006: the AGPL-3.0 default needs GitHub and a public project
- MIL-007: fetch the framework's own submodules (qc); start through a command link; README usage
- UC-002 with SSD, DM, OC, SD and DCD; US-001.07 and US-002
- Reconcile the project DM, DCD, dictionary, use case diagram and traceability matrix
- Review records RC-022 to RC-028
Add objective 10 to the Business Case, US-001.06 and the use case, SSD, OC,
SD, DM-001, DM-002, dictionary, DCD-001 and DCD-002 changes: a license set
in config.env (PROJECT_LICENSE, a Gitea license key or none) applies with or
without GitHub; when absent AGPL-3.0 applies only when GitHub is chosen. It
is never asked, and a license the server does not offer stops the run
before anything is created.
Add milestone MIL-006 (8 Go/No-Go criteria, 4 tasks) and its phase in the
Project Plan. All new rows are Proposed.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
.env becomes optional. A credential it does not provide (an absent file, an
absent or empty key) is asked, without echo: GITEA_TOKEN at the start,
GITHUB_PAT and GITHUB_USER once GitHub is chosen. An invalid value is asked
again and never shown; when input ends the run stops before any request.
Asked tokens are registered for redaction at once.
After the local project exists the script asks (default no) whether to
create a .env in it. On a yes it holds only the needed keys, is created
private (mode 600) from the start, is excluded from git through
.git/info/exclude (no tracked file changes), is never replaced without a
second yes and is never written when git tracks it. The summary names the
keys, never the values.
New library files credentials.sh and envfile.sh; README, .env.example and
the security decisions updated; tests cover every case.
Task: MIL-005#1
Task: MIL-005#2
Task: MIL-005#3
Task: MIL-005#4
Task: MIL-005#5
Closes#35Closes#36Closes#37Closes#38Closes#39
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Add objective 9 to the Business Case (and amend objective 6 and success
criterion 1: a token may be written only to the new project's .env after a
yes), US-001.05, UC-001 extensions 2b, 9c and 9d, with the SSD, OC, SD,
DM-001, DM-002 and dictionary in step. Add the classes CredentialCollector,
EnvFileWriter and EnvFile to DCD-001 and DCD-002, and both ends'
multiplicities to every association. Restore three lines of SD-001 damaged
by an earlier edit.
Add milestone MIL-005 (9 Go/No-Go criteria, 5 tasks) and its phase in the
Project Plan. Accept the planning set and the two DCDs; reviews recorded in
RC-020 and RC-021.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- DCD-001 (UC-001): design classes refining DM-001, with class table,
method traceability to OC-001 and SD-001, patterns and dependency check,
and the mapping of each class to src/lib.
- DCD-002: the consolidated project-level model, created from DCD-001.
- SD-001: messages aligned with the DCD method signatures; cites DCD-001.
- Dictionary, registry and traceability matrix updated.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The repeated run with a write:user token passes on both hosts, so
criterion 7 is now Pass; only the README review (criterion 6) remains.
Refs #20
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>