- Close stdin for ssh, git, curl and the framework scripts, so a real ssh
no longer swallows answers meant for later prompts.
- Count LICENSE and LICENSE + README.md (what Gitea creates) as content
the script made, so a partly created repository can be reused.
- Document the observed token scopes (write:user for user-owned Gitea
repositories) and the Gitea README.md in the README.
- Correct criterion 2 of MIL-002 (new Proposed version row).
- Record the run and the final security review as RC-017.
- Tests: stdin regression, initial_only reuse, other files count as
content, example config needs its address edited.
Task: MIL-003#6
Task: MIL-002#1
Refs #20
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
create-project.sh validates config.env and .env (parsed, never sourced),
checks the required tools, asks for the project details and prints a
summary. It makes no network call and no change on disk yet.
- config.env.example and .env.example hold placeholders only
- tokens go through a private curl config file, never the command line
- tests run in private directories with a stub curl; shellcheck and shfmt
are part of tests/run-tests.sh
Task: MIL-001#1
Task: MIL-001#2
Task: MIL-001#3
Task: MIL-001#4
Task: MIL-001#5
Task: MIL-001#6
Closes#3Closes#4Closes#5Closes#6Closes#7Closes#8
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>