Add the "Git excludes" step to the overview, the sample plan, the numbered
run steps and a new section: which paths are excluded and why, that nothing
is committed or changed in a tracked file, that the entries live in
.git/info/exclude and so are not shared with a clone, what happens to a path
git already tracks, and how to track one anyway. Add the tracked-path case to
the error table and the new roles of git.sh and framework.sh to the code
layout.
Closes#67
The `.env` (credentials) section now points to howto/create-access-tokens.md
next to the Token permissions reference, so a reader who needs a token finds
the step-by-step guide where the credentials are described.
howto/create-access-tokens.md walks through creating the Gitea access token
and the GitHub classic personal access token that RepoFoundry needs, with nine
illustrations in howto/img/, how to hand the tokens to the script, how to keep
them safe and what the script's token errors mean.
The README's Token permissions section now links to it.
create_local_project no longer adds a github remote, with or without GitHub:
a push to origin reaches GitHub through the push mirror. A github remote that
already exists, such as one made by an earlier version, is left as it is, and
a different origin is still refused.
- Remove github_remote_url, which nothing else used
- README describes the one remote and how to remove an old github remote
- Tests: origin is the only remote with and without GitHub, no GitHub address
in .git/config, and an existing github remote is kept
Task: MIL-008#1
Task: MIL-008#2
Task: MIL-008#3
- README: start from the folder where the project is created, make the script a global command, where config.env and .env are read from and the confirmation
- Tests: qc tests set up the temp directory and force a real failure; the default-files test runs from a folder without files of its own; the link test allows for path aliases; the work directory cleanup deletes links
Task: MIL-007#3
Task: MIL-007#4
Refs #49
Refs #51
- PROJECT_LICENSE (a Gitea license key, or none) is read, checked and never asked
- Without it AGPL-3.0 applies only when GitHub is chosen and the project is public
- The license is applied on Gitea with or without GitHub, and checked against the server first
- Plan and summary name the license and where it came from
- MIL-006 accepted; README and config.env.example document the key
- Tests: new test-license.sh; existing tests use a public project where they expect AGPL-3.0
Task: MIL-006#1
Task: MIL-006#2
Task: MIL-006#3
Task: MIL-006#4
Refs #44
Refs #45
Refs #46
Refs #50
.env becomes optional. A credential it does not provide (an absent file, an
absent or empty key) is asked, without echo: GITEA_TOKEN at the start,
GITHUB_PAT and GITHUB_USER once GitHub is chosen. An invalid value is asked
again and never shown; when input ends the run stops before any request.
Asked tokens are registered for redaction at once.
After the local project exists the script asks (default no) whether to
create a .env in it. On a yes it holds only the needed keys, is created
private (mode 600) from the start, is excluded from git through
.git/info/exclude (no tracked file changes), is never replaced without a
second yes and is never written when git tracks it. The summary names the
keys, never the values.
New library files credentials.sh and envfile.sh; README, .env.example and
the security decisions updated; tests cover every case.
Task: MIL-005#1
Task: MIL-005#2
Task: MIL-005#3
Task: MIL-005#4
Task: MIL-005#5
Closes#35Closes#36Closes#37Closes#38Closes#39
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- Say in the README and config.env.example that a value containing " #"
must be quoted, and pin both behaviours with a test.
- Say in the script header and the README that details set in config.env
are not asked.
- Record the review as RC-019 and link it in the traceability matrix.
Task: MIL-004#4
Task: MIL-004#5
Refs #30
Refs #31
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Eight optional keys (PROJECT_NAME, PROJECT_DESCRIPTION, PROJECT_VISIBILITY,
GITEA_OWNER, USE_GITHUB, GITHUB_OWNER, PROJECT_DIRECTORY, ENABLE_PLAN_GATE)
are read and checked with the validators the prompts use. A key that is
present counts as set (only the description may be empty); it is not asked
and the summary marks it "(from config.env)". An invalid value stops the
run before any request and names the key. USE_GITHUB=no skips the GitHub
owner and warns about a stray GITHUB_OWNER. The confirmations stay
interactive. Keys and an example are documented; tests cover every key.
Task: MIL-004#1
Task: MIL-004#2
Task: MIL-004#3
Task: MIL-004#4
Task: MIL-004#5
Closes#27Closes#28Closes#29Closes#30Closes#31
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- Close stdin for ssh, git, curl and the framework scripts, so a real ssh
no longer swallows answers meant for later prompts.
- Count LICENSE and LICENSE + README.md (what Gitea creates) as content
the script made, so a partly created repository can be reused.
- Document the observed token scopes (write:user for user-owned Gitea
repositories) and the Gitea README.md in the README.
- Correct criterion 2 of MIL-002 (new Proposed version row).
- Record the run and the final security review as RC-017.
- Tests: stdin regression, initial_only reuse, other files count as
content, example config needs its address edited.
Task: MIL-003#6
Task: MIL-002#1
Refs #20
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
After the repositories and the mirror, the script now creates the local
project: the directory, git on main, credential-free origin (and github)
remotes, and the license history from Gitea. Then it adds the framework as
a submodule over SSH, installs its skills and git hooks once (plan gate
optional), and copies the AGENTS.md and artifact registry templates.
Nothing is overwritten without a yes: an existing directory, core.hooksPath,
AGENTS.md or docs/artifact-registry.md each ask first (default no). Without
SSH the framework steps can only be skipped, after a yes. No commit is made
in the new project. New optional config key FRAMEWORK_REPO.
New library files git.sh, localproject.sh and framework.sh. Tests run real
git against local bare repositories that stand in for Gitea and the
framework, with a private git configuration (769 checks). The README is now
the full guide.
Task: MIL-003#1
Task: MIL-003#2
Task: MIL-003#3
Task: MIL-003#4
Task: MIL-003#5
Refs #15
Refs #16
Refs #17
Refs #18
Refs #19
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Dry run by default: the script reads from both hosts (tokens, owners,
names, license, SSH) and prints a plan; --apply creates the repositories
and the Gitea -> GitHub push mirror after a final yes. Choosing GitHub
applies the AGPL-3.0 license to the Gitea repository. A failed step is
reported with what exists and how to continue; nothing is ever deleted.
create-project.sh is now the entry point; the work lives in src/lib/, one
responsibility per file. .gitignore gets !src/lib (the Python template
ignores any lib/ folder). Tests grow to 599 checks, with a stub curl and
ssh, and guards for the file structure.
Task: MIL-002#1
Task: MIL-002#2
Task: MIL-002#3
Task: MIL-002#4
Task: MIL-002#5
Task: MIL-002#6
Refs #9
Refs #10
Refs #11
Refs #12
Refs #13
Refs #14
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>