6 Commits
Author SHA1 Message Date
TirsvadandClaude Sonnet 5.5 53b6c274ac Resolve pending commit link for RC-017
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-06 01:56:10 +08:00
TirsvadandClaude Sonnet 5.5 ef87e73954 Record the user-owner end-to-end run (run A2) in RC-017
The repeated run with a write:user token passes on both hosts, so
criterion 7 is now Pass; only the README review (criterion 6) remains.

Refs #20

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-06 01:56:09 +08:00
TirsvadandClaude Sonnet 5.5 55d9ca6eee Add a section banner to .env.example
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-06 00:27:00 +08:00
TirsvadandClaude Sonnet 5.5 6b1b9c6af4 Ignore config.env
The file holds the Maintainer's own addresses and project details, so it
stays out of the repository like .env.

Refs #31

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-06 00:25:48 +08:00
TirsvadandClaude Sonnet 5.5 4634048eab Resolve pending commit link for RC-019
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 23:18:30 +08:00
TirsvadandClaude Sonnet 5.5 ceaa7d18d8 Code review of MIL-004: document quoting of values, add RC-019
- Say in the README and config.env.example that a value containing " #"
  must be quoted, and pin both behaviours with a test.
- Say in the script header and the README that details set in config.env
  are not asked.
- Record the review as RC-019 and link it in the traceability matrix.

Task: MIL-004#4
Task: MIL-004#5
Refs #30
Refs #31

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 23:18:29 +08:00
10 changed files with 108 additions and 13 deletions
+4
View File
@@ -12,6 +12,10 @@
# chosen owner and to push to the new one. Prefer a fine-grained token. # chosen owner and to push to the new one. Prefer a fine-grained token.
GITHUB_PAT= GITHUB_PAT=
########################################
# Secrets for workframe
########################################
# GitHub account the token belongs to. It identifies who authenticates; it is # GitHub account the token belongs to. It identifies who authenticates; it is
# only a default suggestion for the owner prompt, because the repository can # only a default suggestion for the owner prompt, because the repository can
# belong to an organization. # belong to an organization.
+1
View File
@@ -187,3 +187,4 @@ repofoundry.*/
!src/lib !src/lib
config.env
+5 -1
View File
@@ -115,6 +115,9 @@ A detail that is set is used and not asked; the summary marks it with
default to no: create now, reusing an existing repository, an existing default to no: create now, reusing an existing repository, an existing
directory, `core.hooksPath` and replacing a template file. directory, `core.hooksPath` and replacing a template file.
- These keys are accepted in `config.env` only, never in `.env`. - These keys are accepted in `config.env` only, never in `.env`.
- A value is read as plain text: an unquoted ` #` starts a comment and cuts the
value there. Put a description that contains ` #` in double quotes, for
example `PROJECT_DESCRIPTION="Tool for #mirrors"`.
With all eight set, a run asks only the confirmations: With all eight set, a run asks only the confirmations:
@@ -144,7 +147,8 @@ src/create-project.sh --config /path/to/config.env --env /path/to/.env
The script asks for, in this order: repository name, description, visibility, The script asks for, in this order: repository name, description, visibility,
Gitea owner, whether to also create a GitHub repository (and its owner), the Gitea owner, whether to also create a GitHub repository (and its owner), the
local directory and whether to enable the plan gate. It then checks both hosts local directory and whether to enable the plan gate (a detail set in
[`config.env`](#configenv-project-details-optional) is not asked). It then checks both hosts
with read-only requests and prints a plan: with read-only requests and prints a plan:
```text ```text
+2 -1
View File
@@ -35,7 +35,8 @@ GITEA_API_URL=https://<your gitea instance>/api/v1
# empty. An invalid value stops the run and names the key. Remove or comment # empty. An invalid value stops the run and names the key. Remove or comment
# out a line to be asked for it. The confirmations ("Create these now" and # out a line to be asked for it. The confirmations ("Create these now" and
# the questions about existing repositories, directories and files) are # the questions about existing repositories, directories and files) are
# always asked. # always asked. Put a value that contains " #" in double quotes: an unquoted
# " #" starts a comment.
#PROJECT_NAME=my-project #PROJECT_NAME=my-project
#PROJECT_DESCRIPTION=What the project is for #PROJECT_DESCRIPTION=What the project is for
#PROJECT_VISIBILITY=private # private or public #PROJECT_VISIBILITY=private # private or public
+1 -1
View File
@@ -23,7 +23,7 @@ document of a type. `Primary File` may contain a glob (e.g.
| DM | Domain Model | docs/domain-model.md | 003 | | DM | Domain Model | docs/domain-model.md | 003 |
| DICT | Domain Dictionary (PO and IT terms) | docs/dictionary.md | 002 | | DICT | Domain Dictionary (PO and IT terms) | docs/dictionary.md | 002 |
| UCD | Use Case Diagram | docs/use-case-diagram.md | 002 | | UCD | Use Case Diagram | docs/use-case-diagram.md | 002 |
| RC | SQA Review Record | docs/sqa/reviews/rc-*.md | 019 | | RC | SQA Review Record | docs/sqa/reviews/rc-*.md | 020 |
| TM | Traceability Matrix | docs/sqa/traceability-matrix.md | 002 | | TM | Traceability Matrix | docs/sqa/traceability-matrix.md | 002 |
## Languages ## Languages
+11 -8
View File
@@ -10,6 +10,7 @@
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version | [613a288] | | 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version | [613a288] |
| 2026-10-06 | Proposed | Jens Tirsvad Nielsen | S02 | Run A repeated with a `write:user` token: passes; criterion 7 now Pass; only the README review remains | [ef87e73] |
--- ---
@@ -18,7 +19,7 @@
- Instance reviewed: the whole flow of `src/create-project.sh` (branch `mil-003-scaffold-and-release` plus the fixes below), run against real GitHub and Gitea repositories; this is task 6 (issue #20) of [MIL-003] and the live evidence for [MIL-002]. - Instance reviewed: the whole flow of `src/create-project.sh` (branch `mil-003-scaffold-and-release` plus the fixes below), run against real GitHub and Gitea repositories; this is task 6 (issue #20) of [MIL-003] and the live evidence for [MIL-002].
- Checklist used: the Go/No-Go criteria of [MIL-003] and the credential, ownership, mirror, submodule and API items named in its task 6. No QC checklist covers an end-to-end run; the code itself was reviewed in [RC-016]. - Checklist used: the Go/No-Go criteria of [MIL-003] and the credential, ownership, mirror, submodule and API items named in its task 6. No QC checklist covers an end-to-end run; the code itself was reviewed in [RC-016].
- Review date: 2026-10-05 - Review date: 2026-10-05
- Hosts: Gitea 1.27.3 at `git.tirsystem.com` (SSH on port 10022) and GitHub; real tokens from `.env` (a classic GitHub token with `repo` and `admin:org`; a Gitea token with `write:repository`, `write:organization`, `read:user` and other scopes, but not `write:user`). - Hosts: Gitea 1.27.3 at `git.tirsystem.com` (SSH on port 10022) and GitHub; real tokens from `.env` (a classic GitHub token with `repo` and `admin:org`; a Gitea token with `write:repository`, `write:organization`, `read:user` and other scopes; it lacked `write:user` until run A2, which used a token that has it).
## End-to-end runs ## End-to-end runs
@@ -27,9 +28,10 @@
| Dry run | `Tirsvad` on both hosts | All preflight checks passed; nothing created. | | Dry run | `Tirsvad` on both hosts | All preflight checks passed; nothing created. |
| First `--apply` | `Tirsvad` on both hosts | Stopped before creating anything: **a defect** (see finding F1). | | First `--apply` | `Tirsvad` on both hosts | Stopped before creating anything: **a defect** (see finding F1). |
| A, after the fix | user `Tirsvad` on both hosts | GitHub repository created. Gitea refused: `required=[write:user]`, which the token lacks. The script stopped, reported what existed (GitHub created, Gitea FAILED, the rest not attempted) and how to continue, and deleted nothing. | | A, after the fix | user `Tirsvad` on both hosts | GitHub repository created. Gitea refused: `required=[write:user]`, which the token lacks. The script stopped, reported what existed (GitHub created, Gitea FAILED, the rest not attempted) and how to continue, and deleted nothing. |
| A2 | user `Tirsvad` on both hosts, repeated on 2026-10-06 with a `write:user` token; all eight project details came from `config.env` (MIL-004), so only "Create these now" and the reuse of the empty GitHub repository were asked | Everything created: the Gitea repository under the user account, the mirror, the local project, the framework, skills, hooks and templates; the empty GitHub repository left by run A was reused after confirmation. No warning. |
| B | organization `TirSystem-BashScript` on both hosts, plan gate on | Everything created: both repositories, the mirror, the local project, the framework, skills, hooks, plan gate and templates. No warning. | | B | organization `TirSystem-BashScript` on both hosts, plan gate on | Everything created: both repositories, the mirror, the local project, the framework, skills, hooks, plan gate and templates. No warning. |
After run B the following was checked independently of the script's own report: After run A2 the following was checked independently of the script's own report: Gitea repository private, owner the user `Tirsvad`, default branch `main`, contents `LICENSE` and `README.md`; push mirror to `https://github.com/Tirsvad/repofoundry-e2e-user.git`, interval `10m0s`, `sync_on_commit` true, `last_error` empty; GitHub repository private with `LICENSE`, `README.md` and the one `Initial commit` that arrived through the mirror; local project on `main` with one commit, `origin` over SSH on port 10022 and `github` over HTTPS, neither with a credential, the framework submodule in place, `core.hooksPath` set and nothing committed by the script; neither token found in the project, its `.git` folder or the run output. The checks below were made after run B and still hold:
- **Gitea:** private, owner the organization, default branch `main`, contents `LICENSE` and `README.md`; push mirror to `https://github.com/TirSystem-BashScript/repofoundry-e2e-org.git`, interval `10m0s`, `sync_on_commit` true, `last_error` empty. - **Gitea:** private, owner the organization, default branch `main`, contents `LICENSE` and `README.md`; push mirror to `https://github.com/TirSystem-BashScript/repofoundry-e2e-org.git`, interval `10m0s`, `sync_on_commit` true, `last_error` empty.
- **GitHub:** private, owner the organization, contents `LICENSE` and `README.md`, one commit `Initial commit` (arrived through the mirror). - **GitHub:** private, owner the organization, contents `LICENSE` and `README.md`, one commit `Initial commit` (arrived through the mirror).
@@ -47,7 +49,7 @@ After run B the following was checked independently of the script's own report:
| 4 | With the plan gate enabled, a commit touching `src/` or `tests/` without a `Task: MIL-NNN#N` trailer is refused | Pass | Run B, for real. | | 4 | With the plan gate enabled, a commit touching `src/` or `tests/` without a `Task: MIL-NNN#N` trailer is refused | Pass | Run B, for real. |
| 5 | An existing `core.hooksPath` is reported and not replaced without consent | Pass | Verified by the automated tests with real git (local and global setting); not repeated on the real hosts. | | 5 | An existing `core.hooksPath` is reported and not replaced without consent | Pass | Verified by the automated tests with real git (local and global setting); not repeated on the real hosts. |
| 6 | README covers installation, configuration, usage examples, security decisions, error handling and stakeholders, in clear English | N-A | The sections are written; the review by S02 has not happened yet (action item). | | 6 | README covers installation, configuration, usage examples, security decisions, error handling and stakeholders, in clear English | N-A | The sections are written; the review by S02 has not happened yet (action item). |
| 7 | End-to-end run on disposable repositories passes and the final review records no open security finding | Fail | No open security finding, and the organization-owner run passes on both hosts. The user-owner run could not be completed on Gitea (token scope). | | 7 | End-to-end run on disposable repositories passes and the final review records no open security finding | Pass | No open security finding. The organization-owner run (B) and the user-owner run (A2, with a `write:user` token) both pass on both hosts. |
| 8 | All acceptance criteria of US-001.03 in [US-001] are met | Pass | Run B: remotes without credentials, framework, skills, hooks, plan gate and templates in place; the "asks first" criterion by the automated tests. | | 8 | All acceptance criteria of US-001.03 in [US-001] are met | Pass | Run B: remotes without credentials, framework, skills, hooks, plan gate and templates in place; the "asks first" criterion by the automated tests. |
## Final security review ## Final security review
@@ -55,7 +57,7 @@ After run B the following was checked independently of the script's own report:
| Item | Result | Evidence | | Item | Result | Evidence |
| --- | --- | --- | | --- | --- | --- |
| Credential handling | No finding | Both tokens were searched for in every file of the new project, including the whole `.git` folder, and in all output of all runs: zero hits. Remote addresses and `.gitmodules` carry no credential. Tokens went to `curl` through a private configuration file and, for an HTTPS fetch, to git through `GIT_ASKPASS` and the environment (covered by tests; the live runs used SSH). | | Credential handling | No finding | Both tokens were searched for in every file of the new project, including the whole `.git` folder, and in all output of all runs: zero hits. Remote addresses and `.gitmodules` carry no credential. Tokens went to `curl` through a private configuration file and, for an HTTPS fetch, to git through `GIT_ASKPASS` and the environment (covered by tests; the live runs used SSH). |
| Repository ownership | No finding | Created under the owner chosen at the prompt on both hosts (organization in run B; GitHub user in run A). `GITHUB_USER` was only a default. | | Repository ownership | No finding | Created under the owner chosen on both hosts (organization in run B; the user account on both hosts in run A2). `GITHUB_USER` was only a default. |
| Mirror direction | No finding | Gitea is the source: a branch pushed to Gitea reached GitHub on its own. Nothing was pushed from GitHub; that direction was not tested. | | Mirror direction | No finding | Gitea is the source: a branch pushed to Gitea reached GitHub on its own. Nothing was pushed from GitHub; that direction was not tested. |
| Submodule setup | No finding | Added over SSH on port 10022 from the configured framework repository; the SSH test and the host key check passed. | | Submodule setup | No finding | Added over SSH on port 10022 from the configured framework repository; the SSH test and the host key check passed. |
| API limitations | Findings F2 to F4 | `sync_on_commit` was applied on Gitea 1.27.3 (the upstream bug did not occur). Token scopes and the README Gitea adds are covered below. | | API limitations | Findings F2 to F4 | `sync_on_commit` was applied on Gitea 1.27.3 (the upstream bug did not occur). Token scopes and the README Gitea adds are covered below. |
@@ -80,18 +82,18 @@ External prerequisites: bash 4.4 or later, `git`, `curl`, `mktemp`; optional `jq
- Gitea: `TirSystem-BashScript/repofoundry-e2e-org` (private; branches `main` and `work`). - Gitea: `TirSystem-BashScript/repofoundry-e2e-org` (private; branches `main` and `work`).
- GitHub: `TirSystem-BashScript/repofoundry-e2e-org` (private; branches `main` and `work`). - GitHub: `TirSystem-BashScript/repofoundry-e2e-org` (private; branches `main` and `work`).
- GitHub: `Tirsvad/repofoundry-e2e-user` (private, empty; created by run A). - Gitea: `Tirsvad/repofoundry-e2e-user` (private; branch `main`; created by run A2).
- A local temporary directory with the run output and the new project. - GitHub: `Tirsvad/repofoundry-e2e-user` (private; branch `main`; created by run A, reused by run A2).
- Local temporary directories with the run output and the new projects.
## Overall Verdict ## Overall Verdict
Go-with-conditions — No open security finding, the organization-owner flow works end to end on both hosts, and the two defects the live run found are fixed with regression tests. Criterion 6 awaits the README review, and criterion 7 is not complete because the user-owner run could not finish on Gitea without `write:user`. Author and reviewer are the same person for now (S01 and S02 are both held by the Maintainer), so the framework independence rule is not met; re-review when a second person takes S02. Go-with-conditions — No open security finding, both the organization-owner flow (run B) and the user-owner flow (run A2) work end to end on both hosts, and the two defects the live run found are fixed with regression tests. The one condition left is criterion 6: the README review by S02. Author and reviewer are the same person for now (S01 and S02 are both held by the Maintainer), so the framework independence rule is not met; re-review when a second person takes S02.
## Action Items ## Action Items
| Action | Owner | Due | | Action | Owner | Due |
| --- | --- | --- | | --- | --- | --- |
| Create a Gitea token that also has `write:user` and repeat run A (the empty GitHub repository `Tirsvad/repofoundry-e2e-user` is offered for reuse) to complete criterion 7 | S01 | 2026-10-16 |
| Review the README against criterion 6 | S02 | 2026-10-12 | | Review the README against criterion 6 | S02 | 2026-10-12 |
| Accept the corrected criterion 2 of [MIL-002] (version row `Proposed`) | S02 | 2026-10-12 | | Accept the corrected criterion 2 of [MIL-002] (version row `Proposed`) | S02 | 2026-10-12 |
| Delete the disposable repositories listed above in the web interfaces | S01 | 2026-10-12 | | Delete the disposable repositories listed above in the web interfaces | S01 | 2026-10-12 |
@@ -105,3 +107,4 @@ Go-with-conditions — No open security finding, the organization-owner flow wor
[RC-016]: ./rc-016-create-project-sh.md [RC-016]: ./rc-016-create-project-sh.md
[US-001]: ../../user-stories.md [US-001]: ../../user-stories.md
[613a288]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/613a288dead4c19c00dee6fbb60d46bc3edf8889 [613a288]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/613a288dead4c19c00dee6fbb60d46bc3edf8889
[ef87e73]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/ef87e7395482da9fad854cd5db7f16200bb8c8af
+70
View File
@@ -0,0 +1,70 @@
# SQA Review Record: Shell code review of the MIL-004 change
## Metadata
| Key | Value |
| --- | --- |
| ID | RC-019 |
| CrossReference | [MIL-004], [QC-SH-001], [RC-016] |
## Version History
| Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version | [ceaa7d1] |
---
## Artifact Under Review
- Instance reviewed: the MIL-004 change to `src/create-project.sh` and `src/lib/` (`config.sh`, `constants.sh`, `project.sh`), `tests/test-presets.sh`, the README and `config.env.example`, on branch `mil-004-configurable-details` (commit `75e8e91` plus the fixes listed below), tasks 1 to 5 (issues #27 to #31) of [MIL-004].
- Checklist used: [QC-SH-001]. The rest of the code was reviewed in [RC-016].
- Review date: 2026-10-05
- Tool versions: bash 5.2.37, shellcheck 0.11.0, shfmt 3.14.1 (Windows, Git Bash)
## Checklist Results
| # | Criterion | Status | Evidence/Notes |
| --- | --- | --- | --- |
| 1 | Starts with `#!/usr/bin/env bash` and `set -euo pipefail` | Pass | Unchanged. |
| 2 | Every expansion is quoted; lists are arrays; tests use `[[ ]]` and `$(...)` | Pass | `shellcheck` is clean. Values from `config.env` are only ever compared, matched against validators or printed; none reaches `eval`, a command line or a file name before it passed a validator. |
| 3 | Names follow the conventions | Pass | `check_preset`, `preset_detail`, `source_note` and the `HINT_*` constants follow the rules. See finding F4 on the name `PROJECT_NAME`. |
| 4 | Passes `shellcheck` and `bash -n` with no unexplained `disable` comments | Pass | No new `disable`. |
| 5 | Errors go to standard error with an `error:` message and a non-zero exit code | Pass | Every refusal goes through `die`, names the key and the file, never the value. |
| 6 | Temporary files use `mktemp` with a `trap` cleanup | Pass | Not touched. |
| 7 | No secret is written in the script, echoed, or put on a command line | Pass | The new keys carry no credential; they are rejected in `.env`, and credential keys stay rejected in `config.env` (tests). The description is printed in the summary, as it was when asked. |
| 8 | A script that changes state defaults to a dry run | Pass | Unchanged: a preset never skips the dry run or "Create these now". Tests prove that with all eight keys set, an empty or missing answer creates nothing. |
| 9 | A header comment states purpose, usage, options, environment variables and exit codes | Pass | Fixed during this review: the header said only "asks for the project details"; it now says that details set in `config.env` are not asked. |
| 10 | The script implements a task or design it cites; deviations are recorded | Pass | Tasks 1 to 5 of [MIL-004] and extensions 3a and 3b of [UC-001]. Deviations: values are accepted in any case, and `USE_GITHUB`/`ENABLE_PLAN_GATE` take `yes` or `no` only; both are in the README. |
| 11 | Behaviour is tested for success, failure and any disabled or bypass path | Pass | 919 checks in the full suite before the review, 0 failed. New: each key set, absent, empty and invalid; mixed asked and preset; `USE_GITHUB` interplay; the summary marker; no prompt text for a preset; the confirmations. Mutation check: making the preset lookup always fail made the tests fail. |
| 12 | Formatted with `shfmt` | Pass | No difference. |
| 13 | Safe to re-run | Pass | No state is kept. |
| 14 | Bash version and external tools stated | Pass | Unchanged. |
## Findings
| # | Finding | Severity | Status |
| --- | --- | --- | --- |
| F1 | An unquoted `PROJECT_DESCRIPTION` containing ` #` is silently cut at the comment mark (`Tool # for mirrors` becomes `Tool`), with no message. This is how the parser reads every value, but a description is the one free-text key, so it is where it bites. A value with both kinds of quote cannot be set at all (it can still be typed at the prompt). | Low (surprise, no data loss or security effect) | Fixed: the README and `config.env.example` say to put such a value in double quotes; a test pins both behaviours. The both-quotes case is documented as a limit of the parser. |
| F2 | The header of `create-project.sh` and the README sentence "The script asks for, in this order" did not mention that preset details are not asked. | Low (documentation) | Fixed. |
| F3 | The summary marks the source after the value, so a fully preset run reads `my-app (from config.env) (private (from config.env))`. Correct but noisy, and `USE_GITHUB=yes` is not marked on the GitHub line (only the owner is). | Low (readability) | Accepted: the marker is asserted by the tests and the wording is not a requirement; revisit if the Maintainer wants a table layout. |
| F4 | The constant `PROJECT_NAME` (the name of this tool, `RepoFoundry`) and the config key `PROJECT_NAME` (the name of the new project) share a spelling. They never meet in code (the key lives in `CONFIG`), but a reader can confuse them. | Low (maintainability) | Open: renaming the constant is out of scope for this change; a candidate for a later clean-up. |
| F5 | A `config.env` that sets `PROJECT_NAME` and `GITEA_OWNER` makes every run use them. Existing repositories are still detected and need the reuse confirmation, so nothing is overwritten. | Info | Documented in the README (per-project configuration). |
No finding affects credentials, ownership, the mirror direction or the confirmations.
## Overall Verdict
Go — all mandatory criteria pass after the fixes for F1 and F2 (found and fixed during this review; the test for F1 was added; the full suite was rerun afterwards: 923 checks, 0 failed). F3 and F4 are recorded and not blocking. Author and reviewer are the same person for now (S01 and S02 are both held by the Maintainer), so the framework independence rule is not met; re-review when a second person takes S02.
## Action Items
| Action | Owner | Due |
| --- | --- | --- |
| Decide whether to rename the constant `PROJECT_NAME` (F4) and whether to restyle the summary markers (F3) | S02 | 2026-10-30 |
---
[MIL-004]: ../../milestones/mil-004-configurable-details.md
[UC-001]: ../../uc-001/uc.md
[RC-016]: ./rc-016-create-project-sh.md
[QC-SH-001]: ../../../framework/qc/qc-programming-shell.md
[ceaa7d1]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/ceaa7d18d8908b4d1e3fb089f238c99b883d71e0
+2 -1
View File
@@ -30,7 +30,7 @@ updated whenever an artifact instance is created or reviewed.
| [MIL-001] | MIL | [BC-001], [PP-001] | [US-001] | [RC-011], [RC-016] | | [MIL-001] | MIL | [BC-001], [PP-001] | [US-001] | [RC-011], [RC-016] |
| [MIL-002] | MIL | [BC-001], [PP-001] | [US-001] | [RC-014], [RC-017] | | [MIL-002] | MIL | [BC-001], [PP-001] | [US-001] | [RC-014], [RC-017] |
| [MIL-003] | MIL | [BC-001], [PP-001] | [US-001] | [RC-015], [RC-017] | | [MIL-003] | MIL | [BC-001], [PP-001] | [US-001] | [RC-015], [RC-017] |
| [MIL-004] | MIL | [BC-001], [PP-001] | [US-001] | [RC-018] | | [MIL-004] | MIL | [BC-001], [PP-001] | [US-001] | [RC-018], [RC-019] |
| [UCD-001] | UCD | [BC-001], [SA-001] | [US-001], [UC-001] | [RC-009] | | [UCD-001] | UCD | [BC-001], [SA-001] | [US-001], [UC-001] | [RC-009] |
| [US-001] | US | [BC-001], [UCD-001], [MIL-001], [MIL-002], [MIL-003], [MIL-004] | [UC-001] | [RC-001] | | [US-001] | US | [BC-001], [UCD-001], [MIL-001], [MIL-002], [MIL-003], [MIL-004] | [UC-001] | [RC-001] |
| [UC-001] | UC | [UCD-001], [US-001], [SA-001] | [SSD-001], [DM-001] | [RC-002] | | [UC-001] | UC | [UCD-001], [US-001], [SA-001] | [SSD-001], [DM-001] | [RC-002] |
@@ -56,6 +56,7 @@ updated whenever an artifact instance is created or reviewed.
[MIL-003]: ../milestones/mil-003-scaffold-and-release.md [MIL-003]: ../milestones/mil-003-scaffold-and-release.md
[MIL-004]: ../milestones/mil-004-configurable-details.md [MIL-004]: ../milestones/mil-004-configurable-details.md
[RC-018]: ./reviews/rc-018-mil-004.md [RC-018]: ./reviews/rc-018-mil-004.md
[RC-019]: ./reviews/rc-019-mil-004-code.md
[UCD-001]: ../use-case-diagram.md [UCD-001]: ../use-case-diagram.md
[US-001]: ../user-stories.md [US-001]: ../user-stories.md
[UC-001]: ../uc-001/uc.md [UC-001]: ../uc-001/uc.md
+1 -1
View File
@@ -5,7 +5,7 @@
# RepoFoundry creates a Gitea repository, optionally an empty GitHub # RepoFoundry creates a Gitea repository, optionally an empty GitHub
# repository with a Gitea -> GitHub push mirror, and a local project with # repository with a Gitea -> GitHub push mirror, and a local project with
# the SQA-QC-Framework. It validates the configuration and credentials, # the SQA-QC-Framework. It validates the configuration and credentials,
# asks for the project details, checks both hosts with read-only requests # asks for the project details (those set in config.env are not asked), checks both hosts with read-only requests
# (tokens, owners, names, license, SSH) and, with --apply, creates the # (tokens, owners, names, license, SSH) and, with --apply, creates the
# repositories and the mirror, then the local project: its directory, git # repositories and the mirror, then the local project: its directory, git
# repository, remotes (no credential in any address), the framework as a # repository, remotes (no credential in any address), the framework as a
+11
View File
@@ -262,3 +262,14 @@ test_with_every_detail_set_an_existing_directory_is_not_replaced() {
assert_file_exists "existing file kept" "$WORK/my-app/mine.txt" assert_file_exists "existing file kept" "$WORK/my-app/mine.txt"
assert_eq "content kept" "keep" "$(cat "$WORK/my-app/mine.txt")" assert_eq "content kept" "keep" "$(cat "$WORK/my-app/mine.txt")"
} }
test_a_quoted_description_may_contain_a_hash() {
local answers=$'my-app\npublic\nTirSystem\nn\n\nn\n'
collect_with 'PROJECT_DESCRIPTION="Tool for #mirrors"' "$answers"
assert_status "quoted" 0 "$STATUS"
assert_contains "whole value kept" "$OUT" "description=Tool for #mirrors"
# Unquoted, the same text is cut at the comment mark, as documented.
collect_with 'PROJECT_DESCRIPTION=Tool for #mirrors' "$answers"
assert_contains "cut at the comment" "$OUT" "description=Tool for"
assert_not_contains "comment dropped" "$OUT" "mirrors"
}