Follow-up to the merged MIL-001 PR: findings from the code review (RC-016,
against QC-SH-001) and the move of the script to src/.
Why this matters
The merged version prints the access tokens in the trace when the script is
run with bash -x (47 occurrences in a test run). This PR switches tracing
off with a warning and adds a test that fails if the guard is removed.
What is in this PR
Security: set -x is disabled while the script runs; no secret reaches a trace
Parser: a byte order mark on the first line of a config file is ignored
json_get: strips the carriage return jq adds on Windows, and returns the
first matching key (not the last) when jq is not installed
Naming: boolean keys renamed to has_github and is_plan_gate_enabled
Header: cites the task it implements (MIL-001, US-001.01, UC-001), lists
every external tool the script calls, documents that tracing is off
Location: create-project.sh moves to src/create-project.sh, so the plan
gate (Task: MIL-NNN#N trailer) now applies to it. config.env and .env
still default to the project root (the parent of src/); --config and --env override
Review record RC-016 and the Traceability Matrix entry
Checks
tests/run-tests.sh: 214 checks, 0 failed; shellcheck and shfmt clean
Mutation checks: a planted token leak and the removed tracing guard are both
caught by the tests
Run against a real .env from the project root and from another directory:
no token in any output, no temporary files left
Follow-ups (non-blocking, from RC-016, owner S02, due 2026-10-30)
Run the tests on Linux and macOS (bash 4.4 or later); the .env permission
warning is skipped on Windows
Check by hand that Ctrl-C removes the temporary directory (SIGTERM is tested)
Check the real repository name rules of GitHub and Gitea in the MIL-002 preflight
Notes for the reviewer
Three accepted documents still show shellcheck create-project.sh without
the src/ path: docs/business-case.md (success criterion 6), docs/milestones/mil-001-foundation.md (Go/No-Go criterion 1) and RC-016.
Left unchanged here, since correcting them needs new Version History rows.
The history has a rename commit followed by a content commit (the first
rename commit was pushed without its edits and fixed one commit later).
No issue closed: issues #3 to #8 were closed by the merged PR 22.
Follow-up to the merged MIL-001 PR: findings from the code review (RC-016,
against QC-SH-001) and the move of the script to `src/`.
## Why this matters
The merged version prints the access tokens in the trace when the script is
run with `bash -x` (47 occurrences in a test run). This PR switches tracing
off with a warning and adds a test that fails if the guard is removed.
## What is in this PR
- Security: `set -x` is disabled while the script runs; no secret reaches a trace
- Parser: a byte order mark on the first line of a config file is ignored
- `json_get`: strips the carriage return `jq` adds on Windows, and returns the
first matching key (not the last) when `jq` is not installed
- Naming: boolean keys renamed to `has_github` and `is_plan_gate_enabled`
- Header: cites the task it implements (MIL-001, US-001.01, UC-001), lists
every external tool the script calls, documents that tracing is off
- Location: `create-project.sh` moves to `src/create-project.sh`, so the plan
gate (`Task: MIL-NNN#N` trailer) now applies to it. `config.env` and `.env`
still default to the project root (the parent of `src/`); `--config` and
`--env` override
- Review record RC-016 and the Traceability Matrix entry
## Checks
- `tests/run-tests.sh`: 214 checks, 0 failed; `shellcheck` and `shfmt` clean
- Mutation checks: a planted token leak and the removed tracing guard are both
caught by the tests
- Run against a real `.env` from the project root and from another directory:
no token in any output, no temporary files left
## Follow-ups (non-blocking, from RC-016, owner S02, due 2026-10-30)
- Run the tests on Linux and macOS (bash 4.4 or later); the `.env` permission
warning is skipped on Windows
- Check by hand that Ctrl-C removes the temporary directory (SIGTERM is tested)
- Check the real repository name rules of GitHub and Gitea in the MIL-002 preflight
## Notes for the reviewer
- Three accepted documents still show `shellcheck create-project.sh` without
the `src/` path: `docs/business-case.md` (success criterion 6),
`docs/milestones/mil-001-foundation.md` (Go/No-Go criterion 1) and RC-016.
Left unchanged here, since correcting them needs new Version History rows.
- The history has a rename commit followed by a content commit (the first
rename commit was pushed without its edits and fixed one commit later).
No issue closed: issues #3 to #8 were closed by the merged PR 22.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Switch off set -x (it printed tokens), accept a byte order mark, strip the
carriage return jq adds on Windows, return the first key without jq, rename
the boolean keys, and cite the task in the header. Add regression tests and
review record RC-016.
Task: MIL-001#2
Task: MIL-001#3
Task: MIL-001#4
Task: MIL-001#6
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Code belongs in src/, where the plan gate applies. config.env and .env
still default to the project root (the parent of src/). Add tests for the
location and the defaults.
Task: MIL-001#2
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Follow-up to the move: config.env and .env default to the project root
(the parent of src/), the header says so, and the tests use the new path.
Add tests for the location and the defaults.
Task: MIL-001#2
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Tirsvad
merged commit 903c948d85 into main2026-10-05 08:23:32 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Follow-up to the merged MIL-001 PR: findings from the code review (RC-016,
against QC-SH-001) and the move of the script to
src/.Why this matters
The merged version prints the access tokens in the trace when the script is
run with
bash -x(47 occurrences in a test run). This PR switches tracingoff with a warning and adds a test that fails if the guard is removed.
What is in this PR
set -xis disabled while the script runs; no secret reaches a tracejson_get: strips the carriage returnjqadds on Windows, and returns thefirst matching key (not the last) when
jqis not installedhas_githubandis_plan_gate_enabledevery external tool the script calls, documents that tracing is off
create-project.shmoves tosrc/create-project.sh, so the plangate (
Task: MIL-NNN#Ntrailer) now applies to it.config.envand.envstill default to the project root (the parent of
src/);--configand--envoverrideChecks
tests/run-tests.sh: 214 checks, 0 failed;shellcheckandshfmtcleancaught by the tests
.envfrom the project root and from another directory:no token in any output, no temporary files left
Follow-ups (non-blocking, from RC-016, owner S02, due 2026-10-30)
.envpermissionwarning is skipped on Windows
Notes for the reviewer
shellcheck create-project.shwithoutthe
src/path:docs/business-case.md(success criterion 6),docs/milestones/mil-001-foundation.md(Go/No-Go criterion 1) and RC-016.Left unchanged here, since correcting them needs new Version History rows.
rename commit was pushed without its edits and fixed one commit later).
No issue closed: issues #3 to #8 were closed by the merged PR 22.
🤖 Generated with Claude Code