| 1 |
Create the local project directory and credential-free remotes |
After consent, create the directory (refuse to reuse an existing one without a yes), run git init on main, and add origin (Gitea) and github using URLs derived from the configured base URLs and the selected owners, with no token in any URL. origin uses HTTPS derived from GITEA_URL, unless the SSH test from the preflight passed, in which case it uses SSH on port 10022. Do not make a commit. |
Yes |
UC-001 |
| 2 |
Add the framework submodule |
From the project directory run git submodule add ssh://git@git.tirsystem.com:10022/TirSystem/SQA-QC-Framework.git framework. Check beforehand that SSH on port 10022 works and stop with an actionable message if not. Document that this SSH access must be configured. |
Yes |
UC-001 |
| 3 |
Install skills and git hooks, with optional plan gate |
Run framework/scripts/install-skills.sh and install-git-hooks.sh. The hook installer only sets core.hooksPath to framework/githooks and is safe to rerun, but it would replace a different existing value, so read the current value first and ask. Offer --enable-plan-gate as an optional choice, which requires a Task: MIL-NNN#N trailer on commits changing src/ or tests/. |
Yes |
UC-001 |
| 4 |
Copy the framework templates without overwriting |
Copy AGENTS-template.md to AGENTS.md and artifact-registry-template.md to docs/artifact-registry.md after mkdir -p docs, asking before replacing an existing file. |
Yes |
UC-001 |
| 5 |
Write README.md |
Clear English for GitHub readers: installation, configuration (config.env, .env), usage examples, security decisions, error handling and partial-failure recovery, the SSH prerequisite for port 10022, token permissions, and the stakeholders: Tirsvad (Product Owner and maintainer, https://www.linkedin.com/in/tirsvad74), Michael Kragh (DevOps, cybersecurity and maintainer, https://www.linkedin.com/in/codemikemike/) and GitHub readers. |
No |
|
| 6 |
End-to-end test and final security review |
Run the whole flow against disposable repositories for a user owner and an organization owner. Review credential handling, repository ownership, mirror direction, submodule setup and API limitations, record the result in an RC-* review, and summarise the files created and the external prerequisites. |
No |
|