aboutsummaryrefslogtreecommitdiffziptar.gz
path: root/docs/manual.md
diff options
context:
space:
mode:
authorgodosa <godosa@godosa.eu>2026-10-07 07:44:16 +0200
committergodosa <godosa@godosa.eu>2026-10-07 07:44:16 +0200
commit9d5641fe6585a61894f7b7427a68c794e5efe76d (patch)
tree79ebae3131df1c50542420db9e5ecb44e3d22076 /docs/manual.md
parent81d4e80fd5aabe4e80f58e960affa795cf7d34ec (diff)
downloadworkflow-9d5641fe6585a61894f7b7427a68c794e5efe76d.tar.gz
workflow-9d5641fe6585a61894f7b7427a68c794e5efe76d.zip
Denylist guard at commit time (pre-commit + commit-msg hooks); drop publish_snapshot
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JEAjUkQRrCYX5MZhWxdtj2
Diffstat (limited to 'docs/manual.md')
-rw-r--r--docs/manual.md17
1 files changed, 9 insertions, 8 deletions
diff --git a/docs/manual.md b/docs/manual.md
index 2b4594b..26661b6 100644
--- a/docs/manual.md
+++ b/docs/manual.md
@@ -212,14 +212,15 @@ wf add "Cave seams. Close the slit beside the lintel." -p 1 -e '<1h' --model son
model that fits. A sonnet task without an exact Done line comes back as a handback.
- **Updating the tool**: `git -C /projects/public/workflow pull`. Read the top of `CHANGES.md`: each line
ends with "Projects: …", which says what a project must do (usually nothing).
-- **Publishing a public copy**: keep the tool repo private (its history names your projects) and
- share a fresh-history snapshot instead. Put your private words (project names, home paths), one
- per line, in `publish-denylist.local` in the tool repo (git-ignored), then run
- `python3 scripts/publish_snapshot.py [DEST]` (default `~/src/wf-public`). It copies master's
- tree without `inbox.md`, `.worktrees/`, `__pycache__/`, `out/`, refuses if any denylist word is
- in a path or file, and commits once per run (first: "initial public snapshot"; later: the new
- `CHANGES.md` lines). It never pushes and never adds a remote: review DEST, then add the public
- remote and `git push` there yourself.
+- **Public by default**: the tool repo's history is public, so never put private names (project
+ names, home paths, hosts) in files or commit messages. A denylist guard checks each commit: put
+ your private words, one per line (`#` comments, `!token` = exemption), in `publish-denylist.local`
+ in the tool repo (git-ignored; extra lists via `git config --add denylist.file <path>`) and enable
+ the hooks once per clone with `git config core.hooksPath .githooks`. The pre-commit hook scans
+ staged lines and paths, the commit-msg hook the message, both case-insensitive; a hit names the
+ place and `word #<line>` only and refuses the commit (`git commit --no-verify` for a false hit).
+ No list → a warning, the commit goes through. Audit the whole tree with
+ `python3 scripts/denylist_check.py tree`.
## 5. Troubleshooting