From 9d5641fe6585a61894f7b7427a68c794e5efe76d Mon Sep 17 00:00:00 2001 From: godosa Date: Wed, 7 Oct 2026 07:44:16 +0200 Subject: Denylist guard at commit time (pre-commit + commit-msg hooks); drop publish_snapshot Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01JEAjUkQRrCYX5MZhWxdtj2 --- docs/manual.md | 17 +++++++++-------- 1 file changed, 9 insertions(+), 8 deletions(-) (limited to 'docs/manual.md') diff --git a/docs/manual.md b/docs/manual.md index 2b4594b..26661b6 100644 --- a/docs/manual.md +++ b/docs/manual.md @@ -212,14 +212,15 @@ wf add "Cave seams. Close the slit beside the lintel." -p 1 -e '<1h' --model son model that fits. A sonnet task without an exact Done line comes back as a handback. - **Updating the tool**: `git -C /projects/public/workflow pull`. Read the top of `CHANGES.md`: each line ends with "Projects: …", which says what a project must do (usually nothing). -- **Publishing a public copy**: keep the tool repo private (its history names your projects) and - share a fresh-history snapshot instead. Put your private words (project names, home paths), one - per line, in `publish-denylist.local` in the tool repo (git-ignored), then run - `python3 scripts/publish_snapshot.py [DEST]` (default `~/src/wf-public`). It copies master's - tree without `inbox.md`, `.worktrees/`, `__pycache__/`, `out/`, refuses if any denylist word is - in a path or file, and commits once per run (first: "initial public snapshot"; later: the new - `CHANGES.md` lines). It never pushes and never adds a remote: review DEST, then add the public - remote and `git push` there yourself. +- **Public by default**: the tool repo's history is public, so never put private names (project + names, home paths, hosts) in files or commit messages. A denylist guard checks each commit: put + your private words, one per line (`#` comments, `!token` = exemption), in `publish-denylist.local` + in the tool repo (git-ignored; extra lists via `git config --add denylist.file `) and enable + the hooks once per clone with `git config core.hooksPath .githooks`. The pre-commit hook scans + staged lines and paths, the commit-msg hook the message, both case-insensitive; a hit names the + place and `word #` only and refuses the commit (`git commit --no-verify` for a false hit). + No list → a warning, the commit goes through. Audit the whole tree with + `python3 scripts/denylist_check.py tree`. ## 5. Troubleshooting -- cgit