Repo cleanup for the 2.1.5 reviewer pass - #1
Open
ShadowfetchLinux wants to merge 1 commit into
Open
Conversation
…y files Remove the stale 2.1.4 torrent and unused hero image, keep a single canonical release note in docs/, and point README/SECURITY at the freeze-host ISO plus the shadowfetchlinux.org guides. Add CONTRIBUTING, issue/PR templates, and a GitHub release paste template so reviewers can verify without hunting. Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
ShadowfetchLinux
marked this pull request as ready for review
August 21, 2026 00:24
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR changes
A first-pass cleanup of the GitHub tree after Tammy Smith takes over the repo. Product behavior (Control Center, Buzz, Phoenix, Fireproof, first-run agents) is untouched.
.deb, GPG private key, Cloudflare token, or secret leaked in the diffmake source-gatecould not be run end-to-end here (this environment lacksshellcheck/gitleaksand a systemd user session). Targeted gates that did run passed: identity/artifact-route tests, desktop-file validation, parsers, Guide/Phoenix contracts, retired-runtime scan.What I verified live (21 Aug 2026)
https://www.shadowfetch.com/linux/download/shadowfetch-2.1.5-amd64.isoContent-Length: 3968471040.sha256sidecar848f043e4d6f85c3607e7034ba911a1ce8b4a317674feebef8b07fcd8f531c24https://www.shadowfetchlinux.org/download/shadowfetch-2.1.5-amd64.iso.orgdoes not serve ISO bytes/download,/verify,/security)shadowfetch.com/linux/{page}301s there.com/linux/shadowfetch.gpg.asc,.org/shadowfetch.gpg.asc, and in-treeshadowfetch-release.ascv2.1.5https://www.shadowfetchlinux.org/releases.json…/apt/sources/shadowfetch-source-2.1.5.tar.gzmain/source+ this git repoChanged
shadowfetch-2.1.4-amd64.iso.torrent(nothing linked it;.com404s that torrent) and unusedkimi-k3-abstract-hero.jpg.docs/RELEASE-2.1.5.md. RootRELEASE-2.1.5.mdis now a short pointer.www.shadowfetch.com/linux/...) because those are the URLs that actually return the ISO. Docs/guides stay onwww.shadowfetchlinux.org. Explains that GitHub Releases do not attach the ISO.SECURITY.md: private reports go to shadowfetchlinux@gmail.com (the address on the live site). Replaced the oldRealbobcorbin/shadowfetch-linuxissues URL.CONTRIBUTING.md(make source-gate) and a PR template. No Code of Conduct invented.docs/GITHUB-RELEASE.mdpaste-ready notes; CI now writes checksum/verify URLs into future draft GitHub releases and still attaches only.sha256/.asc..gitignore: torrents, extra.debleftovers, OpenPGP private-keyring paths.Realbobcorbin2.1.1 torrent redirect now points at Archive.org. README/comments document that the Worker is the artifact proxy, not the public site.SOURCES.md/LICENSES.md: written offer now matches the live licensing page (git + APTmain/source+shadowfetchlinux@gmail.com), instead of the 404 tarball.ROADMAP-NEXT-BUILD.md;packages.manifestlabeled as a 2.1.1 listing.Left alone (and why)
TRADEMARKS.md, repo name/topics/homepage.SHA256SUMS,SHA256SUMS.asc,shadowfetch-release.asc)./linux/pages: production 301s those routes to shadowfetchlinux.org. Rewriting ~1.5k lines of unserved copy would not change what reviewers see.weekly_release.sh(maintainer-local cron; no secrets in-tree).qa/2.1.4/evidence and historical changelogs (provenance).releases.jsonstill saying 2.1.4 — that feed is generated by the Astro site, not this repo.Maintainer checklist (GitHub account, cannot be done from a PR)
These are User-account facts, not repo-file bugs:
Bob Corbin <Robertcorbin84@gmail.com>and at least one209457103+Realbobcorbin@users.noreply.github.com. Do not rewrite history to hide that. Optionally setuser.emailto the GitHub noreply address going forward, and enable commit signing (SSH or GPG) on new commits only.ShadowfetchLinuxis a User (isInOrganization: false). Do not convert it. Call it a project account if reviewers ask.shadowfetch-2.1.5-amd64.iso.sha256and.asctov2.1.5, or pastedocs/GITHUB-RELEASE.md.needs-triageandhardware-report(templates reference them; GitHub may auto-create on first issue).https://www.shadowfetchlinux.org/releases.jsonstill lists 2.1.4 aslatesteven though/downloadand/changelogalready show 2.1.5. Fix that feed on the site so machines and humans agree.How to test
Docs / GitHub-community files. After merge, open the repo front page and confirm: checksum + fingerprint in the README fold, no 2.1.4 torrent in the file list, Issues forms for Bug + Hardware, SECURITY policy email matches the site footer.