What Happens If a Commit Is Unsigned? (Forgejo Enforcement Across Machines)
In my previous post, I covered migrating from GPG to SSH commit signing.
Blog posts about GitHub
View All TagsIn my previous post, I covered migrating from GPG to SSH commit signing.
If you are still using GPG for commit signing purely out of habit, this is your nudge to reconsider.
After my first adventures with GitHub spec-kit, I was left pretty disappointed with the results. The structure and architecture looked fine on the surface, but the actual implementation was mostly placeholders. Tasks were marked as complete when they clearly weren’t, and authentication that was supposed to use Azure AD and Google was just accepting any username and password. Not good enough.
Since starting this experiment, I’ve switched to Claude Sonnet 4.5, which is a big step up from the previous model. With better prompts and a more capable LLM, I wanted to dig into why things went wrong the first time—and, more importantly, how to avoid those mistakes in future.
After several weeks regaling you with tales of aortic replacements and pacemaker adventures, you might be rather relieved to encounter a proper technical post. Whilst convalescing in Kirchberg Hospital, waiting for my INR levels to reach their proper therapeutic range, I find myself with time on my hands and only my trusty phone and a modest tablet for company.
What better opportunity, I thought, to explore GitHub's spec-kit and attempt some spec-driven development? The goal, rather splendidly practical given my current circumstances, is to build an application to remind me to take my blood-thinning medication in the evening and perform my INR blood tests in the morning. I've imaginatively titled this endeavour the blood_thinner_INR_tracker.