anvilsign in

collin/anvil

BoardRenderedSource

Todo

  • pull mirror (maybe): a repo that virtually mirrors a GitHub repo
    • just displays it here — periodically fetched, read-only on the anvil side
  • pull requests (gix merge)
  • webhooks (mind the SSRF item in docs/untrusted-mode.md)
  • richer file editing: a real markdown editor with a live render preview (reuse render_markdown) before committing
  • attachment reclaim: an orphan sweep (delete attachments no committed file references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass
  • remove a repo's attachment + artifact dirs on repo delete — blocked: there is no repo-delete path yet (only the create-rollback uses it)
  • admin usage: per-repo drill-down, and a cheap cached/periodic variant if the on-demand disk walk gets slow on large instances
  • API tokens: a write scope (would need CSRF-exempt write paths) and last_used_at tracking