anvilsign in

collin/anvil

BoardRenderedSource

Todo

Backlog

  • pull requests (gix merge)

  • pull mirror (maybe): a repo that virtually mirrors a GitHub repo

    • just displays it here — periodically fetched, read-only on the anvil side
  • richer file editing: a real markdown editor with a live render preview (reuse render_markdown) before committing

  • webhooks (mind the SSRF item in docs/untrusted-mode.md)

  • attachment reclaim: an orphan sweep (delete attachments no committed file references) and/or a per-attachment delete action — the recourse once a repo hits its quota. Deferred: deletion is destructive and "orphaned" is fuzzy (tip-only vs any-ref), so it wants its own design pass

  • remove a repo's attachment + artifact dirs on repo delete — blocked: there is no repo-delete path yet (only the create-rollback uses it)

  • admin usage: per-repo drill-down, and a cheap cached/periodic variant if the on-demand disk walk gets slow on large instances

  • API tokens: a write scope (would need CSRF-exempt write paths) and last_used_at tracking