sec_pending() suppressed any PENDING-N whose number appeared as a REVIEWED-N, never checking the ruling was about that item. The two sequences have drifted: REVIEWED-84 rules on PENDING-87. So PENDING-84 was invisible at wake on the very morning the steward's pulling thread pointed at it, and closing it later produced no visible count change because it had never been counted. Found 2026-08-01 at wake, surfaced not fixed; register row 179. Resolution now reads the PENDING each ruling names in its header. Rulings that name none (REVIEWED-78, -81, -82) suppress nothing. Extracted as ruled_pendings() so it is testable at all -- the logic was buried in a file-reading routine with no way to exercise it. Five self-tests added, including the 2026-08-01 bug as a regression control and an empty-input positive control. Bounded-change proof against the live files: 18 -> 19 visible. Three items surfaced that were falsely hidden (PENDING-78, -81, -82); two stopped being shown that are genuinely ruled (PENDING-87 by REVIEWED-84, PENDING-88 by REVIEWED-85 -- no REVIEWED-87 or -88 exists, so number-matching had never suppressed them). That proof also caught an overclaim in this fix's own docstring, which asserted the correction could only ever surface more items and never fewer. It corrects in both directions. Comment repaired to say what the code does; the false version would have been a comment promising behaviour the code does not deliver, in a file whose purpose is to stop governance hiding from the steward. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
🖖 David's Dotfiles - "Engage!"
"Make it so!" - A complete macOS setup system inspired by Star Trek's efficiency and elegance.
From zero to fully configured macOS in minutes. This dotfiles repository provides a comprehensive, automated setup for developers, writers, and knowledge workers.
🚀 Quick Start
One command to rule them all:
# From GitHub
git clone https://github.com/davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage
# From Gitea (alternative mirror)
git clone git@git.davidglidden.eu:davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage
That's it! The engage script will guide you through a complete system setup.
✨ What This System Provides
📦 Software Management
- 120+ CLI tools via Homebrew (development, media, security)
- 40+ Applications via casks (productivity, creativity, utilities)
- 20+ Mac App Store apps via
mas(native macOS apps)
🔧 Configuration Management
- Shell setup: Zsh with Antidote, Powerlevel10k, history sync
- Development tools: Git hooks, SSH templates, NPM config
- Application configs: LaunchBar, Hazel, Bartender, Karabiner
- Obsidian vault: Complete knowledge management system
🖥️ macOS System Configuration
- System preferences: Dock, Finder, keyboard, security
- Security hardening: Firewall, privacy, authentication
- Keyboard shortcuts: Mission Control, app shortcuts
- Developer settings: Safari dev tools, Terminal enhancements
🛡️ Backup & Security Strategy
- Encrypted backups for sensitive files (SSH keys, credentials)
- History management with daily snapshots and retention
- Git hooks for security and code quality
- Application data backup and restore scripts
📁 Repository Structure
dotfiles/
├── engage # 🖖 Master installation script
├── Brewfile # Package management (brew/cask/mas)
├── README.md # This file
├── .gitconfig # Git configuration
├── .npmrc # NPM defaults
├── .zshrc # Shell configuration
├── .vimrc # Vim configuration
├── bin/ # Custom scripts
│ ├── backup-dotfiles # Quick dotfiles backup
│ └── check-app-configs # Configuration status checker
├── git/ # Git configuration
│ └── hooks/ # Global git hooks
├── macos/ # macOS system configuration
│ ├── setup-macos.sh # Master macOS setup
│ ├── defaults.sh # System preferences
│ ├── security.sh # Security hardening
│ └── keyboard-shortcuts.sh # Custom shortcuts
├── macos-apps/ # macOS app configurations
│ └── backup-app-configs.sh # App settings backup
├── obsidian/ # Obsidian knowledge vault
│ ├── setup-obsidian.sh # Vault configuration
│ └── community-plugins.json # Essential plugins
├── scripts/ # Installation scripts
│ └── symlinks.sh # Dotfile linking
├── shell/ # Shell enhancements
│ └── history-sync.zsh # History management
└── ssh/ # SSH configuration
├── config.example # SSH config template
└── README.md # SSH setup guide
🎯 Core Philosophy
This system balances automation with choice:
- Smart defaults that work out of the box
- Interactive modes for customization
- Modular design - use what you need
- Security first - encrypted backups, secure defaults
- Documentation - clear guides and examples
Inspired by the best dotfiles repositories but designed for real-world complexity.
📱 Essential Applications Included
Development
- iTerm2 + Kitty - Terminal emulators
- BBEdit - Text editor with deep macOS integration
- GitHub Desktop - Git GUI
- Docker - Containerization
Productivity
- Obsidian - Knowledge management powerhouse
- 1Password - Password management
- LaunchBar - Application launcher
- Hazel - Automated file organization
- Drafts - Quick capture and text processing
Utilities
- Karabiner-Elements - Keyboard customization
- Bartender - Menu bar organization
- Keka - Archive utility
- Oversight - Privacy monitoring
- Signal - Secure messaging
Creative & Media
- VLC - Media player
- HandBrake - Video transcoding
- Transmit - File transfer
- Calibre - E-book management
🛠️ Advanced Usage
Manual Installation Steps
If you prefer granular control:
# 1. Install packages only
brew bundle install --file=~/dotfiles/Brewfile
# 2. Set up dotfiles
~/dotfiles/scripts/symlinks.sh
# 3. Configure macOS
~/dotfiles/macos/setup-macos.sh
# 4. Set up applications
~/dotfiles/macos-apps/backup-app-configs.sh
Customization
Modify the Brewfile to add/remove applications:
# Add new CLI tool
brew "your-tool"
# Add new application
cask "your-app"
# Add Mac App Store app
mas "App Name", id: 123456789
Customize macOS defaults in macos/defaults.sh:
# Change dock position
defaults write com.apple.dock orientation -string "left"
# Adjust key repeat speed
defaults write NSGlobalDomain KeyRepeat -int 1
Backup Strategy
Before making changes:
# Backup current dotfiles
~/dotfiles/bin/backup-dotfiles
# Backup macOS settings
~/dotfiles/macos/backup-defaults.sh
# Backup sensitive files (encrypted)
~/dotfiles/backup-scripts/backup-sensitive.sh
🔐 Security Features
- SSH keys encrypted with GPG
- Firewall enabled with stealth mode
- Privacy settings optimized
- Git hooks prevent secrets in commits
- Secure defaults for Safari and system
- Application permissions documented
🧠 Obsidian Knowledge System
Includes a sophisticated personal knowledge management setup:
- 13 essential plugins for advanced functionality
- Template system with Templater integration
- Daily/weekly/monthly review cycles
- Christopher Alexander pattern language philosophy
- Multilingual support (EN/ES/FR/CA)
🤝 Contributing
This is a personal dotfiles repository, but ideas and improvements are welcome:
- Fork the repository
- Create a feature branch
- Test thoroughly on a fresh macOS installation
- Submit a pull request with clear description
📜 License
MIT License - Use, modify, and share freely.
🙏 Acknowledgments
Inspired by:
- Mathias Bynens' dotfiles
- ptb/mac-setup
- Homebrew Bundle
- The Star Trek universe for the best command ever: "Engage!"
Live long and prosper! 🖖
Made with ❤️ for the macOS community