Skip to content

Commit db679a0

Browse files
committed
docs(readme): quick start, reviews, fork behavior, and security
- Quick start covering the guided first-run setup and --setup. - Pull requests & reviews section: reviews are on by default, fork-aware discovery, and how to enable via gh. - Security summary linking SECURITY.md. - Note --copy skips the picker.
1 parent aba20ff commit db679a0

1 file changed

Lines changed: 61 additions & 1 deletion

File tree

‎README.md‎

Lines changed: 61 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,30 @@ Maintainers can produce all platform binaries with `make release` (output in
6363

6464
---
6565

66+
## Quick start
67+
68+
```bash
69+
commit-chronicle
70+
```
71+
72+
On the **first run** with no repos configured, it walks you through a one-time
73+
setup: it scans the usual places (`~/projects`, `~/work`, `~/code`, the current
74+
folder, …), shows how many git repos each holds, lets you pick one, and offers
75+
to remember it. It also checks whether `gh` is authenticated so PRs and reviews
76+
can be included.
77+
78+
After that, just run `commit-chronicle` from anywhere:
79+
80+
```bash
81+
commit-chronicle # pick range → pick items → edit → export
82+
commit-chronicle --since "7 days ago"
83+
commit-chronicle --date today --copy # also: yesterday, "3 days ago", etc.
84+
```
85+
86+
> Re-run setup any time with `commit-chronicle --setup`.
87+
88+
---
89+
6690
## Usage
6791

6892
Run it inside a git repo, or configure repos/roots (below) to scan many at once:
@@ -104,7 +128,7 @@ In the editor: `ctrl+s` save · `esc` cancel.
104128
--all select everything (skip the picker)
105129
--no-edit skip the editor step
106130
--no-pr skip GitHub PR + review discovery (git commits only)
107-
--copy copy the worklog to the clipboard
131+
--copy copy the whole worklog to the clipboard (skips the picker)
108132
-h, --help show help
109133
```
110134

@@ -135,12 +159,41 @@ file format.
135159

136160
---
137161

162+
## Pull requests & reviews
163+
164+
PRs and reviews are **included by default** — there's no flag to turn them on.
165+
All you need is the GitHub CLI, authenticated once:
166+
167+
```bash
168+
gh auth login # one-time
169+
gh auth status # verify
170+
```
171+
172+
With that in place, every run gathers, alongside your commits:
173+
174+
- pull requests **you authored** (tag `PR`)
175+
- pull requests **you reviewed** (tag `review`, dated by your review)
176+
- commits on your PRs that the plain author match might miss
177+
178+
**Fork workflows just work.** If you push to your own `origin` fork but open
179+
PRs and submit reviews against an `upstream` parent, discovery queries *every*
180+
remote — so your reviews on the upstream repo are found automatically.
181+
182+
Pass `--no-pr` if you ever want commits only. No `gh` installed (or not
183+
authenticated) also falls back to git-only, with a one-line note telling you how
184+
to enable PRs/reviews.
185+
186+
---
187+
138188
## How it works
139189

140190
- **Commits** come from `git log --all --author=<you>` across every ref.
141191
- **PRs / reviews** come from `gh` (the GitHub CLI). It lists your PRs in the
142192
window, then fetches commit/review details per-PR — GitHub searches are
143193
date-bounded so it only inspects PRs that could fall in range.
194+
- **Fork-aware:** discovery follows *every* remote of a repo, not just
195+
`origin`. In a fork workflow you push to your `origin` fork but open PRs and
196+
submit reviews against the `upstream` parent, so both are queried.
144197
- Everything is keyed by hash (commits) or repo+number (PRs) and de-duplicated,
145198
so a commit that shows up both in history and on a PR appears once.
146199
- Output is grouped by date; commits, PRs and reviews each render as distinct,
@@ -156,6 +209,13 @@ No `gh`, or pass `--no-pr`, and it runs git-only.
156209
- **gh**, authenticated (`gh auth login`) — optional, for PR & review discovery
157210
- a clipboard tool for `--copy`: `pbcopy` (macOS), `wl-copy` or `xclip` (Linux)
158211

212+
## Security
213+
214+
All `git`/`gh` calls use an explicit argument vector (no shell), `gh` handles
215+
GitHub auth (no tokens touched here), and commit/PR text is stripped of terminal
216+
escape sequences before display. CI runs `govulncheck` on every push. See
217+
[SECURITY.md](SECURITY.md) for details and how to report issues.
218+
159219
## License
160220

161221
See [LICENSE](LICENSE).

0 commit comments

Comments
 (0)