# Repository privacy check

Use the copy prepared in Week 0 Task 4: `bootcamp-course/weeks/week-00/privacy-check.md`.
Keep both repos private during this check. Never write a secret into this checklist.

> **What this teaches:** I can keep private learning notes separate from project work that is cleaned of private details. I can check both the current files and the Git history before I publish anything.

## Private course repository

- [ ] The repo is set to private.
- [ ] The computer worksheet and any older raw notes stay outside Git.
- [ ] The week record holds no raw computer details. That means no username, hostname, IP address, account or project ID, token, key, or personal full path.
- [ ] Test answers, review notes, progress records, and AI-help lines stay here, not in the project.

## Project working tree

Your working tree is your files on disk. Run these commands one at a time inside `java-gradebook-cli`. Read the first result before you run the second.

### Command 01 — Show current uncommitted changes

**Before you run it:** Make sure your prompt is inside `java-gradebook-cli`.

```shell
git status --short
```

**What this command does:** `git status` looks at your files on disk. `--short` prints a short list of changed and untracked paths. It changes nothing.

**How to read the result:** Every path it prints must belong to the software product. Stop if you see a private course record, a password or key, build output, or a `.venv` folder.

### Command 02 — Show every path Git already tracks

**Before you run it:** Finish reading the Command 01 output first. This second list can include files with no current change.

```shell
git ls-files
```

**What this command does:** `git ls-files` prints every path Git already tracks. It changes nothing.

**How to read the result:** Read every path. Stop if Git tracks a private record, a secret, personal data, a build folder, or a local setup file.

Together, the two results separate new local files from files already in Git's snapshots.

- [ ] Only project code, tests, config that works on any computer, and made-up data are present.
- [ ] Build output, `.venv` folders, editor settings, passwords and keys, and private course records are ignored or absent.
- [ ] No tracked file contains a personal full path.

## Project history

### Command 03 — Read every commit and its changes

**Before you run it:** Finish both working-tree checks above. A clean current folder does not prove that earlier commits are clean.

```shell
git log -p --all
```

**What this command does:** `-p` shows the changes within each commit. `--all` includes every local branch. This changes nothing.

**How to read the result:** Read every change before you publish. Space shows another screen; q leaves the viewer. No output is normal before the first commit. Deleting a file today does not remove it from older commits. If you are not sure, keep the repo private and look into that commit.

**Continue only when:** You understand every current path. You have also checked every listed commit for the private or sensitive things named below.

- [ ] No commit contains a secret, real personal or student data, a private course record, or a copied solution.
- [ ] All demo data is made-up.
- [ ] Any doubt is cleared up while the repo is still private.

## First project push — only after the checks pass

Finish the project README requested in Task 4 before staging.
Use your editor's New File command inside `java-gradebook-cli`; save it as `README.md`.
Open the linked README template and adapt it to your actual working starter.
If that file already exists, edit it without replacing earlier work.

Stay inside `java-gradebook-cli`, not the notes repo.

Check the destination:

```shell
git remote -v
```

Both origin lines must name your private Java repo from Task 3. Otherwise stop.

Stage only the starter files and README:

```shell
git add -- pom.xml .gitignore mvnw mvnw.cmd .mvn/wrapper/maven-wrapper.properties src README.md
```

This selects the project files without uploading them. Any error means stop.

Read all staged changes, including files staged earlier:

```shell
git diff --cached
```

Check every filename and line. Only project code, tests, README, and shared config may appear.
No secrets, course records, build output, or real personal data may appear.

Only if that check fails, unstage without changing your files:

```shell
git reset -- .
```

Fix the files, then stage and inspect again. Skip recovery when the check passes.

After the full staged check passes, commit:

```shell
git commit -m "Set up tested Java starter"
```

Expect a commit ID. Nothing to commit means no new changes; any other error means stop.

Push to the checked private destination:

```shell
git push -u origin HEAD
```

Stop for login or remote errors. Never force-push.
Confirm the latest commit on GitHub. Keep the repo private unless its current files and complete history passed the publication check.

## Result

- Keep project private / safe to make project public:
- Proof checked:
- Remaining risk:
- Exact next action:

## Explain it back

Explain why a private repo does not make it safe to commit a secret. Then explain why the current files and the Git history need separate checks.
