Agent skill

Django Verification

by xu-xiang in xu-xiang/everything-claude-code-zh

针对 Django 项目的验证循环:包含数据库迁移、代码检查、带覆盖率的测试、安全扫描,以及在发布或 PR 前的部署就绪检查。

MITAuto-check passedBackend & APIs

Install Django Verification

skills CLI
$ npx skills add xu-xiang/everything-claude-code-zh --skill django-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xu-xiang/everything-claude-code-zh django-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/django-verification .claude/skills/django-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
django-verification
GitHub stars
2k
Token cost
~2.2k tokens
SKILL.md length
227 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

针对 Django 项目的验证循环:包含数据库迁移、代码检查、带覆盖率的测试、安全扫描,以及在发布或 PR 前的部署就绪检查。

  • Tasks that involve Backend development
  • SKILL.md covers 何时启用, 阶段 1:环境检查 (Environment Check), 阶段 2:代码质量与格式化 (Code Quality &… and 阶段 3:数据库迁移 (Migrations), plus 13 more sections
  • Calls python, git and pytest; needs SECRET_KEY and DJANGO_SECRET_KEY

What it does

Django Verification is an agent skill from xu-xiang/everything-claude-code-zh. 针对 Django 项目的验证循环:包含数据库迁移、代码检查、带覆盖率的测试、安全扫描,以及在发布或 PR 前的部署就绪检查。

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development. It works with Django. The repository describes itself as: everything-claude-code 中文翻译项目:完整的 Claude Code 配置集合(agents, skills, hooks, commands, rules, MCPs)。源自 Anthropic 黑客松获胜者的实战配置,助力中文工程师高效理解与使用 Claude Code。 The licence is MIT.

When your agent uses it

  • Tasks that involve Backend development

Example prompts

  • “/django-verification”

Requirements

  • Python 3
  • A credential in DJANGO_SECRET_KEY
  • A credential in SECRET_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit dfbf946. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • git
    • pytest
    • black
    • npm
    • mypy
    • ruff
    • pip
    • gitleaks
    • django-admin

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY
    • DJANGO_SECRET_KEY
    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Django Verification loads about 2.2k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 227 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xu-xiang/everything-claude-code-zh at commit dfbf946, republished under its MIT licence (© xu-xiang). 227 words, ~2,158 tokens.

Download SKILL.mdSave it as .claude/skills/django-verification/SKILL.md (or your agent's skills folder).
name
django-verification
description
针对 Django 项目的验证循环:包含数据库迁移、代码检查、带覆盖率的测试、安全扫描,以及在发布或 PR 前的部署就绪检查。
origin
ECC

Django 验证循环 (Django Verification Loop)

在提交 PR 前、重大变更后以及部署前运行,以确保 Django 应用的质量与安全性。

何时启用

  • 在为 Django 项目提交 Pull Request 前
  • 在重大模型变更、迁移更新或依赖升级后
  • 预发布(Staging)或生产环境部署前的验证
  • 运行完整的 环境检查 → 代码检查 → 测试 → 安全扫描 → 部署就绪流水线
  • 验证迁移安全性及测试覆盖率

阶段 1:环境检查 (Environment Check)

bash
# 验证 Python 版本
python --version  # 应符合项目要求

# 检查虚拟环境
which python
pip list --outdated

# 验证环境变量
python -c "import os; import environ; print('DJANGO_SECRET_KEY set' if os.environ.get('DJANGO_SECRET_KEY') else 'MISSING: DJANGO_SECRET_KEY')"

如果环境配置错误,请停止并修复。

阶段 2:代码质量与格式化 (Code Quality & Formatting)

bash
# 类型检查
mypy . --config-file pyproject.toml

# 使用 ruff 进行 Lint 检查
ruff check . --fix

# 使用 black 进行格式化检查
black . --check
black .  # 自动修复

# 导入语句排序
isort . --check-only
isort .  # 自动修复

# Django 特有的检查
python manage.py check --deploy

常见问题:

  • 公共函数缺失类型提示(Type hints)
  • 违反 PEP 8 格式规范
  • 未排序的导入语句
  • 生产环境配置中遗留了调试设置(Debug settings)

阶段 3:数据库迁移 (Migrations)

bash
# 检查未应用的迁移
python manage.py showmigrations

# 创建缺失的迁移
python manage.py makemigrations --check

# 预演迁移应用 (Dry-run)
python manage.py migrate --plan

# 应用迁移(测试环境)
python manage.py migrate

# 检查迁移冲突
python manage.py makemigrations --merge  # 仅在存在冲突时运行

报告:

  • 待处理的迁移数量
  • 任何迁移冲突
  • 模型变更但未生成迁移文件

阶段 4:测试 + 覆盖率 (Tests + Coverage)

bash
# 使用 pytest 运行所有测试并生成覆盖率报告
pytest --cov=apps --cov-report=html --cov-report=term-missing --reuse-db

# 运行特定应用的测试
pytest apps/users/tests/

# 运行带有标记的测试
pytest -m "not slow"  # 跳过慢速测试
pytest -m integration  # 仅运行集成测试

# 查看覆盖率报告
open htmlcov/index.html

报告:

  • 测试总计:X 通过,Y 失败,Z 跳过
  • 总体覆盖率:XX%
  • 各应用覆盖率明细

覆盖率目标:

组件目标
模型 (Models)90%+
序列化器 (Serializers)85%+
视图 (Views)80%+
服务 (Services)90%+
总体80%+

阶段 5:安全扫描 (Security Scan)

bash
# 依赖漏洞扫描
pip-audit
safety check --full-report

# Django 安全检查
python manage.py check --deploy

# Bandit 安全 Lint 检查
bandit -r . -f json -o bandit-report.json

# 密钥扫描(如果安装了 gitleaks)
gitleaks detect --source . --verbose

# 环境变量检查
python -c "from django.core.exceptions import ImproperlyConfigured; from django.conf import settings; settings.DEBUG"

报告:

  • 发现的有漏洞的依赖
  • 安全配置问题
  • 检测到硬编码的密钥
  • DEBUG 模式状态(生产环境应为 False)

阶段 6:Django 管理命令 (Django Management Commands)

bash
# 检查模型问题
python manage.py check

# 收集静态文件
python manage.py collectstatic --noinput --clear

# 创建超级用户(如测试需要)
echo "from apps.users.models import User; User.objects.create_superuser('admin@example.com', 'admin')" | python manage.py shell

# 数据库完整性检查
python manage.py check --database default

# 缓存验证(如果使用 Redis)
python -c "from django.core.cache import cache; cache.set('test', 'value', 10); print(cache.get('test'))"

阶段 7:性能检查 (Performance Checks)

bash
# Django Debug Toolbar 输出(检查 N+1 查询)
# 在 DEBUG=True 的开发模式下运行并访问页面
# 在 SQL 面板中查看重复查询

# 查询计数分析
django-admin debugsqlshell  # 如果安装了 django-debug-sqlshell

# 检查缺失的索引
python manage.py shell << EOF
from django.db import connection
with connection.cursor() as cursor:
    cursor.execute("SELECT table_name, index_name FROM information_schema.statistics WHERE table_schema = 'public'")
    print(cursor.fetchall())
EOF

报告:

  • 每页查询数量(典型页面应 < 50)
  • 缺失的数据库索引
  • 检测到重复查询

阶段 8:静态资源 (Static Assets)

bash
# 检查 npm 依赖(如果使用 npm)
npm audit
npm audit fix

# 构建静态文件(如果使用 webpack/vite)
npm run build

# 验证静态文件
ls -la staticfiles/
python manage.py findstatic css/style.css

阶段 9:配置审查 (Configuration Review)

python
# 在 Python shell 中运行以验证设置
python manage.py shell << EOF
from django.conf import settings
import os

# 关键检查项
checks = {
    'DEBUG 为 False': not settings.DEBUG,
    'SECRET_KEY 已设置': bool(settings.SECRET_KEY and len(settings.SECRET_KEY) > 30),
    'ALLOWED_HOSTS 已设置': len(settings.ALLOWED_HOSTS) > 0,
    'HTTPS 已启用': getattr(settings, 'SECURE_SSL_REDIRECT', False),
    'HSTS 已启用': getattr(settings, 'SECURE_HSTS_SECONDS', 0) > 0,
    '数据库已正确配置': settings.DATABASES['default']['ENGINE'] != 'django.db.backends.sqlite3',
}

for check, result in checks.items():
    status = '✓' if result else '✗'
    print(f"{status} {check}")
EOF

阶段 10:日志配置 (Logging Configuration)

bash
# 测试日志输出
python manage.py shell << EOF
import logging
logger = logging.getLogger('django')
logger.warning('测试警告消息')
logger.error('测试错误消息')
EOF

# 检查日志文件(如果已配置)
tail -f /var/log/django/django.log

阶段 11:API 文档 (API Documentation, 如果使用 DRF)

bash
# 生成 Schema
python manage.py generateschema --format openapi-json > schema.json

# 验证 Schema
# 检查 schema.json 是否为有效的 JSON
python -c "import json; json.load(open('schema.json'))"

# 访问 Swagger UI (如果使用 drf-yasg)
# 在浏览器访问 http://localhost:8000/swagger/

阶段 12:差异审查 (Diff Review)

bash
# 显示差异统计
git diff --stat

# 显示实际变更内容
git diff

# 显示变更的文件名
git diff --name-only

# 检查常见问题
git diff | grep -i "todo\|fixme\|hack\|xxx"
git diff | grep "print("  # 调试语句
git diff | grep "DEBUG = True"  # 调试模式
git diff | grep "import pdb"  # 调试器

检查清单:

  • 无调试语句(print, pdb, breakpoint())
  • 关键代码中无 TODO/FIXME 注释
  • 无硬编码的密钥或凭据
  • 模型变更已包含数据库迁移文件
  • 配置变更已记录文档
  • 外部调用已包含错误处理
  • 关键位置已进行事务管理

输出模板 (Output Template)

DJANGO 验证报告
==========================

阶段 1:环境检查
  ✓ Python 3.11.5
  ✓ 虚拟环境已激活
  ✓ 所有环境变量已设置

阶段 2:代码质量
  ✓ mypy: 无类型错误
  ✗ ruff: 发现 3 个问题(已自动修复)
  ✓ black: 无格式问题
  ✓ isort: 导入语句已正确排序
  ✓ manage.py check: 无问题

阶段 3:数据库迁移
  ✓ 无未应用的迁移
  ✓ 无迁移冲突
  ✓ 所有模型均有迁移文件

阶段 4:测试 + 覆盖率
  测试:247 通过,0 失败,5 跳过
  覆盖率:
    总体:87%
    users: 92%
    products: 89%
    orders: 85%
    payments: 91%

阶段 5:安全扫描
  ✗ pip-audit: 发现 2 个漏洞(需要修复)
  ✓ safety check: 无问题
  ✓ bandit: 无安全问题
  ✓ 未检测到密钥
  ✓ DEBUG = False

阶段 6:Django 命令
  ✓ collectstatic 已完成
  ✓ 数据库完整性正常
  ✓ 缓存后端可连接

阶段 7:性能
  ✓ 未检测到 N+1 查询
  ✓ 数据库索引已配置
  ✓ 查询计数在可接受范围内

阶段 8:静态资源
  ✓ npm audit: 无漏洞
  ✓ 资源构建成功
  ✓ 静态文件已收集

阶段 9:配置
  ✓ DEBUG = False
  ✓ SECRET_KEY 已配置
  ✓ ALLOWED_HOSTS 已设置
  ✓ HTTPS 已启用
  ✓ HSTS 已启用
  ✓ 数据库已正确配置

阶段 10:日志
  ✓ 日志已配置
  ✓ 日志文件可写

阶段 11:API 文档
  ✓ Schema 已生成
  ✓ Swagger UI 可访问

阶段 12:差异审查
  变更文件数:12
  +450, -120 行
  ✓ 无调试语句
  ✓ 无硬编码密钥
  ✓ 已包含迁移文件

建议:⚠️ 在部署前修复 pip-audit 发现的漏洞

后续步骤:
1. 更新有漏洞的依赖
2. 重新运行安全扫描
3. 部署到预发布环境进行最终测试

部署前检查清单 (Pre-Deployment Checklist)

  • 所有测试均已通过
  • 覆盖率 ≥ 80%
  • 无安全漏洞
  • 无未应用的迁移
  • 生产环境设置中 DEBUG = False
  • SECRET_KEY 已正确配置
  • ALLOWED_HOSTS 已正确设置
  • 数据库备份已启用
  • 静态文件已收集并提供服务
  • 日志已配置且正常工作
  • 错误监控(如 Sentry 等)已配置
  • CDN 已配置(如适用)
  • Redis/缓存后端已配置
  • Celery worker 已运行(如适用)
  • HTTPS/SSL 已配置
  • 环境变量已记录文档

持续集成 (Continuous Integration)

GitHub Actions 示例
yaml
# .github/workflows/django-verification.yml
name: Django Verification

on: [push, pull_request]

jobs:
  verify:
    runs-on: ubuntu-latest
    services:
      postgres:
        image: postgres:14
        env:
          POSTGRES_PASSWORD: postgres
        options: >-
          --health-cmd pg_isready
          --health-interval 10s
          --health-timeout 5s
          --health-retries 5

    steps:
      - uses: actions/checkout@v3

      - name: Set up Python
        uses: actions/setup-python@v4
        with:
          python-version: '3.11'

      - name: Cache pip
        uses: actions/cache@v3
        with:
          path: ~/.cache/pip
          key: ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }}

      - name: Install dependencies
        run: |
          pip install -r requirements.txt
          pip install ruff black mypy pytest pytest-django pytest-cov bandit safety pip-audit

      - name: Code quality checks
        run: |
          ruff check .
          black . --check
          isort . --check-only
          mypy .

      - name: Security scan
        run: |
          bandit -r . -f json -o bandit-report.json
          safety check --full-report
          pip-audit

      - name: Run tests
        env:
          DATABASE_URL: postgres://postgres:postgres@localhost:5432/test
          DJANGO_SECRET_KEY: test-secret-key
        run: |
          pytest --cov=apps --cov-report=xml --cov-report=term-missing

      - name: Upload coverage
        uses: codecov/codecov-action@v3

快速参考 (Quick Reference)

检查项命令
环境python --version
类型检查mypy .
Lint 检查ruff check .
格式化black . --check
迁移python manage.py makemigrations --check
测试pytest --cov=apps
安全pip-audit && bandit -r .
Django 检查python manage.py check --deploy
静态文件收集python manage.py collectstatic --noinput
差异统计git diff --stat

记住:自动化验证可以捕捉常见问题,但不能取代人工代码审查和在预发布环境中的手动测试。

© xu-xiang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/django-verification of xu-xiang/everything-claude-code-zh.

Open the folder on GitHubat commit dfbf946

Compare with similar skills

Django Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Django Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Django Verification this skillxu-xiang/everything-claude-code-zh2k—~2.2kAutomated safety check: PassMIT
Saleor Django Schema Migrationsaleor/saleor23k—~1kAutomated safety check: PassBSD-3-Clause
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Silk Profilerbaserow/baserow6.1k—~2.9kAutomated safety check: PassCustom licence
Arch Wikiahmedemad3/arch-wiki250—~5.1kAutomated safety check: PassNone
Run Testsnetboxlabs/netbox-branching155—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Generates and splits Django schema migrations for Saleor with manage.py makemigrations, enforcing one new model or one field change per migration file.

    23k GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Silk Profiler

    baserow/baserow

    Investigate backend performance using Django Silk profiling data.

    6.1k GitHub stars~2.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Arch Wiki

    ahmedemad3/arch-wiki

    Scans any project codebase for new/changed modules, endpoints, middleware, infrastructure, Docker topologies, SQL queries, or permissions and updates docs/architecture/architecture.json.

    250 GitHub stars~5.1k tokensUpdated 21 days ago
    Backend & APIsAuto-check passed
  • Run Tests

    netboxlabs/netbox-branching

    Run the netboxbranching plugin's Django test suite against a local NetBox checkout.

    155 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Add or change a CLIST Django management command, including arguments, resource selection, EventLog monitoring, or cron and Healthchecks wiring.

    439 GitHub stars~848 tokensUpdated 5 days ago
    Backend & APIsAuto-check passed

More from xu-xiang/everything-claude-code-zh

All 78 skills in this repo
  • Configure Ecc

    xu-xiang/everything-claude-code-zh

    Everything Claude Code 的交互式安装程序 — 引导用户选择并安装技能和规则到用户级或项目级目录,验证路径,并可选择优化已安装文件。

    2k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Continuous Learning V2

    xu-xiang/everything-claude-code-zh

    基于本能(Instinct)的学习系统,通过钩子(hooks)观察会话,创建带有置信度评分的原子本能,并将其演化为技能(Skills)、命令(Commands)或智能体(Agents)。v2.1 版本增加了项目作用域(project-scoped)的本能,以防止跨项目污染。

    2k GitHub stars~2.1k tokensUpdated 7 mo ago
    Auto-check passed
  • API Design

    xu-xiang/everything-claude-code-zh

    生产级 API 的 REST API 设计模式,包括资源命名、状态码、分页、过滤、错误响应、版本控制和速率限制. An agent skill from xu-xiang/everything-claude-code-zh.

    2k GitHub stars~2.7k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及适用于 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及针对 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed

Works with

Categories

Questions about Django Verification

What does Django Verification do?

针对 Django 项目的验证循环:包含数据库迁移、代码检查、带覆盖率的测试、安全扫描,以及在发布或 PR 前的部署就绪检查。. Django Verification is an agent skill from xu-xiang/everything-claude-code-zh.

When should I use Django Verification?

Django Verification fits situations like: tasks that involve Backend development.

How do I install Django Verification in Claude Code?

Run `npx skills add xu-xiang/everything-claude-code-zh --skill django-verification -a claude-code`. Or copy the skill folder (skills/django-verification in xu-xiang/everything-claude-code-zh) into .claude/skills/django-verification in your project. Claude Code loads it when a task matches its description.

How do I install Django Verification in Codex?

Run `npx skills add xu-xiang/everything-claude-code-zh --skill django-verification -a codex`. Or copy the skill folder (skills/django-verification in xu-xiang/everything-claude-code-zh) into .agents/skills/django-verification in your project. Codex loads it when a task matches its description.

Can I use Django Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xu-xiang/everything-claude-code-zh --skill django-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/django-verification, .gemini/skills/django-verification, .github/skills/django-verification and .opencode/skills/django-verification in your project.

What does Django Verification need to run?

Going by SKILL.md and its folder, Django Verification needs the command-line tools its instructions call (python, git, pytest, black, npm and mypy) and credentials named SECRET_KEY, DJANGO_SECRET_KEY and POSTGRES_PASSWORD. Our summary lists: Python 3; A credential in DJANGO_SECRET_KEY; A credential in SECRET_KEY.

Does Django Verification access the network?

SKILL.md contains no URLs. Its commands use git, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Django Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Django Verification use?

Django Verification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Django Verification use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Django Verification?

Skills that share tags, products or a category with Django Verification: Saleor Django Schema Migration (saleor/saleor, 23k stars), Django Access Review (getsentry/skills, 1k stars), Silk Profiler (baserow/baserow, 6.1k stars) and Arch Wiki (ahmedemad3/arch-wiki, 250 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Django Verification?

xu-xiang (a GitHub user) maintains it in xu-xiang/everything-claude-code-zh, which has 1,978 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on March 5, 2026.

Source: xu-xiang/everything-claude-code-zh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.