# T01 — Repo + dependency baseline **Phase** 0 · **Depends on** — · **Status** Done ## Goal Put the project under version control and add every dependency v2 needs, verifying the build stays green before a single line of feature code changes. Done when `git log` shows v1 committed, the new libraries resolve, and `assembleDebug testDebugUnitTest lintDebug` all pass. ## Context - `~/dojo/rippr` is **not currently a git repo**. A multi-phase rewrite with no version control and no way to diff or revert is reckless — this is the first thing to fix. - `.gitignore` already exists and covers `build/`, `.gradle/`, `local.properties`, `.idea/`, `.DS_Store`. - `gradle/libs.versions.toml` is the single source of dependency truth. Everything goes through the catalog; no inline coordinates in `app/build.gradle.kts`. - `app/build.gradle.kts` already carries a `constraints` block forcing `androidx.fragment:1.8.5` — play-services drags in 1.1.0 transitively and lint rejects it. Leave that alone. ## Design Three new dependencies, all in the catalog: | Library | Why | |---|---| | `org.osmdroid:osmdroid-android` | Map rendering (T13/T14). Apache-2.0, no API key | | `androidx.navigation:navigation-compose` | Three destinations (T08) | | `androidx.lifecycle:lifecycle-viewmodel-compose` | ViewModels (T08) | osmdroid is added now rather than at T13 so any resolution or manifest-merge surprise surfaces against a known-green build instead of tangled up with map code. `local.properties` stays gitignored — it holds a machine-specific `sdk.dir`. ## Implementation 1. `git init` in `~/dojo/rippr`, confirm `.gitignore` covers build outputs, and verify `git status` shows no `build/` or `local.properties` noise. 2. Commit v1 as the baseline — source, design generators, vendored Material glyphs, and the v2 docs. 3. Add to `[versions]`: `osmdroid`, `navigation`, `lifecycleViewmodel`. 4. Add to `[libraries]`: `osmdroid-android`, `androidx-navigation-compose`, `androidx-lifecycle-viewmodel-compose`. 5. Wire the three into `app/build.gradle.kts` `dependencies`. 6. Build and test. 7. Commit the dependency bump separately, so a resolution problem is bisectable. ## Acceptance criteria - [ ] `git log` shows at least two commits: v1 baseline, then dependency bump - [ ] `git status` clean — no build artefacts or `local.properties` tracked - [ ] All three libraries resolve - [ ] `./gradlew assembleDebug testDebugUnitTest lintDebug` passes - [ ] 12/12 existing unit tests still green ## Tests No new tests. This task's job is proving the existing suite still passes with the new dependency graph — particularly that osmdroid does not introduce a manifest-merge conflict or a duplicate-class error. ## Risks / gotchas - **osmdroid manifest merge.** It historically declared storage permissions. Modern versions use app-private cache, but check the merged manifest afterward: `aapt2 dump xmltree --file AndroidManifest.xml app/build/outputs/apk/debug/app-debug.apk` and confirm no unexpected permission appeared. - **Do not commit the APK.** Release artefacts belong in `~/dojo/samplez`, not here. ## Out of scope Any use of the new libraries. This task only proves they resolve.