2026-07-26 - 2026-08-26
Overview
2 Pull requests merged by 1 user
Merged
#96 build: update golangci-lint to v2.12.2 with org-standard v2 config
Merged
#95 docs: document the no-DNS-mocking policy in README (closes #94)
8 Pull requests proposed by 1 user
Proposed
#97 Remove DNS mocking from tests
Proposed
#112 feat: add security response headers middleware (closes #98)
Proposed
#113 notify: drain in-flight deliveries at shutdown (closes #106)
Proposed
#118 server: set ReadTimeout, WriteTimeout, and IdleTimeout (closes #99)
Proposed
#122 ci: re-run make check on every cibuild instead of serving it from the layer cache (closes #115)
Proposed
#128 build: isolate golangci-lint cache and lock per checkout (closes #121)
Proposed
#131 build: always install pinned lint tools in script/bootstrap (closes #117)
Proposed
#136 next
1 Issue closed from 1 user
Closed
#94 Document the no-DNS-mocking policy in the README
36 Issues created by 1 user
Opened
#93 internal/resolver tests query live nameservers and fail nondeterministically
Opened
#94 Document the no-DNS-mocking policy in the README
Opened
#98 Add security response headers middleware (HSTS, CSP, X-Frame-Options, nosniff, Referrer-Policy, Permissions-Policy)
Opened
#99 http.Server is missing ReadTimeout, WriteTimeout, and IdleTimeout
Opened
#100 CORS wildcard applies to the authenticated /metrics route, and advertises methods that do not exist
Opened
#101 No rate limiting on the Basic-Auth-protected /metrics endpoint
Opened
#102 Add the MIT LICENSE file and README licence statement (1.0 blocker)
Opened
#103 script/test always runs with -v instead of the conditional verbose rerun pattern
Opened
#104 Per-nameserver query status is discarded: NS failure and NS recovery notifications never fire
Opened
#105 Nameserver glue/IP changes are never detected — README claims they trigger a notification
Opened
#106 In-flight notification goroutines are not awaited at shutdown, so alerts are lost
Opened
#107 DECISION NEEDED: DNSWATCHER_SENTRY_DSN is documented and accepted but does nothing
Opened
#108 README accuracy sweep: architecture omissions, undocumented state field, overclaimed MAINTENANCE_MODE and /metrics
Opened
#109 Dockerfile does not implement the mandated fail-fast lint stage, and does not pass VERSION as a build ARG
Opened
#110 internal/globals, internal/healthcheck, and internal/logger have no tests at all
Opened
#111 internal/state ships test-only constructors in the production build
Opened
#114 Final state persistence at shutdown depends on implicit fx hook ordering and is untested
Opened
#115 script/cibuild can report a green it did not earn: RUN make check is served from the Docker layer cache
Opened
#116 internal/notify shutdown tests: misleading failure diagnostic and an overloaded timing constant
Opened
#117 script/bootstrap installs pinned tools only when missing, so the golangci-lint pin is inert on any machine that already has one
Opened
#119 fmt tooling is incomplete: fmt-check does not verify goimports, and no formatter covers Markdown
Opened
#120 Server timeout tests protect the constructor but not the call site, and carry an inverted rationale comment
Opened
#121 script/lint shares one golangci-lint cache and lock across concurrent worktrees, so results can come from another codebase
Opened
#123 DECISION NEEDED: gomodguard linter is deprecated, and .golangci.yml can only be changed by you
Opened
#124 script/docker has the same layer-cache hole as script/cibuild, so make docker can hand a developer an unearned green
Opened
#125 CHECK_EPOCH freshness is host-conditional: busybox date silently drops %N
Opened
#126 DECISION/ACCESS NEEDED: the CI job log Gitea returns for a commit does not correspond to that commit
Opened
#129 script/install-precommit fails in a linked worktree: .git is a file, not a directory
Opened
#130 Lint cache follow-ups: same-checkout runs abort instead of queueing, and make clean leaves .lint-cache/
Opened
#132 go.mod is untidy: golang.org/x/sync listed both direct and indirect, so script/bootstrap mutates a tracked file
Opened
#133 script/lint and script/fmt invoke golangci-lint and goimports by bare name, so a PATH shadow still overrides the pin
Opened
#134 Run all linting in Docker via Dockerfile.lint + script/lint
Opened
#135 TOP PRIORITY: consolidate all open PRs onto one next branch, one PR
Opened
#137 Stale/incorrect comment text in script/bootstrap and script/cibuild, and record the config-verify tradeoff
Opened
#138 queryServers always tries servers in fixed order, so every resolution starts at a.root-servers.net
Opened
#139 make test is served from Go's test cache, so a repeat green proves no DNS was queried
2 Unresolved Conversations
Open
#66
1.0/mvp
Open
#59
No DNSSEC validation in iterative resolution