- Add canonical .golangci.yml (v2 schema, default: all, project
thresholds for lll/funlen/cyclop/dupl)
- Bump golangci-lint pins from v2.0.2 to v2.12.2 in Makefile
(go install, new /v2 module path) and Dockerfile (tagged+digest
Debian image pin)
- Fix all lint findings surfaced by the new linter set across
cmd/mfer, internal/bork, internal/cli, internal/log, and mfer:
static sentinel errors (err113), context-aware HTTP and exec
(noctx), guarded integer conversions and stricter permissions
(gosec), named constants (mnd, goconst), function decomposition
(funlen, cyclop, gocognit, nestif), declaration ordering
(funcorder), t.Parallel/t.TempDir/t.Setenv adoption in tests
(paralleltest, usetesting), protobuf getters (protogetter), plus
formatting and style cleanups (wsl_v5, nlreturn, lll, revive,
testifylint, and others)
- Serialize CLI runs in tests behind a mutex so parallel tests do
not cross-wire the process-global logger's captured output
- Add --sign-key flag and MFER_SIGN_KEY env var to gen and freshen commands
- Sign inner message multihash with GPG detached signature
- Include signer fingerprint and public key in outer wrapper
- Add comprehensive tests with temporary GPG keyring
- Increase test timeout to 10s for GPG key generation
- Add FileCount, FileSize, RelFilePath, AbsFilePath, ModTime, Multihash types
- Add UnixSeconds and UnixNanos types for timestamp handling
- Add URL types (ManifestURL, FileURL, BaseURL) with safe path joining
- Consolidate scanner package into mfer package
- Update checker to use custom types in Result and CheckStatus
- Add ModTime.Timestamp() method for protobuf conversion
- Update all tests to use proper custom types
- Atomic writes for mfer gen: writes to temp file, renames on success,
cleans up temp on error/interrupt. Prevents empty manifests on Ctrl-C.
- Humanized byte sizes using dustin/go-humanize (e.g., "10 MiB" not "10485760")
- Progress lines clear when done (using ANSI escape \r\033[K])
- Debug logging when files are added to manifest (mfer gen -vv)
- Move -v/-q flags from global to per-command for better UX
- Add tests for atomic write behavior with failing filesystem mock
- pathIsHidden(".") was returning true, causing freshen to skip entire
directory tree when dotfiles excluded
- Banner now prints directly to stdout to avoid log prefix artifacts
Changed the default behavior to exclude dotfiles (files/dirs starting with .)
which is the more common use case. Added --include-dotfiles flag for when
hidden files need to be included in the manifest.
Replace callback-based progress reporting in Builder.AddFile with
channel-based FileHashProgress for consistency with EnumerateStatus
and ScanStatus patterns. Update scanner.go to use the new channel API.