The old backend/.golangci.yml declared version "2" but used v1 schema
keys, so under v2 it never validated and its thresholds were inert: the
linter ran at defaults. Replace it verbatim with the org-standard file,
repin the Dockerfile.backend lint stage from golangci-lint v2.7.2 to
v2.12.2, and assert the config's sha256 as the first step of the backend
lint target so it cannot silently drift again -- a local hash check
against a constant, no network. With the config loading, lll flags one
over-long line; wrap it and the two others named on the issue, moving
each //nolint justification above the code line, and drop a dead
//nolint:wsl (wsl is disabled by the standard config). TODO.md updated.
Model: opus-4-8
Place the backend Dockerfile at repo root as Dockerfile.backend so
the build context includes .git, giving git describe access for
version stamping. Fix .gitignore pattern to anchor /netwatch-server
so it does not exclude cmd/netwatch-server/. Remove .git from
.dockerignore. Update CI workflow and backend Makefile docker target.