The old backend/.golangci.yml declared version "2" but used v1 schema
keys, so under v2 it never validated and its thresholds were inert: the
linter ran at defaults. Replace it verbatim with the org-standard file,
repin the Dockerfile.backend lint stage to golangci-lint v2.12.2, and
assert the config's sha256 as the first step of the backend lint target
so it cannot silently drift again -- a local hash check, no network.
Fix every finding the standard config surfaces in the Go source: wrap
over-long lines, drop a dead //nolint:wsl, hoist the repeated test IP
literals in middleware_test.go to named constants (goconst), and switch
its request to NewRequestWithContext (noctx). TODO.md updated.
Model: opus-4-8