chore(backend): re-vendor .golangci.yml with gomodguard_v2 (closes #41) #71

Merged
clawbot merged 1 commits from chore/golangci-gomodguard-v2 into next 2026-09-29 10:56:01 +02:00
Collaborator

Re-vendors the org-standard .golangci.yml into backend/.golangci.yml for #41, as sneak/prompts#60 asks of every repo that vendors it.

golangci-lint v2.12 deprecates gomodguard, which the old file reached through default: all, so every backend lint run printed a deprecation warning. The new file, fetched unedited from sneak/prompts, disables gomodguard and enables gomodguard_v2 with the org block list (rs/zerolog, the pre-fork go-redis/redis, sergi/go-diff, hexops/gotextdiff). backend/script/lint now checks the new sha256.

What the diff does not show:

  • The new file also turns depguard on, with a test-support rule that forbids importing net/http/httptest outside test code. That rule's deny list is the one part a repo may extend. The old netwatch copy had no depguard rule and netwatch has no test-support packages of its own, so there is nothing to carry forward and the vendored file is byte-identical to the canonical one.
  • Neither new rule finds anything in the backend: no blocked module is required and no non-test file imports net/http/httptest, so no source change was needed.
  • The TODO.md Future Steps item that tracked this as an upstream problem is removed.

Model: opus-5-5

Re-vendors the org-standard `.golangci.yml` into `backend/.golangci.yml` for https://git.eeqj.de/sneak/netwatch/issues/41, as https://git.eeqj.de/sneak/prompts/issues/60 asks of every repo that vendors it. golangci-lint v2.12 deprecates `gomodguard`, which the old file reached through `default: all`, so every backend lint run printed a deprecation warning. The new file, fetched unedited from `sneak/prompts`, disables `gomodguard` and enables `gomodguard_v2` with the org block list (`rs/zerolog`, the pre-fork `go-redis/redis`, `sergi/go-diff`, `hexops/gotextdiff`). `backend/script/lint` now checks the new sha256. What the diff does not show: - The new file also turns `depguard` on, with a `test-support` rule that forbids importing `net/http/httptest` outside test code. That rule's `deny` list is the one part a repo may extend. The old netwatch copy had no `depguard` rule and netwatch has no test-support packages of its own, so there is nothing to carry forward and the vendored file is byte-identical to the canonical one. - Neither new rule finds anything in the backend: no blocked module is required and no non-test file imports `net/http/httptest`, so no source change was needed. - The `TODO.md` Future Steps item that tracked this as an upstream problem is removed. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 09:46:30 +02:00
clawbot self-assigned this 2026-09-29 09:46:31 +02:00
Author
Collaborator

PASS: backend/.golangci.yml is byte-identical to the canonical file in sneak/prompts, backend/script/lint checks its sha256, the deprecation warning is gone, and the new rules hold with no source changes.

Model: opus-5-5

PASS: `backend/.golangci.yml` is byte-identical to the canonical file in `sneak/prompts`, `backend/script/lint` checks its sha256, the deprecation warning is gone, and the new rules hold with no source changes. Model: opus-5-5
clawbot added 1 commit 2026-09-29 10:25:44 +02:00
golangci-lint v2.12 deprecates gomodguard, which the org .golangci.yml
reached through "default: all", so every lint run printed a
deprecation warning. backend/.golangci.yml is now the current copy
from sneak/prompts, fetched unedited: gomodguard is disabled and
gomodguard_v2 enabled with the org block list. The new file also
turns depguard on with its test-support rule, which forbids
net/http/httptest outside test code. netwatch has no test-support
packages of its own to add to that rule, so the file is identical to
the canonical one. backend/script/lint checks the new sha256. The
backend raises no findings under the new rules.

Model: opus-5-5
clawbot force-pushed chore/golangci-gomodguard-v2 from a346837d34 to 074b7bde15 2026-09-29 10:25:44 +02:00 Compare
Author
Collaborator

PASS: After the rebase the change is identical to the reviewed commit except TODO.md, which keeps every entry on next plus this change's entry, and backend/.golangci.yml still matches the canonical file.

Model: opus-5-5

PASS: After the rebase the change is identical to the reviewed commit except `TODO.md`, which keeps every entry on `next` plus this change's entry, and `backend/.golangci.yml` still matches the canonical file. Model: opus-5-5
clawbot merged commit c226ceee01 into next 2026-09-29 10:56:01 +02:00
clawbot deleted branch chore/golangci-gomodguard-v2 2026-09-29 10:56:01 +02:00
clawbot removed the needs-review label 2026-09-29 10:56:01 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#71