From 074b7bde15b6ce6554f30dd1c5af8c3fe17d90e1 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Tue, 29 Sep 2026 07:42:33 +0000 Subject: [PATCH] chore(backend): re-vendor .golangci.yml with gomodguard_v2 (closes #41) golangci-lint v2.12 deprecates gomodguard, which the org .golangci.yml reached through "default: all", so every lint run printed a deprecation warning. backend/.golangci.yml is now the current copy from sneak/prompts, fetched unedited: gomodguard is disabled and gomodguard_v2 enabled with the org block list. The new file also turns depguard on with its test-support rule, which forbids net/http/httptest outside test code. netwatch has no test-support packages of its own to add to that rule, so the file is identical to the canonical one. backend/script/lint checks the new sha256. The backend raises no findings under the new rules. Model: opus-5-5 --- TODO.md | 13 +++++---- backend/.golangci.yml | 68 +++++++++++++++++++++++++++++++++++++++++-- backend/script/lint | 2 +- 3 files changed, 74 insertions(+), 9 deletions(-) diff --git a/TODO.md b/TODO.md index e37242e..212faab 100644 --- a/TODO.md +++ b/TODO.md @@ -23,6 +23,13 @@ latest run passes. # Completed Steps +- 2026-09-29: `backend/.golangci.yml` re-vendored from `sneak/prompts` (issue + #41): `gomodguard`, deprecated in golangci-lint v2.12.0, is disabled and its + successor `gomodguard_v2` enabled with the org block list, so lint runs print + no deprecation warning. The new file also turns `depguard` on with its + `test-support` rule, which keeps `net/http/httptest` out of non-test code; + netwatch adds no entries of its own to that rule. `backend/script/lint` checks + the new sha256 - 2026-09-29: nginx sends the security headers `REPO_POLICIES.md` requires on every response (issue #18), including errors, `/assets/` and what it passes on from the backend, whose own copies it drops so each header goes out once. They @@ -191,9 +198,3 @@ latest run passes. (main always green policy) - Decide what to do with untracked resume.sh: commit it, gitignore it, or delete it -- Upstream fix needed in `sneak/prompts`: the org-standard `.golangci.yml` - enables `gomodguard`, which golangci-lint v2.12.2 reports as deprecated since - v2.12.0 and replaced by `gomodguard_v2`, so every backend lint run prints a - deprecation warning. The file is standardized and must never be edited in this - repo, so nothing can be done here beyond tracking it — tracked at - diff --git a/backend/.golangci.yml b/backend/.golangci.yml index 26b1610..a7a74c2 100644 --- a/backend/.golangci.yml +++ b/backend/.golangci.yml @@ -10,14 +10,20 @@ run: linters: default: all + enable: + # Successor to the deprecated gomodguard. Named explicitly, rather than + # left to `default: all`, because it carries the module policy below. + - gomodguard_v2 disable: # Genuinely incompatible with project patterns - exhaustruct # Requires all struct fields - - depguard # Dependency allow/block lists - godot # Requires comments to end with periods - - wsl # Deprecated, replaced by wsl_v5 - wrapcheck # Too verbose for internal packages - varnamelen # Short names like db, id are idiomatic Go + # Deprecated: the warning is attached to the old name, so it is + # silenced by disabling that name, not by enabling the successor. + - wsl # Deprecated, replaced by wsl_v5 + - gomodguard # Deprecated, replaced by gomodguard_v2 settings: lll: line-length: 88 @@ -28,6 +34,64 @@ linters: max-complexity: 15 dupl: threshold: 100 + depguard: + # Test-support code must not be compiled into the shipped binary. A + # test-support package exists to hand a test privileges the program + # itself must never have, so a file that is not a test must not import + # one. Test files, and the files inside a package whose directory name + # ends in `test`, are where that code belongs, and are exempt. + # + # The deny list below is the one part of this file a repository is + # expected to extend, and the only part it may. depguard matches an + # import path against a list of prefixes, so it cannot be told "any path + # whose last segment ends in test"; a repository's own test-support + # packages have to be named here one at a time, by full import path, + # under a module path that differs from repository to repository. Add + # them; change nothing else. + rules: + test-support: + list-mode: lax + files: + - "$all" + - "!$test" + - "!**/*test/**" + deny: + - pkg: net/http/httptest + desc: >- + Test-support code belongs in test files and in packages whose + directory name ends in test, not in the shipped binary. + # Only decisions already recorded in the Go package defaults are + # listed here. Every entry matches the module path exactly. + gomodguard_v2: + blocked: + - module: github.com/rs/zerolog + recommendations: + - log/slog + reason: "Structured logging is stdlib log/slog." + # One entry per pre-fork module path, because the later releases + # are separate paths. A prefix match would be shorter but would + # also reach github.com/go-redis/redismock, the test double for + # the successor these entries recommend. + - module: github.com/go-redis/redis + recommendations: + - github.com/redis/go-redis/v9 + reason: "Pre-fork module; use the maintained go-redis v9." + - module: github.com/go-redis/redis/v7 + recommendations: + - github.com/redis/go-redis/v9 + reason: "Pre-fork module; use the maintained go-redis v9." + - module: github.com/go-redis/redis/v8 + recommendations: + - github.com/redis/go-redis/v9 + reason: "Pre-fork module; use the maintained go-redis v9." + - module: github.com/sergi/go-diff + recommendations: + - github.com/aymanbagabas/go-udiff + reason: "No unified diff output; use go-udiff." + - module: github.com/hexops/gotextdiff + recommendations: + - github.com/aymanbagabas/go-udiff + reason: "Unmaintained fork; use go-udiff." issues: max-issues-per-linter: 0 diff --git a/backend/script/lint b/backend/script/lint index 256f805..720b747 100755 --- a/backend/script/lint +++ b/backend/script/lint @@ -14,7 +14,7 @@ set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" -GOLANGCI_CONFIG_SHA256="021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb" +GOLANGCI_CONFIG_SHA256="a79b63a254602a5318db5d0e9a06bc71b84bf0c1d896305229d8bfed1d1b1776" main() { cd "$ROOT" -- 2.54.0