#!/bin/sh # script/lint: run golangci-lint over the backend. This runs inside the # lint stage of Dockerfile.backend, whose digest-pinned golangci-lint # image provides the linter; nothing installs golangci-lint on the host. # From a checkout, run `make lint` at the repo root, which builds that # stage. # # .golangci.yml is standardized org-wide and must never be edited here # (REPO_POLICIES.md). Its last silent drift replaced the v2 schema with # v1 keys, which left every threshold in the file inert while the build # stayed green. So the file is first checked against the canonical # copy's sha256: a local comparison, no network, nothing unpinned. set -eu ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" GOLANGCI_CONFIG_SHA256="021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb" main() { cd "$ROOT" actual="$(sha256sum .golangci.yml | cut -d' ' -f1)" if [ "$actual" != "$GOLANGCI_CONFIG_SHA256" ]; then echo ".golangci.yml has drifted from the org standard." >&2 echo " expected $GOLANGCI_CONFIG_SHA256" >&2 echo " actual $actual" >&2 echo "Restore it verbatim from sneak/prompts; do not edit it." >&2 exit 1 fi golangci-lint run ./... } main "$@"