Record the gomodguard_v2 migration in TODO.md (closes #57)
check / check (push) Waiting to run

Adds the Completed Steps entry for re-vendoring the canonical
.golangci.yml, which switches off the deprecated gomodguard and runs
gomodguard_v2 and depguard in its place.

Model: opus-5-5
This commit is contained in:
2026-10-04 13:16:17 +00:00
parent 8f2779a0cc
commit 83bea41607
+5
View File
@@ -29,6 +29,11 @@ P2: security: referer blacklist
# Completed Steps
- 2026-10-04 `.golangci.yml` re-vendored from the canonical copy (closes #57):
the deprecated `gomodguard` is switched off, so lint runs print no
deprecation warning; its successor `gomodguard_v2` runs with the shared
module block list, and `depguard` keeps `net/http/httptest` out of files that
are not tests. The tree needed no code changes.
- 2026-10-04 deployment guide and example Caddy config (closes #89):
"Deployment" in `README.md` says what the reverse proxy in front of pixa must
do (terminate TLS; pass `Host`, `Origin` and `Referer` on unchanged; set