From c1a85ec5a242147cd5dbd6f9ea804817f4d98678 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 12:44:42 +0000 Subject: [PATCH] Record the gomodguard_v2 migration in TODO.md (closes #57) Adds the Completed Steps entry for re-vendoring the canonical .golangci.yml, which switches off the deprecated gomodguard and runs gomodguard_v2 and depguard in its place. Model: opus-5-5 --- TODO.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/TODO.md b/TODO.md index 84e896f..11b5a2d 100644 --- a/TODO.md +++ b/TODO.md @@ -53,6 +53,11 @@ P2: security: referer blacklist not exist is passed over; any other error, such as a directory on the path that pixa may not enter, aborts startup naming the file, as a file that does not parse already did. +- 2026-10-04 `.golangci.yml` re-vendored from the canonical copy (closes #57): + the deprecated `gomodguard` is switched off, so lint runs print no + deprecation warning; its successor `gomodguard_v2` runs with the shared + module block list, and `depguard` keeps `net/http/httptest` out of files that + are not tests. The tree needed no code changes. - 2026-10-04 deployment guide and example Caddy config (closes #89): "Deployment" in `README.md` says what the reverse proxy in front of pixa must do (terminate TLS; pass `Host`, `Origin` and `Referer` on unchanged; set