2025-10-02 - 2026-10-02
Översikt
28 Pull begärelser sammanfogad av 2 användare
Sammanfogad
#70 Derive the image version from git; send .git without its config (closes #69, closes #71)
Sammanfogad
#67 Read the architecture at run time, not via a Buildarch ldflag (closes #66)
Sammanfogad
#55 Migrate canonical .golangci.yml to gomodguard_v2, with a block list
Sammanfogad
#34 Milestone next: check-cache busting, build-context hygiene, lint in a container
Sammanfogad
#45 Add -count=1 to the canonical Go make test example
Sammanfogad
#59 Enable depguard so a non-test file cannot import test support
Sammanfogad
#49 Scope the .golangci.yml agent prohibition to vendored copies
Sammanfogad
#54 Require thin cmd/ entrypoints: all logic in internal/ or pkg/
Sammanfogad
#42 Raise org-wide make test cap to 60s, backstop timeout to 90s
Sammanfogad
#24 Set canonical .golangci.yml to the org-standard v2 config (golangci-lint v2.12.2)
Sammanfogad
#23 Adopt scripts-to-rule-them-all: script/ entrypoints, Makefile shims, policy update
Sammanfogad
#22 TODO
Sammanfogad
#19 style: strengthen constructor naming and Params struct rules
Sammanfogad
#21 docs: document conditional -v test rerun pattern in REPO_POLICIES.md
Sammanfogad
#18 docs: document fail-fast lint stage pattern for Dockerfiles
Sammanfogad
#17 Add HTTP service hardening policy for 1.0 releases
Sammanfogad
#15 policy: no build artifacts in repos
Sammanfogad
#14 Self-apply checklist to LLM prose tells doc
Sammanfogad
#13 Remove unfunny frequency exchange from lol section
Sammanfogad
#12 Fix em-dash examples in checklist + strip frequency persuasion
Sammanfogad
#11 LLM prose tells: merge adjacent sentences, add checklist items
Sammanfogad
#10 LLM prose tells: fix first paragraph
Sammanfogad
#9 LLM prose tells: methodical checklist pass
Sammanfogad
#8 Update LLM prose tells: new patterns + lol section
Sammanfogad
#7 Add LLM prose tells reference and copyediting checklist
Sammanfogad
#6 REPO_POLICIES: expand pre-1.0 schema migration rule (closes #5)
Sammanfogad
#4 fix: formatting + add clawpub reference
Sammanfogad
#2 style(go): add rule against type-only packages (per upaas #126 review)
1 Pull-begäran föreslås av 1 användare
Föreslagen
#68 next → main: architecture at run time, version from git
22 Ärenden closed from 2 användare
Stängd
#71 Version stamp follow-up: keep .git/config out of the build context; a bare docker build must succeed
Stängd
#69 Version stamp: the build derives the version from git; .git is no longer excluded
Stängd
#66 Remove buildarch from the Go styleguide and HTTP server conventions: read the architecture at run time
Stängd
#63 Run every build, test and lint step in the Dockerfiles at nice -n 19
Stängd
#36 Operational consequence of CHECK_EPOCH: every check layer is unreusable by construction, so builder-cache growth is unbounded across the fleet
Stängd
#33 DECISION NEEDED: canonical script/bootstrap pins NODE_VERSION and YARN_VERSION but policy tells it to skip on any version found — the pins are decorative
Stängd
#46 Decision: vmsetup and secpol are tracked projects with no repo on the instance
Stängd
#25 canonical .golangci.yml emits a gomodguard deprecation warning under golangci-lint v2.12+
Stängd
#28 script/bootstrap installs the pinned golangci-lint only if missing, so version pins are inert on any machine that already has the tool
Stängd
#29 SECURITY: canonical .dockerignore does not exclude .env, *.pem or *.key, so local secrets ship into the Docker build context
Stängd
#30 script/lint shares one golangci-lint cache across all concurrent sessions, producing cross-contaminated results
Stängd
#27 canonical .dockerignore omits .claude/, so agent worktrees land in the Docker build context
Stängd
#40 All linting must run in Docker: canonicalise homoicon's Dockerfile.lint + script/lint pattern
Stängd
#26 script/cibuild reports a green it did not earn: Docker serves the make check layer from cache
Stängd
#57 PROPAGATION: roll the -count=1 Go test-cache fix (#44) into every consuming Go repo — as ONE commit per repo
Stängd
#56 Dockerfile.lint has no .git, so gitignore-honouring linters walk a different file set than they do locally
Stängd
#32 Go test cache is a second, independent source of unearned greens: canonical make test lacks -count=1
Stängd
#52 REPO_POLICIES: carve out capability-URL services from "when in doubt, harden"
Stängd
#41 Test-time cap: is 60s the new org-wide ceiling, or a dnswatcher divergence?
Stängd
#20 docs: document conditional -v test rerun pattern in REPO_POLICIES.md
Stängd
#16 additional repo policy
Stängd
#5 REPO_POLICIES: add pre-1.0 schema migration rule
34 Ärenden skapad av 1 användare
Öppnad
#5 REPO_POLICIES: add pre-1.0 schema migration rule
Öppnad
#16 additional repo policy
Öppnad
#20 docs: document conditional -v test rerun pattern in REPO_POLICIES.md
Öppnad
#25 canonical .golangci.yml emits a gomodguard deprecation warning under golangci-lint v2.12+
Öppnad
#26 script/cibuild reports a green it did not earn: Docker serves the make check layer from cache
Öppnad
#27 canonical .dockerignore omits .claude/, so agent worktrees land in the Docker build context
Öppnad
#28 script/bootstrap installs the pinned golangci-lint only if missing, so version pins are inert on any machine that already has the tool
Öppnad
#29 SECURITY: canonical .dockerignore does not exclude .env, *.pem or *.key, so local secrets ship into the Docker build context
Öppnad
#30 script/lint shares one golangci-lint cache across all concurrent sessions, producing cross-contaminated results
Öppnad
#31 DECISION NEEDED: canonical REPO_POLICIES.md is missing the in-repo memory bullet that stale vendored copies still carry — retired, or lost?
Öppnad
#32 Go test cache is a second, independent source of unearned greens: canonical make test lacks -count=1
Öppnad
#33 DECISION NEEDED: canonical script/bootstrap pins NODE_VERSION and YARN_VERSION but policy tells it to skip on any version found — the pins are decorative
Öppnad
#35 PROPAGATION: roll the Docker build-context trio (#26 CHECK_EPOCH, #29 .dockerignore secrets, #27 .claude/) into every consuming repo — as ONE commit per repo
Öppnad
#36 Operational consequence of CHECK_EPOCH: every check layer is unreusable by construction, so builder-cache growth is unbounded across the fleet
Öppnad
#37 DECISION NEEDED: should pinned Go tools be go install-with-commit-pin, or tracked as go.mod tool dependencies?
Öppnad
#38 SECURITY: canonical .gitignore misses common secret shapes (*.env, .envrc, *.p12/*.pfx, extensionless SSH keys)
Öppnad
#39 PROPAGATION: roll the Go tooling fixes (#28 bootstrap version enforcement, #30 lint cache/lock isolation) into every Go repo — as ONE commit per repo
Öppnad
#40 All linting must run in Docker: canonicalise homoicon's Dockerfile.lint + script/lint pattern
Öppnad
#41 Test-time cap: is 60s the new org-wide ceiling, or a dnswatcher divergence?
Öppnad
#44 Canonical Go make test example omits -count=1, shipping a false green to every repo
Öppnad
#46 Decision: vmsetup and secpol are tracked projects with no repo on the instance
Öppnad
#48 next still carries the pre-ruling 20s/30s test budget, so PR 34 will revert the org-wide ruling when it rebases
Öppnad
#51 issue-to-pr workers break the no-scripted-search-and-replace and no-raw-go-tools rules at a measured 3-in-4 rate
Öppnad
#52 REPO_POLICIES: carve out capability-URL services from "when in doubt, harden"
Öppnad
#56 Dockerfile.lint has no .git, so gitignore-honouring linters walk a different file set than they do locally
Öppnad
#57 PROPAGATION: roll the -count=1 Go test-cache fix (#44) into every consuming Go repo — as ONE commit per repo
Öppnad
#60 PROPAGATION: roll the new canonical .golangci.yml bytes (gomodguard_v2 migration) into every consuming repository
Öppnad
#61 Test recipe reruns a hung suite, so a hang costs the 90s backstop twice and can exceed the 5 minute build limit
Öppnad
#62 Fold the August fleet findings into the policies, or drop them
Öppnad
#63 Run every build, test and lint step in the Dockerfiles at nice -n 19
Öppnad
#65 Canonical golangci-lint pin cannot lint Go 1.27 modules; its successors enable exhaustruct_v5, which the canonical config does not disable
Öppnad
#66 Remove buildarch from the Go styleguide and HTTP server conventions: read the architecture at run time
Öppnad
#69 Version stamp: the build derives the version from git; .git is no longer excluded
Öppnad
#71 Version stamp follow-up: keep .git/config out of the build context; a bare docker build must succeed