Pin golangci-lint v2.14.0; disable exhaustruct_v5 (closes #65)

v2.12.2 is built with go1.26 and refuses to lint a module whose go
directive is 1.27 or later. v2.14.0 is built with go1.27. Releases
from v2.13.0 deprecate exhaustruct in favour of exhaustruct_v5, which
default: all switches on and which reports every partial struct
literal, so the canonical config disables it beside exhaustruct for
the same reason. REPO_POLICIES now names the new image digest and says
that a repo moving to a new version re-vendors .golangci.yml with it.

Model: opus-5-5
This commit is contained in:
2026-10-03 15:42:23 +00:00
parent 7ea5cdcdcd
commit 10729365de
3 changed files with 16 additions and 6 deletions
+1
View File
@@ -17,6 +17,7 @@ linters:
disable:
# Genuinely incompatible with project patterns
- exhaustruct # Requires all struct fields
- exhaustruct_v5 # Requires all struct fields (successor to exhaustruct)
- godot # Requires comments to end with periods
- wrapcheck # Too verbose for internal packages
- varnamelen # Short names like db, id are idiomatic Go
+5
View File
@@ -21,6 +21,11 @@ fmt-check, and commit.
# Completed Steps
- 2026-10-03: Moved the canonical golangci-lint to v2.14.0, built with go1.27,
because v2.12.2 refuses to lint a module whose `go` directive is 1.27 (issue
65). Releases from v2.13.0 deprecate `exhaustruct` in favour of
`exhaustruct_v5`, which `default: all` switches on, so the canonical
`.golangci.yml` now disables `exhaustruct_v5` beside `exhaustruct`.
- 2026-10-03: Brought the canonical `.gitignore` level with `.dockerignore` on
secrets (issue 38): it now also ignores `prod.env`-style `*.env` files,
`.envrc`, `*.p12`, `*.pfx` and the extensionless SSH private keys, written to
+10 -6
View File
@@ -1,6 +1,6 @@
---
title: Repository Policies
last_modified: 2026-10-02
last_modified: 2026-10-03
---
This document covers repository structure, tooling, and workflow standards. Code
@@ -451,12 +451,16 @@ style conventions are in separate documents:
`test-support` depguard rule, where a repo names its own test-support packages
by full import path. A repo adds entries there and changes nothing else, and a
re-vendor carries its entries forward. The canonical golangci-lint version is
v2.12.2 (released 2026-05-06), pinned as the digest of the lint phase's base
v2.14.0 (released 2026-09-24), pinned as the digest of the lint phase's base
image
(`golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240`,
which reports `2.12.2 built with go1.26.2 from c0d3ddc9`). That digest is the
only pin, since no repo installs golangci-lint on the host: bumping the
version means changing it and nothing else.
(`golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f`,
which reports `2.14.0 built with go1.27.0 from 114493f9`). A golangci-lint
built with go1.26 refuses to lint a module whose `go` directive is 1.27 or
later, so a new Go version needs a golangci-lint built with it. That digest is
the only pin, since no repo installs golangci-lint on the host. A repo moving
to a new version changes that digest and re-vendors `.golangci.yml` in the
same commit, because a new release can add linters that `default: all`
switches on until the canonical copy disables them.
- **`script/bootstrap` installs a pinned tool by comparing versions, never by
testing presence.** An `if ! command -v <tool>; then install; fi` guard tests