From a614cd6ffba859228f5268cf9c9f21f4794ccc5c Mon Sep 17 00:00:00 2001 From: sneak Date: Wed, 19 Aug 2026 14:25:30 +0000 Subject: [PATCH] policy: scope the .golangci.yml rule to vendored copies Stated unqualified, the rule forbade an agent from modifying .golangci.yml anywhere, including the canonical copy in this repo -- the only place it can be fixed. Compliance and remediation were mutually exclusive. Scope the prohibition to the vendored copy in a consuming repo, which is the property the rule exists to protect, and name the one legitimate path for change: a PR against canonical here, merged only by the user. --- prompts/REPO_POLICIES.md | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/prompts/REPO_POLICIES.md b/prompts/REPO_POLICIES.md index 9aba6b0..7e45c8f 100644 --- a/prompts/REPO_POLICIES.md +++ b/prompts/REPO_POLICIES.md @@ -1,6 +1,6 @@ --- title: Repository Policies -last_modified: 2026-08-07 +last_modified: 2026-08-19 --- This document covers repository structure, tooling, and workflow standards. Code @@ -263,11 +263,14 @@ style conventions are in separate documents: - Make all changes on a feature branch. You can do whatever you want on a feature branch. -- `.golangci.yml` is standardized and must _NEVER_ be modified by an agent, only - manually by the user. Fetch from - `https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`. The - canonical golangci-lint version is v2.12.2 (released 2026-05-06), installed - commit-pinned via +- `.golangci.yml` is standardized. The vendored copy in a consuming repo must + _NEVER_ be modified by an agent: fetch it from + `https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml` and keep it + byte-identical, so that no repo can quietly loosen its own linting. Linter + configuration changes are made to the canonical copy in the `prompts` repo and + reach consuming repos by re-vendoring; an agent may open a PR against + canonical, which only the user merges. The canonical golangci-lint version is + v2.12.2 (released 2026-05-06), installed commit-pinned via `go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5`. - When pinning images or packages by hash, add a comment above the reference