diff --git a/TODO.md b/TODO.md index 02ca544..0c2047e 100644 --- a/TODO.md +++ b/TODO.md @@ -25,7 +25,9 @@ fmt-check, and commit. because v2.12.2 refuses to lint a module whose `go` directive is 1.27 (issue 65). Releases from v2.13.0 deprecate `exhaustruct` in favour of `exhaustruct_v5`, which `default: all` switches on, so the canonical - `.golangci.yml` now disables `exhaustruct_v5` beside `exhaustruct`. + `.golangci.yml` now disables `exhaustruct_v5` beside `exhaustruct`. v2.12.2 + rejects that file, so `REPO_POLICIES.md` and both repo checklists now say a + repo sets the lint phase digest and re-vendors `.golangci.yml` in one commit. - 2026-10-02: The image version now comes from git inside the build (issues 69 and 71), superseding the 2026-09-08 entry that excluded `.git`. The canonical `.dockerignore` sends `.git` but keeps out `.git/config`, which can hold a diff --git a/prompts/EXISTING_REPO_CHECKLIST.md b/prompts/EXISTING_REPO_CHECKLIST.md index 369b534..129ccec 100644 --- a/prompts/EXISTING_REPO_CHECKLIST.md +++ b/prompts/EXISTING_REPO_CHECKLIST.md @@ -1,6 +1,6 @@ --- title: Existing Repo Checklist -last_modified: 2026-10-02 +last_modified: 2026-10-03 --- Use this checklist when beginning work in a repo that may not yet conform to our @@ -80,7 +80,9 @@ with your task. `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml` - [ ] Language-specific config: - [ ] Go: `go.mod`, `go.sum`, `.golangci.yml` (fetch from - `https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`) + `https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml` and, + in the same commit, set the lint phase digest to the one named in the + `.golangci.yml` paragraph of `REPO_POLICIES.md`) - [ ] JS: `package.json`, `yarn.lock`, `.prettierrc`, `.prettierignore` (fetch from `https://git.eeqj.de/sneak/prompts/raw/branch/main/.prettierrc` and diff --git a/prompts/NEW_REPO_CHECKLIST.md b/prompts/NEW_REPO_CHECKLIST.md index b4d8e5f..d28a79e 100644 --- a/prompts/NEW_REPO_CHECKLIST.md +++ b/prompts/NEW_REPO_CHECKLIST.md @@ -1,6 +1,6 @@ --- title: New Repo Checklist -last_modified: 2026-10-02 +last_modified: 2026-10-03 --- Use this checklist when creating a new repository from scratch. Follow the steps @@ -94,7 +94,9 @@ Template files can be fetched from: `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml` - [ ] Language-specific: - [ ] Go: `go mod init sneak.berlin/go/`, `.golangci.yml` (fetch from - `https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`) + `https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml` and, + in the same commit, set the lint phase digest to the one named in the + `.golangci.yml` paragraph of `REPO_POLICIES.md`) - [ ] JS: `yarn init`, `yarn add --dev prettier` - [ ] Python: `pyproject.toml` diff --git a/prompts/REPO_POLICIES.md b/prompts/REPO_POLICIES.md index 4456a98..2d12b70 100644 --- a/prompts/REPO_POLICIES.md +++ b/prompts/REPO_POLICIES.md @@ -454,13 +454,15 @@ style conventions are in separate documents: v2.14.0 (released 2026-09-24), pinned as the digest of the lint phase's base image (`golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f`, - which reports `2.14.0 built with go1.27.0 from 114493f9`). A golangci-lint - built with go1.26 refuses to lint a module whose `go` directive is 1.27 or - later, so a new Go version needs a golangci-lint built with it. That digest is - the only pin, since no repo installs golangci-lint on the host. A repo moving - to a new version changes that digest and re-vendors `.golangci.yml` in the - same commit, because a new release can add linters that `default: all` - switches on until the canonical copy disables them. + which reports `2.14.0 built with go1.27.0 from 114493f9`). A module's `go` + directive must not name a newer Go minor version than the one golangci-lint + was built with, or golangci-lint refuses to lint it: this release lints + `go 1.27.1` but not `go 1.28`. That digest is the only pin, since no repo + installs golangci-lint on the host. A repo sets the lint phase digest to the + one named here and re-vendors `.golangci.yml` in the same commit, whichever of + the two prompted the change: the canonical copy can name linters that an older + golangci-lint rejects, and a newer golangci-lint can add linters that + `default: all` switches on until the canonical copy disables them. - **`script/bootstrap` installs a pinned tool by comparing versions, never by testing presence.** An `if ! command -v ; then install; fi` guard tests