From f5c4bb6e2cde73937f1a7a69249d49174cb2e65e Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Tue, 6 Oct 2026 05:15:41 +0200 Subject: [PATCH] Disable canonicalheader in the canonical .golangci.yml (closes #105) In golangci-lint v2.14.0, `canonicalheader` misses findings at random in a package that also calls `ResponseWriter.Header()`: on the same tree, repeated runs sometimes reported a non-canonical header key and sometimes reported nothing. So one commit could fail lint on one run and pass on the next, in every Go repository that vendors this file. Reproduced with the pinned image and the canonical config. The canonical `.golangci.yml` now disables it, with a comment saying it comes back once a pinned golangci-lint release fixes it. New `.golangci.yml` sha256: `e49052a1418127b54b20cea530dfd3cc6ddfc126a9fd27fd570ccca1a3f18bc7`. Model: opus-5-5 --- .golangci.yml | 2 ++ TODO.md | 5 +++++ 2 files changed, 7 insertions(+) diff --git a/.golangci.yml b/.golangci.yml index 1b73eb9..32db9fe 100644 --- a/.golangci.yml +++ b/.golangci.yml @@ -25,6 +25,8 @@ linters: # silenced by disabling that name, not by enabling the successor. - wsl # Deprecated, replaced by wsl_v5 - gomodguard # Deprecated, replaced by gomodguard_v2 + # Misses findings at random in v2.14.0; back once a pinned release fixes it + - canonicalheader settings: lll: line-length: 88 diff --git a/TODO.md b/TODO.md index 3194bce..80d8ca8 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,11 @@ fmt-check, and commit. # Completed Steps +- 2026-10-06: The canonical `.golangci.yml` now disables `canonicalheader` + (issue 105). In golangci-lint v2.14.0 it misses findings at random in a + package that also calls `ResponseWriter.Header()`, so the same tree can fail + lint on one run and pass on the next. It comes back once a pinned + golangci-lint release fixes it. - 2026-10-06: The canonical `.gitignore` and `.editorconfig` now each end with a comment saying the repository's own entries go below it and a re-vendor keeps them (issue 103, which took in issue 104), as `.dockerignore`'s header already