2 Commits

Author SHA1 Message Date
fd5d305ba7 Merge branch 'main' into policy/scope-golangci-rule-to-vendored-copies
All checks were successful
check / check (push) Successful in 24s
2026-08-30 06:26:09 +02:00
a614cd6ffb policy: scope the .golangci.yml rule to vendored copies
All checks were successful
check / check (push) Successful in 9s
Stated unqualified, the rule forbade an agent from modifying
.golangci.yml anywhere, including the canonical copy in this repo --
the only place it can be fixed. Compliance and remediation were
mutually exclusive.

Scope the prohibition to the vendored copy in a consuming repo, which
is the property the rule exists to protect, and name the one legitimate
path for change: a PR against canonical here, merged only by the user.
2026-08-19 14:25:30 +00:00
2 changed files with 2 additions and 31 deletions

View File

@@ -13,6 +13,7 @@ linters:
disable:
# Genuinely incompatible with project patterns
- exhaustruct # Requires all struct fields
- depguard # Dependency allow/block lists
- godot # Requires comments to end with periods
- wsl # Deprecated, replaced by wsl_v5
- wrapcheck # Too verbose for internal packages
@@ -27,32 +28,6 @@ linters:
max-complexity: 15
dupl:
threshold: 100
depguard:
# Test-support code must not be compiled into the shipped binary. A
# test-support package exists to hand a test privileges the program
# itself must never have, so a file that is not a test must not import
# one. Test files, and the files inside a package whose directory name
# ends in `test`, are where that code belongs, and are exempt.
#
# The deny list below is the one part of this file a repository is
# expected to extend, and the only part it may. depguard matches an
# import path against a list of prefixes, so it cannot be told "any path
# whose last segment ends in test"; a repository's own test-support
# packages have to be named here one at a time, by full import path,
# under a module path that differs from repository to repository. Add
# them; change nothing else.
rules:
test-support:
list-mode: lax
files:
- "$all"
- "!$test"
- "!**/*test/**"
deny:
- pkg: net/http/httptest
desc: >-
Test-support code belongs in test files and in packages whose
directory name ends in test, not in the shipped binary.
issues:
max-issues-per-linter: 0

View File

@@ -269,11 +269,7 @@ style conventions are in separate documents:
byte-identical, so that no repo can quietly loosen its own linting. Linter
configuration changes are made to the canonical copy in the `prompts` repo and
reach consuming repos by re-vendoring; an agent may open a PR against
canonical, which only the user merges. One list is exempt from byte-identity,
because it cannot be written once for every repo: the `deny` list of the
`test-support` depguard rule, where a repo names its own test-support packages
by full import path. A repo adds entries there and changes nothing else, and a
re-vendor carries its entries forward. The canonical golangci-lint version is
canonical, which only the user merges. The canonical golangci-lint version is
v2.12.2 (released 2026-05-06), installed commit-pinned via
`go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5`.