Author SHA1 Message Date
sneak a614cd6ffb policy: scope the .golangci.yml rule to vendored copies
check / check (push) Successful in 9s
Stated unqualified, the rule forbade an agent from modifying
.golangci.yml anywhere, including the canonical copy in this repo --
the only place it can be fixed. Compliance and remediation were
mutually exclusive.

Scope the prohibition to the vendored copy in a consuming repo, which
is the property the rule exists to protect, and name the one legitimate
path for change: a PR against canonical here, merged only by the user.
2026-08-19 14:25:30 +00:00
2 changed files with 8 additions and 17 deletions
+4 -9
View File
@@ -124,15 +124,10 @@ last_modified: 2026-03-18
1. Keep the `main()` function as small as possible. 1. Keep the `main()` function as small as possible.
1. Keep the `main` package as small as possible. Each `cmd/<name>/` directory 1. Keep the `main` package as small as possible. Move as much code as is
contains a single `main.go` whose body is one call into library code (for feasible to a library package, even if it's an internal one. `main` is just
example `os.Exit(cli.Main())` calling `internal/cli`). All CLI logic — flag an entrypoint to your code, not a place for implementations. Exception:
parsing, subcommand dispatch, argument handling, output formatting — lives single-file scripts.
in `internal/` or `pkg/`, not in `cmd/`. `main` is just an entrypoint to
your code, not a place for implementations. Exception: single-file scripts.
1. No project logic outside `internal/` or `pkg/`. Anything in `cmd/` is a thin
entrypoint only.
1. HTTP HandleFuncs should be returned from methods or functions that need to 1. HTTP HandleFuncs should be returned from methods or functions that need to
handle HTTP requests. Don't use methods or your top level functions as handle HTTP requests. Don't use methods or your top level functions as
+4 -8
View File
@@ -1,6 +1,6 @@
--- ---
title: Repository Policies title: Repository Policies
last_modified: 2026-09-05 last_modified: 2026-08-19
--- ---
This document covers repository structure, tooling, and workflow standards. Code This document covers repository structure, tooling, and workflow standards. Code
@@ -270,10 +270,8 @@ style conventions are in separate documents:
configuration changes are made to the canonical copy in the `prompts` repo and configuration changes are made to the canonical copy in the `prompts` repo and
reach consuming repos by re-vendoring; an agent may open a PR against reach consuming repos by re-vendoring; an agent may open a PR against
canonical, which only the user merges. The canonical golangci-lint version is canonical, which only the user merges. The canonical golangci-lint version is
v2.13.2 (released 2026-08-27, built with Go 1.27; a linter built with an older v2.12.2 (released 2026-05-06), installed commit-pinned via
Go cannot check a module whose `go` directive is newer), installed `go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5`.
commit-pinned via
`go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@27774aaf853a4fd21f1dd5e69439459dc1b26e68`.
- When pinning images or packages by hash, add a comment above the reference - When pinning images or packages by hash, add a comment above the reference
with the version and date (YYYY-MM-DD). with the version and date (YYYY-MM-DD).
@@ -392,9 +390,7 @@ style conventions are in separate documents:
language-specific config). Everything else goes in a subdirectory. Canonical language-specific config). Everything else goes in a subdirectory. Canonical
subdirectory names: subdirectory names:
- `bin/` — executable scripts and tools - `bin/` — executable scripts and tools
- `cmd/` — Go command entrypoints; thin only: one `main.go` per binary whose - `cmd/` — Go command entrypoints
body is a single call into `internal/` or `pkg/`, no project logic in
`cmd/`
- `configs/` — configuration templates and examples - `configs/` — configuration templates and examples
- `deploy/` — deployment manifests (k8s, compose, terraform) - `deploy/` — deployment manifests (k8s, compose, terraform)
- `docs/` — documentation and markdown (README.md stays in root) - `docs/` — documentation and markdown (README.md stays in root)