Pin golangci-lint v2.14.0; disable exhaustruct_v5 (closes #65) #79

Open
clawbot wants to merge 2 commits from issue-65-golangci-lint-go127 into next
Collaborator

Closes #65.

The canonical golangci-lint, v2.12.2, is built with go1.26 and refuses a module whose go directive is 1.27 or later. prompts/REPO_POLICIES.md now pins v2.14.0, whose image reports 2.14.0 built with go1.27.0 from 114493f9, and states the rule golangci-lint applies: the go directive must not name a newer Go minor version than the one golangci-lint was built with.

From v2.13.0, exhaustruct is deprecated and replaced by exhaustruct_v5, which default: all switched on. It is now disabled beside exhaustruct; the old name stays in the list, or its deprecation warning returns. No other linter is added or newly deprecated between the two releases.

v2.12.2 rejects the new .golangci.yml because it does not know exhaustruct_v5, so a repo now sets the lint phase digest and re-vendors .golangci.yml in one commit, whichever prompted the change. Both repo checklists point to that rule.

New .golangci.yml sha256: 3ed73ffd561691e565c5c89a994dd8cfeb3faf06a1f87638ca9ab4dde4fecfa2

Disclosures:

  • To see the new finding, use a literal gosec does not also flag (an http.Server that sets ReadHeaderTimeout); golangci-lint reports one issue per line.
  • Judgement call: the release date is 2026-09-24, the release and build date; the upstream changelog says 2026-09-23.
  • The 2.12.2 in the script/bootstrap paragraph is a version-parsing example, not the pin.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/prompts/issues/65. The canonical golangci-lint, v2.12.2, is built with go1.26 and refuses a module whose `go` directive is 1.27 or later. `prompts/REPO_POLICIES.md` now pins v2.14.0, whose image reports `2.14.0 built with go1.27.0 from 114493f9`, and states the rule golangci-lint applies: the `go` directive must not name a newer Go minor version than the one golangci-lint was built with. From v2.13.0, `exhaustruct` is deprecated and replaced by `exhaustruct_v5`, which `default: all` switched on. It is now disabled beside `exhaustruct`; the old name stays in the list, or its deprecation warning returns. No other linter is added or newly deprecated between the two releases. v2.12.2 rejects the new `.golangci.yml` because it does not know `exhaustruct_v5`, so a repo now sets the lint phase digest and re-vendors `.golangci.yml` in one commit, whichever prompted the change. Both repo checklists point to that rule. New `.golangci.yml` sha256: `3ed73ffd561691e565c5c89a994dd8cfeb3faf06a1f87638ca9ab4dde4fecfa2` Disclosures: - To see the new finding, use a literal gosec does not also flag (an `http.Server` that sets `ReadHeaderTimeout`); golangci-lint reports one issue per line. - Judgement call: the release date is 2026-09-24, the release and build date; the upstream changelog says 2026-09-23. - The `2.12.2` in the `script/bootstrap` paragraph is a version-parsing example, not the pin. Model: opus-5-5
clawbot self-assigned this 2026-10-03 15:53:31 +02:00
clawbot added the needs-review label 2026-10-03 15:53:31 +02:00
Author
Collaborator

Two findings, both in the new sentences of the .golangci.yml paragraph of prompts/REPO_POLICIES.md:

  1. "A repo moving to a new version changes that digest and re-vendors .golangci.yml in the same commit" ties the two together in one direction only. The new canonical .golangci.yml does not load under v2.12.2, the previous pin: that release does not know exhaustruct_v5 and rejects the whole file. A repo still on the old digest that re-vendors the file, as the .golangci.yml items in prompts/EXISTING_REPO_CHECKLIST.md and prompts/NEW_REPO_CHECKLIST.md tell it to without naming the digest, gets a lint phase that fails before checking any code. "a new version" also reads as the Go version named in the sentence before. Acceptable: say plainly that the lint phase digest and .golangci.yml always change together in one commit, whichever of the two prompted the change, because the canonical file can name linters an older release rejects; and have those two checklist items point to that rule.

  2. "so a new Go version needs a golangci-lint built with it" overstates the rule. golangci-lint compares only the Go minor version: v2.14.0, built with go1.27.0, lints a module whose go directive is 1.27.1, and a golangci-lint built with a later Go would also do. Acceptable: say that the go directive must not name a newer Go minor version than the one golangci-lint was built with.

Model: opus-5-5

Two findings, both in the new sentences of the `.golangci.yml` paragraph of `prompts/REPO_POLICIES.md`: 1. "A repo moving to a new version changes that digest and re-vendors `.golangci.yml` in the same commit" ties the two together in one direction only. The new canonical `.golangci.yml` does not load under v2.12.2, the previous pin: that release does not know `exhaustruct_v5` and rejects the whole file. A repo still on the old digest that re-vendors the file, as the `.golangci.yml` items in `prompts/EXISTING_REPO_CHECKLIST.md` and `prompts/NEW_REPO_CHECKLIST.md` tell it to without naming the digest, gets a lint phase that fails before checking any code. "a new version" also reads as the Go version named in the sentence before. Acceptable: say plainly that the lint phase digest and `.golangci.yml` always change together in one commit, whichever of the two prompted the change, because the canonical file can name linters an older release rejects; and have those two checklist items point to that rule. 2. "so a new Go version needs a golangci-lint built with it" overstates the rule. golangci-lint compares only the Go minor version: v2.14.0, built with go1.27.0, lints a module whose `go` directive is 1.27.1, and a golangci-lint built with a later Go would also do. Acceptable: say that the `go` directive must not name a newer Go minor version than the one golangci-lint was built with. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-03 16:43:32 +02:00
Author
Collaborator

Reworked: prompts/REPO_POLICIES.md now says a repo sets the lint phase digest and re-vendors .golangci.yml in one commit, whichever of the two prompted the change, with both repo checklists pointing to that rule; the Go version sentence now says the go directive must not name a newer Go minor version than the one golangci-lint was built with.

Model: opus-5-5

Reworked: `prompts/REPO_POLICIES.md` now says a repo sets the lint phase digest and re-vendors `.golangci.yml` in one commit, whichever of the two prompted the change, with both repo checklists pointing to that rule; the Go version sentence now says the `go` directive must not name a newer Go minor version than the one golangci-lint was built with. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-03 17:00:01 +02:00
clawbot changed title from Pin golangci-lint v2.14.0; disable exhaustruct_v5 to Pin golangci-lint v2.14.0; disable exhaustruct_v5 (closes #65) 2026-10-03 17:11:00 +02:00
Author
Collaborator

Two findings:

  1. Commit subject: neither the rework commit d6fe2c3 ("Set the lint digest and .golangci.yml together; state the Go version rule") nor the PR title ends with (closes #65), so a squash merge that takes either as its subject lands without the suffix the landing commit must carry for #65. Acceptable: every commit subject on the branch, and the PR title, end with (closes #65).

  2. PR body: about 280 words, over the 250-word limit. Acceptable: 250 words or fewer, for example by cutting the paragraph on reproducing the finding with a literal that gosec does not flag down to one disclosure line.

Judgement call: the issue's example &http.Server{Addr: a, Handler: h} is still reported, by gosec rather than exhaustruct_v5; I read that part of the definition of done as concerning exhaustruct_v5 only.

Model: opus-5-5

Two findings: 1. Commit subject: neither the rework commit `d6fe2c3` ("Set the lint digest and .golangci.yml together; state the Go version rule") nor the PR title ends with ` (closes #65)`, so a squash merge that takes either as its subject lands without the suffix the landing commit must carry for https://git.eeqj.de/sneak/prompts/issues/65. Acceptable: every commit subject on the branch, and the PR title, end with ` (closes #65)`. 2. PR body: about 280 words, over the 250-word limit. Acceptable: 250 words or fewer, for example by cutting the paragraph on reproducing the finding with a literal that gosec does not flag down to one disclosure line. Judgement call: the issue's example `&http.Server{Addr: a, Handler: h}` is still reported, by gosec rather than `exhaustruct_v5`; I read that part of the definition of done as concerning `exhaustruct_v5` only. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-03 17:19:12 +02:00
Author
Collaborator

Rework: the PR title now ends (closes #65), and the PR lands as one squash commit whose subject is that title, so the branch's own commit subjects are left as they are. The PR body is cut to under 250 words, with the note on reproducing the finding reduced to one disclosure line. No file changed.

Model: opus-5-5

Rework: the PR title now ends ` (closes #65)`, and the PR lands as one squash commit whose subject is that title, so the branch's own commit subjects are left as they are. The PR body is cut to under 250 words, with the note on reproducing the finding reduced to one disclosure line. No file changed. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-03 17:20:04 +02:00
clawbot added needs-rebase and removed needs-review labels 2026-10-03 17:41:10 +02:00
clawbot added 2 commits 2026-10-03 17:55:34 +02:00
v2.12.2 is built with go1.26 and refuses to lint a module whose go
directive is 1.27 or later. v2.14.0 is built with go1.27. Releases
from v2.13.0 deprecate exhaustruct in favour of exhaustruct_v5, which
default: all switches on and which reports every partial struct
literal, so the canonical config disables it beside exhaustruct for
the same reason. REPO_POLICIES now names the new image digest and says
that a repo moving to a new version re-vendors .golangci.yml with it.

Model: opus-5-5
The canonical .golangci.yml now names exhaustruct_v5, which v2.12.2
rejects, so a repo that re-vendors the file on the old digest gets a
lint phase that fails before checking any code. REPO_POLICIES now says
a repo sets the lint phase digest and re-vendors .golangci.yml in one
commit, whichever prompted the change, and both repo checklists point
to that rule. It also replaces "a new Go version needs a golangci-lint
built with it" with the rule golangci-lint applies: the go directive
must not name a newer Go minor version than the one it was built with.

Model: opus-5-5
clawbot force-pushed issue-65-golangci-lint-go127 from d6fe2c32f2 to bab59b474a 2026-10-03 17:55:34 +02:00 Compare
Author
Collaborator

Rebased onto next: only TODO.md conflicted, because both this branch and #80 added an entry at the top of Completed Steps, and I kept both entries, with this branch's above the .gitignore one.

Model: opus-5-5

Rebased onto `next`: only `TODO.md` conflicted, because both this branch and https://git.eeqj.de/sneak/prompts/pulls/80 added an entry at the top of Completed Steps, and I kept both entries, with this branch's above the `.gitignore` one. Model: opus-5-5
clawbot added needs-review and removed needs-rebase labels 2026-10-03 17:55:40 +02:00
Author
Collaborator

State for whoever picks this up: branch issue-65-golangci-lint-go127, last pushed commit bab59b4, rebased onto next at 7ea5cdc, label needs-review. A reviewer started 15:56 UTC on the worker account claude2 (session "pr-reviewer: prompts #79") and posts its verdict here. Left: that verdict; on a pass, squash-merge into next with this PR's title and add the change to the description of #68. If no verdict appears, a fresh reviewer checks that only the TODO.md conflict changed since d6fe2c3, whose substance earlier reviews here found sound.

Model: opus-5-5

State for whoever picks this up: branch `issue-65-golangci-lint-go127`, last pushed commit `bab59b4`, rebased onto `next` at `7ea5cdc`, label `needs-review`. A reviewer started 15:56 UTC on the worker account `claude2` (session "pr-reviewer: prompts #79") and posts its verdict here. Left: that verdict; on a pass, squash-merge into `next` with this PR's title and add the change to the description of https://git.eeqj.de/sneak/prompts/pulls/68. If no verdict appears, a fresh reviewer checks that only the `TODO.md` conflict changed since `d6fe2c3`, whose substance earlier reviews here found sound. Model: opus-5-5
All checks were successful
check / check (push) Successful in 29s
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin issue-65-golangci-lint-go127:issue-65-golangci-lint-go127
git checkout issue-65-golangci-lint-go127
Sign in to join this conversation.