All checks were successful
check / check (push) Successful in 27s
Option-2 answer to sneak's ruling of 2026-08-19 on sneak/homoicon#4: migrate to the successor, with settings. Closes #25. ## The change `golangci-lint` v2.12.0 deprecated `gomodguard`, and this config sets `linters.default: all`, so it is enabled everywhere and warns on every run. - `gomodguard` joins `wsl` in `linters.disable` under a shared "deprecated" comment. The warning is attached to the old name, so disabling it is what silences it. - `gomodguard_v2` is named in `linters.enable`, a no-op under `default: all` that gives the settings block a visible owner. - Blocked, each restating a decision already recorded in the Go package defaults: `rs/zerolog` → `log/slog`; the pre-fork `go-redis/redis` → `redis/go-redis/v9`; `sergi/go-diff` and `hexops/gotextdiff` → `go-udiff`. Every entry matches the module path exactly, so the pre-fork go-redis takes three: `go-redis/redis`, `/v7`, `/v8`. A prefix would also cover `go-redis/redismock`, the test double for the successor recommended here. Deliberately absent: recorded rejections that vendoring repos still require (`mattn/go-sqlite3`, `gorm.io/gorm`, `pmezard/go-difflib`), plus `urfave/cli` and unversioned `go-chi/chi`. Blocking those would redden repos mid-migration on their next re-vendor. ## After merge The file's sha256 moves from `d10f47ef5e0d8620efd62275b016a7de8fd5abedf333922eec86fe4abc06176e` to `a79b63a254602a5318db5d0e9a06bc71b84bf0c1d896305229d8bfed1d1b1776`, so every vendoring repo mismatches. #60 is the propagation brief; it and the record on #25 carry this value. ## Disclosures - Judgement call: `wsl` moved two lines down to share the "deprecated" comment. No behaviour change, but it widens the diff. - The `go.mod` survey and the settings-block probe are on #25. - Unverified: the linter was not run against each vendoring repo; the per-repo claim rests on reading their `go.mod` files. - `make check` exit 0. Model: opus-5 Co-authored-by: Jeffrey Paul <sneak@noreply.example.org> Reviewed-on: #55 Co-authored-by: clawbot <clawbot@noreply.example.org> Co-committed-by: clawbot <clawbot@noreply.example.org>
5.1 KiB
5.1 KiB
Workflow
- branch (from
main) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - merge to
mainif the branch is not protected, otherwise open a PR - push
Status
pre-1.0
Next Step
Finish the two draft prompt documents in the working tree and commit them:
prompts/FIXUP_CLEAN.md (currently a near-empty stub) and prompts/FIXUP_REPORT.md
(a rough draft). Write the missing content, run make fmt so they pass
fmt-check, and commit.
Completed Steps
- 2026-09-08: Moved linting and testing into Docker as phases of the main
Dockerfile, per the owner ruling on issue 40.script/lintandscript/testbuild one phase each by name with--no-cache— the same answer issue 26 got, so no separate cache-busting mechanism survives — and the final stage copies a harmless file from both, so the image cannot be built unless they pass. This also closes issue 30: a container has its own result cache and its own lock, so a lint verdict can no longer belong to another checkout. No separate lint Dockerfile, and nogolangci-lint config verifystep.script/checkruns the gates and nothing else, andscript/cibuildbootstraps first, since it is all CI runs andscript/fmt-checkis native. - 2026-09-08: Kept in-repo agent scratch out of the Docker build context and out
of version control:
.claude/is one full checkout of the repo per in-flight agent, and underCOPY . .all of it was reaching the image. Also closed the consequence of excluding.git—git describeyields an empty version inside a build stage without failing, soscript/dockerandscript/cibuildnow compute the version on the host and pass--build-arg VERSION. - 2026-09-08: Closed the secret exposure in the canonical
.dockerignore: a local.env,*.pemor*.keywas reaching the build context underCOPY . ., invisible to every git-based check. The patterns are now written to.dockerignore's own semantics —**/-prefixed so they hold at every depth, case-folded with character ranges — andREPO_POLICIES.mdrequires verifying by enumerating the image rather than by reading the file. - 2026-09-08: Made a pinned tool in
script/bootstrapactually reach the host.REPO_POLICIES.mdnow requires comparing the installed version against the pin rather than testingPATHpresence, and re-resolving the binary throughPATHafter installing, so a version bump cannot be a silent no-op and a shadowed install cannot report success. - 2026-09-08: Closed the false green in the canonical CI gate:
script/cibuildandscript/dockernow build with--no-cache, so the Dockerfile's check layers cannot be served from cache on an unchanged tree, and the text claiming a baredocker build .proves the checks ran is corrected inREPO_POLICIES.md, both checklists and the Go styleguide. - 2026-09-03: Added
-count=1to bothgo testinvocations in the canonical Gomake testexample inREPO_POLICIES.md, so the target cannot report a cached pass it did not earn, and documented that Go's test-result cache is a second, independent cache stacked below the Docker layer cache. - 2026-08-31: Migrated the canonical
.golangci.ymlfrom the deprecatedgomodguardtogomodguard_v2: the old linter is disabled by name (which is what silences the deprecation warning), the successor is named explicitly inlinters.enable, and it carries ablockedmodule list drawn only from decisions already recorded in the Go package defaults. - 2026-08-07: Set the canonical
.golangci.ymlto the org-standard v2-schema config already deployed byte-identical across the org's Go repos (settings underlinters.settingsso thresholds like lll/funlen/cyclop/dupl actually apply under golangci-lint v2). Recorded the canonical golangci-lint version (v2.12.2, commit-pinned) in REPO_POLICIES.md. - 2026-03-20: Strengthened constructor naming and Params struct rules in the Go styleguide.
- 2026-03-18: Documented fail-fast Dockerfile lint stage and conditional -v test rerun patterns in REPO_POLICIES.md.
- 2026-03-11: Added HTTP service hardening policy for 1.0 releases.
- 2026-03-10: Added policy: no build artifacts in repos.
- 2026-03-04: Added LLM prose tells reference and copyediting checklist, then several self-applied revision passes.
- 2026-02-28: Expanded the pre-1.0 schema migration rule; added clawpub reference.
- 2026-02-23: Added Go style rules (no type-only packages, Stringer for string-based types); template repos section in README.
- 2026-02-22: Initial policy corpus: REPO_POLICIES.md, code styleguides (general, Go, JS, Python), repo checklists, CI policy, hash pinning, Go HTTP server conventions, repo scaffolding.
Future Steps
- Finish, format, and commit FIXUP_CLEAN.md and FIXUP_REPORT.md (the Next Step).
- Commit this TODO.md at the repo root; it is the last missing policy file.
- Decide the fate of untracked resume.sh: commit it or delete it.
- Add more prompt templates for common development tasks (from README TODO).