All checks were successful
check / check (push) Successful in 27s
Option-2 answer to sneak's ruling of 2026-08-19 on sneak/homoicon#4: migrate to the successor, with settings. Closes #25. ## The change `golangci-lint` v2.12.0 deprecated `gomodguard`, and this config sets `linters.default: all`, so it is enabled everywhere and warns on every run. - `gomodguard` joins `wsl` in `linters.disable` under a shared "deprecated" comment. The warning is attached to the old name, so disabling it is what silences it. - `gomodguard_v2` is named in `linters.enable`, a no-op under `default: all` that gives the settings block a visible owner. - Blocked, each restating a decision already recorded in the Go package defaults: `rs/zerolog` → `log/slog`; the pre-fork `go-redis/redis` → `redis/go-redis/v9`; `sergi/go-diff` and `hexops/gotextdiff` → `go-udiff`. Every entry matches the module path exactly, so the pre-fork go-redis takes three: `go-redis/redis`, `/v7`, `/v8`. A prefix would also cover `go-redis/redismock`, the test double for the successor recommended here. Deliberately absent: recorded rejections that vendoring repos still require (`mattn/go-sqlite3`, `gorm.io/gorm`, `pmezard/go-difflib`), plus `urfave/cli` and unversioned `go-chi/chi`. Blocking those would redden repos mid-migration on their next re-vendor. ## After merge The file's sha256 moves from `d10f47ef5e0d8620efd62275b016a7de8fd5abedf333922eec86fe4abc06176e` to `a79b63a254602a5318db5d0e9a06bc71b84bf0c1d896305229d8bfed1d1b1776`, so every vendoring repo mismatches. #60 is the propagation brief; it and the record on #25 carry this value. ## Disclosures - Judgement call: `wsl` moved two lines down to share the "deprecated" comment. No behaviour change, but it widens the diff. - The `go.mod` survey and the settings-block probe are on #25. - Unverified: the linter was not run against each vendoring repo; the per-repo claim rests on reading their `go.mod` files. - `make check` exit 0. Model: opus-5 Co-authored-by: Jeffrey Paul <sneak@noreply.example.org> Reviewed-on: #55 Co-authored-by: clawbot <clawbot@noreply.example.org> Co-committed-by: clawbot <clawbot@noreply.example.org>
92 lines
5.1 KiB
Markdown
92 lines
5.1 KiB
Markdown
# Workflow
|
|
|
|
- branch (from `main`)
|
|
- do the work in Next Step
|
|
- move Next Step to the top of Completed Steps
|
|
- move the top item of Future Steps into Next Step
|
|
- commit (`TODO.md` changes in the same commit as the work)
|
|
- merge to `main` if the branch is not protected, otherwise open a PR
|
|
- push
|
|
|
|
# Status
|
|
|
|
pre-1.0
|
|
|
|
# Next Step
|
|
|
|
Finish the two draft prompt documents in the working tree and commit them:
|
|
prompts/FIXUP_CLEAN.md (currently a near-empty stub) and prompts/FIXUP_REPORT.md
|
|
(a rough draft). Write the missing content, run `make fmt` so they pass
|
|
fmt-check, and commit.
|
|
|
|
# Completed Steps
|
|
|
|
- 2026-09-08: Moved linting and testing into Docker as phases of the main
|
|
`Dockerfile`, per the owner ruling on issue 40. `script/lint` and
|
|
`script/test` build one phase each by name with `--no-cache` — the same answer
|
|
issue 26 got, so no separate cache-busting mechanism survives — and the final
|
|
stage copies a harmless file from both, so the image cannot be built unless
|
|
they pass. This also closes issue 30: a container has its own result cache and
|
|
its own lock, so a lint verdict can no longer belong to another checkout. No
|
|
separate lint Dockerfile, and no `golangci-lint config verify` step.
|
|
`script/check` runs the gates and nothing else, and `script/cibuild`
|
|
bootstraps first, since it is all CI runs and `script/fmt-check` is native.
|
|
- 2026-09-08: Kept in-repo agent scratch out of the Docker build context and out
|
|
of version control: `.claude/` is one full checkout of the repo per in-flight
|
|
agent, and under `COPY . .` all of it was reaching the image. Also closed the
|
|
consequence of excluding `.git` — `git describe` yields an empty version
|
|
inside a build stage without failing, so `script/docker` and `script/cibuild`
|
|
now compute the version on the host and pass `--build-arg VERSION`.
|
|
- 2026-09-08: Closed the secret exposure in the canonical `.dockerignore`: a
|
|
local `.env`, `*.pem` or `*.key` was reaching the build context under
|
|
`COPY . .`, invisible to every git-based check. The patterns are now written
|
|
to `.dockerignore`'s own semantics — `**/`-prefixed so they hold at every
|
|
depth, case-folded with character ranges — and `REPO_POLICIES.md` requires
|
|
verifying by enumerating the image rather than by reading the file.
|
|
- 2026-09-08: Made a pinned tool in `script/bootstrap` actually reach the host.
|
|
`REPO_POLICIES.md` now requires comparing the installed version against the
|
|
pin rather than testing `PATH` presence, and re-resolving the binary through
|
|
`PATH` after installing, so a version bump cannot be a silent no-op and a
|
|
shadowed install cannot report success.
|
|
- 2026-09-08: Closed the false green in the canonical CI gate: `script/cibuild`
|
|
and `script/docker` now build with `--no-cache`, so the Dockerfile's check
|
|
layers cannot be served from cache on an unchanged tree, and the text claiming
|
|
a bare `docker build .` proves the checks ran is corrected in
|
|
`REPO_POLICIES.md`, both checklists and the Go styleguide.
|
|
- 2026-09-03: Added `-count=1` to both `go test` invocations in the canonical Go
|
|
`make test` example in `REPO_POLICIES.md`, so the target cannot report a
|
|
cached pass it did not earn, and documented that Go's test-result cache is a
|
|
second, independent cache stacked below the Docker layer cache.
|
|
- 2026-08-31: Migrated the canonical `.golangci.yml` from the deprecated
|
|
`gomodguard` to `gomodguard_v2`: the old linter is disabled by name (which is
|
|
what silences the deprecation warning), the successor is named explicitly in
|
|
`linters.enable`, and it carries a `blocked` module list drawn only from
|
|
decisions already recorded in the Go package defaults.
|
|
- 2026-08-07: Set the canonical `.golangci.yml` to the org-standard v2-schema
|
|
config already deployed byte-identical across the org's Go repos (settings
|
|
under `linters.settings` so thresholds like lll/funlen/cyclop/dupl actually
|
|
apply under golangci-lint v2). Recorded the canonical golangci-lint version
|
|
(v2.12.2, commit-pinned) in REPO_POLICIES.md.
|
|
- 2026-03-20: Strengthened constructor naming and Params struct rules in the Go
|
|
styleguide.
|
|
- 2026-03-18: Documented fail-fast Dockerfile lint stage and conditional -v test
|
|
rerun patterns in REPO_POLICIES.md.
|
|
- 2026-03-11: Added HTTP service hardening policy for 1.0 releases.
|
|
- 2026-03-10: Added policy: no build artifacts in repos.
|
|
- 2026-03-04: Added LLM prose tells reference and copyediting checklist, then
|
|
several self-applied revision passes.
|
|
- 2026-02-28: Expanded the pre-1.0 schema migration rule; added clawpub
|
|
reference.
|
|
- 2026-02-23: Added Go style rules (no type-only packages, Stringer for
|
|
string-based types); template repos section in README.
|
|
- 2026-02-22: Initial policy corpus: REPO_POLICIES.md, code styleguides
|
|
(general, Go, JS, Python), repo checklists, CI policy, hash pinning, Go HTTP
|
|
server conventions, repo scaffolding.
|
|
|
|
# Future Steps
|
|
|
|
- Finish, format, and commit FIXUP_CLEAN.md and FIXUP_REPORT.md (the Next Step).
|
|
- Commit this TODO.md at the repo root; it is the last missing policy file.
|
|
- Decide the fate of untracked resume.sh: commit it or delete it.
|
|
- Add more prompt templates for common development tasks (from README TODO).
|