check / check (push) Successful in 1m29s
Milestone 1, the repo's first code. smallwebwaf passes each request to the app and the answer back unchanged, streaming bodies and WebSocket upgrades, within four timeouts (client and app, request and response) and two size limits, and writes one JSON line per request to stdout. Every setting has an SWWAF_ name and a default, and an invalid value stops the start. The repo gets the standard layout: script/ entrypoints, make targets that call them, a Dockerfile that runs the checks, and the Gitea workflow. Disclosure: SPEC.md changed. Go's server reads the request line and headers before smallwebwaf sees the request, so slow headers are closed without an answer, and neither slow nor oversized headers get a log line. Disclosure: standard library only. Model: opus-5-5
99 lines
3.9 KiB
YAML
99 lines
3.9 KiB
YAML
version: "2"
|
|
|
|
# Config schema uses the golangci-lint v2 layout (settings live under
|
|
# linters.settings, not top-level linters-settings) so that the
|
|
# thresholds below are actually applied by golangci-lint >= v2.
|
|
|
|
run:
|
|
timeout: 5m
|
|
modules-download-mode: readonly
|
|
|
|
linters:
|
|
default: all
|
|
enable:
|
|
# Successor to the deprecated gomodguard. Named explicitly, rather than
|
|
# left to `default: all`, because it carries the module policy below.
|
|
- gomodguard_v2
|
|
disable:
|
|
# Genuinely incompatible with project patterns
|
|
- exhaustruct # Requires all struct fields
|
|
- godot # Requires comments to end with periods
|
|
- wrapcheck # Too verbose for internal packages
|
|
- varnamelen # Short names like db, id are idiomatic Go
|
|
# Deprecated: the warning is attached to the old name, so it is
|
|
# silenced by disabling that name, not by enabling the successor.
|
|
- wsl # Deprecated, replaced by wsl_v5
|
|
- gomodguard # Deprecated, replaced by gomodguard_v2
|
|
settings:
|
|
lll:
|
|
line-length: 88
|
|
funlen:
|
|
lines: 80
|
|
statements: 50
|
|
cyclop:
|
|
max-complexity: 15
|
|
dupl:
|
|
threshold: 100
|
|
depguard:
|
|
# Test-support code must not be compiled into the shipped binary. A
|
|
# test-support package exists to hand a test privileges the program
|
|
# itself must never have, so a file that is not a test must not import
|
|
# one. Test files, and the files inside a package whose directory name
|
|
# ends in `test`, are where that code belongs, and are exempt.
|
|
#
|
|
# The deny list below is the one part of this file a repository is
|
|
# expected to extend, and the only part it may. depguard matches an
|
|
# import path against a list of prefixes, so it cannot be told "any path
|
|
# whose last segment ends in test"; a repository's own test-support
|
|
# packages have to be named here one at a time, by full import path,
|
|
# under a module path that differs from repository to repository. Add
|
|
# them; change nothing else.
|
|
rules:
|
|
test-support:
|
|
list-mode: lax
|
|
files:
|
|
- "$all"
|
|
- "!$test"
|
|
- "!**/*test/**"
|
|
deny:
|
|
- pkg: net/http/httptest
|
|
desc: >-
|
|
Test-support code belongs in test files and in packages whose
|
|
directory name ends in test, not in the shipped binary.
|
|
# Only decisions already recorded in the Go package defaults are
|
|
# listed here. Every entry matches the module path exactly.
|
|
gomodguard_v2:
|
|
blocked:
|
|
- module: github.com/rs/zerolog
|
|
recommendations:
|
|
- log/slog
|
|
reason: "Structured logging is stdlib log/slog."
|
|
# One entry per pre-fork module path, because the later releases
|
|
# are separate paths. A prefix match would be shorter but would
|
|
# also reach github.com/go-redis/redismock, the test double for
|
|
# the successor these entries recommend.
|
|
- module: github.com/go-redis/redis
|
|
recommendations:
|
|
- github.com/redis/go-redis/v9
|
|
reason: "Pre-fork module; use the maintained go-redis v9."
|
|
- module: github.com/go-redis/redis/v7
|
|
recommendations:
|
|
- github.com/redis/go-redis/v9
|
|
reason: "Pre-fork module; use the maintained go-redis v9."
|
|
- module: github.com/go-redis/redis/v8
|
|
recommendations:
|
|
- github.com/redis/go-redis/v9
|
|
reason: "Pre-fork module; use the maintained go-redis v9."
|
|
- module: github.com/sergi/go-diff
|
|
recommendations:
|
|
- github.com/aymanbagabas/go-udiff
|
|
reason: "No unified diff output; use go-udiff."
|
|
- module: github.com/hexops/gotextdiff
|
|
recommendations:
|
|
- github.com/aymanbagabas/go-udiff
|
|
reason: "Unmaintained fork; use go-udiff."
|
|
|
|
issues:
|
|
max-issues-per-linter: 0
|
|
max-same-issues: 0
|