check / check (push) Waiting to run
SWWAF_LOOKUP_SOURCE=file looks every client up in the file SWWAF_LOOKUP_DB_PATH names, without GeoJS. file without the path, the path with another source, or a file that cannot be read stops the start. The file is read whole into memory, so overwriting it in place cannot disturb a lookup, and read again 2 seconds after its last change; a replacement that cannot be read is logged, counted and sent as a file_error alert, and the old one stays in use. Metrics give when it was read and the failed reads. Tests write their databases through internal/lookup/lookuptest. Deviation: go.mod and go.sum written by hand; go runs only through make. Judgement call: the 2-second wait, as the rule files have. Model: opus-5-5
104 lines
4.2 KiB
YAML
104 lines
4.2 KiB
YAML
version: "2"
|
|
|
|
# Config schema uses the golangci-lint v2 layout (settings live under
|
|
# linters.settings, not top-level linters-settings) so that the
|
|
# thresholds below are actually applied by golangci-lint >= v2.
|
|
|
|
run:
|
|
timeout: 5m
|
|
modules-download-mode: readonly
|
|
|
|
linters:
|
|
default: all
|
|
enable:
|
|
# Successor to the deprecated gomodguard. Named explicitly, rather than
|
|
# left to `default: all`, because it carries the module policy below.
|
|
- gomodguard_v2
|
|
disable:
|
|
# Genuinely incompatible with project patterns
|
|
- exhaustruct # Requires all struct fields
|
|
- exhaustruct_v5 # Requires all struct fields (successor to exhaustruct)
|
|
- godot # Requires comments to end with periods
|
|
- wrapcheck # Too verbose for internal packages
|
|
- varnamelen # Short names like db, id are idiomatic Go
|
|
# Deprecated: the warning is attached to the old name, so it is
|
|
# silenced by disabling that name, not by enabling the successor.
|
|
- wsl # Deprecated, replaced by wsl_v5
|
|
- gomodguard # Deprecated, replaced by gomodguard_v2
|
|
settings:
|
|
lll:
|
|
line-length: 88
|
|
funlen:
|
|
lines: 80
|
|
statements: 50
|
|
cyclop:
|
|
max-complexity: 15
|
|
dupl:
|
|
threshold: 100
|
|
depguard:
|
|
# Test-support code must not be compiled into the shipped binary. A
|
|
# test-support package exists to hand a test privileges the program
|
|
# itself must never have, so a file that is not a test must not import
|
|
# one. Test files, and the files inside a package whose directory name
|
|
# ends in `test`, are where that code belongs, and are exempt.
|
|
#
|
|
# The deny list below is the one part of this file a repository is
|
|
# expected to extend, and the only part it may. depguard matches an
|
|
# import path against a list of prefixes, so it cannot be told "any path
|
|
# whose last segment ends in test"; a repository's own test-support
|
|
# packages have to be named here one at a time, by full import path,
|
|
# under a module path that differs from repository to repository. Add
|
|
# them; change nothing else.
|
|
rules:
|
|
test-support:
|
|
list-mode: lax
|
|
files:
|
|
- "$all"
|
|
- "!$test"
|
|
- "!**/*test/**"
|
|
deny:
|
|
- pkg: net/http/httptest
|
|
desc: >-
|
|
Test-support code belongs in test files and in packages whose
|
|
directory name ends in test, not in the shipped binary.
|
|
- pkg: sneak.berlin/go/smallwebwaf/internal/lookup/lookuptest
|
|
desc: >-
|
|
Test-support code belongs in test files and in packages whose
|
|
directory name ends in test, not in the shipped binary.
|
|
# Only decisions already recorded in the Go package defaults are
|
|
# listed here. Every entry matches the module path exactly.
|
|
gomodguard_v2:
|
|
blocked:
|
|
- module: github.com/rs/zerolog
|
|
recommendations:
|
|
- log/slog
|
|
reason: "Structured logging is stdlib log/slog."
|
|
# One entry per pre-fork module path, because the later releases
|
|
# are separate paths. A prefix match would be shorter but would
|
|
# also reach github.com/go-redis/redismock, the test double for
|
|
# the successor these entries recommend.
|
|
- module: github.com/go-redis/redis
|
|
recommendations:
|
|
- github.com/redis/go-redis/v9
|
|
reason: "Pre-fork module; use the maintained go-redis v9."
|
|
- module: github.com/go-redis/redis/v7
|
|
recommendations:
|
|
- github.com/redis/go-redis/v9
|
|
reason: "Pre-fork module; use the maintained go-redis v9."
|
|
- module: github.com/go-redis/redis/v8
|
|
recommendations:
|
|
- github.com/redis/go-redis/v9
|
|
reason: "Pre-fork module; use the maintained go-redis v9."
|
|
- module: github.com/sergi/go-diff
|
|
recommendations:
|
|
- github.com/aymanbagabas/go-udiff
|
|
reason: "No unified diff output; use go-udiff."
|
|
- module: github.com/hexops/gotextdiff
|
|
recommendations:
|
|
- github.com/aymanbagabas/go-udiff
|
|
reason: "Unmaintained fork; use go-udiff."
|
|
|
|
issues:
|
|
max-issues-per-linter: 0
|
|
max-same-issues: 0
|