Update golangci-lint to v2.12.2 with canonical config (#187)
All checks were successful
Check / check (push) Successful in 4s
All checks were successful
Check / check (push) Successful in 4s
Bumps golangci-lint from v2.10.1 to v2.12.2 everywhere it is pinned and installs the canonical `.golangci.yml`, then fixes every finding the new linter surfaces so `make check` is green. ## Version pins - `Dockerfile` lint stage: `golangci/golangci-lint:v2.12.2` (Debian-based), tag plus digest pin - `script/bootstrap`: `GOLANGCI_LINT_VERSION=2.12.2` with updated `linux-amd64`/`linux-arm64` release-archive sha256 pins ## Config `.golangci.yml` replaced with the canonical config. Material change: the old file declared `version: "2"` but kept settings under the legacy top-level `linters-settings` key, which golangci-lint v2 ignores — so the intended thresholds (`lll` 88, `funlen` 80/50, `cyclop` 15, `dupl` 100) were not being applied. The canonical file moves them under `linters.settings` and drops `issues.exclude-use-default`. ## Lint fixes (216 findings) - `lll` (96): wrapped lines to the 88-column limit - `noctx` (46): `httptest.NewRequestWithContext` with `t.Context()` throughout the tests - `goconst` (24): shared constants for template/JSON keys in `internal/handlers` and repeated test literals - `gosec` (23): app-page redirects now go through a `redirectToApp` helper that path-escapes the app ID (G710 open redirect); `http.ServeFile` of the internally derived deployment log path annotated like the adjacent `os.Stat` (G703) - `dupl` (22): extracted a generic `findAllByAppID` in `internal/models`, a `deleteAppResource` helper in `internal/handlers`, a shared `parsePush` in `internal/service/webhook`, and table-driven/helper-based dedup in tests - `nolintlint` (5): removed `//nolint:funlen` directives made obsolete by the new limits (plus one more that became obsolete after refactoring) - `nilerr` (3, surfaced during fixing): resource-delete lookups now propagate the find error to the caller No behavior changes intended; all tests pass and `make check` is green. Note: golangci-lint v2.12 warns that `gomodguard` is deprecated in favor of `gomodguard_v2` — a future canonical-config update should address this centrally. Co-authored-by: sneak <sneak@sneak.berlin> Reviewed-on: #187 Co-authored-by: clawbot <clawbot@noreply.example.org> Co-committed-by: clawbot <clawbot@noreply.example.org>
This commit was merged in pull request #187.
This commit is contained in:
@@ -98,88 +98,77 @@ type GitLabPushPayload struct {
|
||||
func ParsePushPayload(source Source, payload []byte) (*PushEvent, error) {
|
||||
switch source {
|
||||
case SourceGitHub:
|
||||
return parseGitHubPush(payload)
|
||||
return parsePush(payload, githubPushEvent)
|
||||
case SourceGitLab:
|
||||
return parseGitLabPush(payload)
|
||||
return parsePush(payload, gitlabPushEvent)
|
||||
case SourceGitea, SourceUnknown:
|
||||
// Gitea and unknown both use Gitea format for backward compatibility.
|
||||
return parseGiteaPush(payload)
|
||||
return parsePush(payload, giteaPushEvent)
|
||||
}
|
||||
|
||||
// Unreachable for known source values, but satisfies exhaustive checker.
|
||||
return parseGiteaPush(payload)
|
||||
return parsePush(payload, giteaPushEvent)
|
||||
}
|
||||
|
||||
func parseGiteaPush(payload []byte) (*PushEvent, error) {
|
||||
var p GiteaPushPayload
|
||||
// parsePush unmarshals payload into P and converts it into a normalized
|
||||
// PushEvent via build.
|
||||
func parsePush[P any](payload []byte, build func(P) *PushEvent) (*PushEvent, error) {
|
||||
var p P
|
||||
|
||||
unmarshalErr := json.Unmarshal(payload, &p)
|
||||
if unmarshalErr != nil {
|
||||
return nil, unmarshalErr
|
||||
}
|
||||
|
||||
commitURL := extractGiteaCommitURL(p)
|
||||
|
||||
return &PushEvent{
|
||||
Source: SourceGitea,
|
||||
Ref: p.Ref,
|
||||
Before: p.Before,
|
||||
After: p.After,
|
||||
Branch: extractBranch(p.Ref),
|
||||
RepoName: p.Repository.FullName,
|
||||
CloneURL: p.Repository.CloneURL,
|
||||
HTMLURL: p.Repository.HTMLURL,
|
||||
CommitURL: commitURL,
|
||||
Pusher: p.Pusher.Username,
|
||||
}, nil
|
||||
return build(p), nil
|
||||
}
|
||||
|
||||
func parseGitHubPush(payload []byte) (*PushEvent, error) {
|
||||
var p GitHubPushPayload
|
||||
|
||||
unmarshalErr := json.Unmarshal(payload, &p)
|
||||
if unmarshalErr != nil {
|
||||
return nil, unmarshalErr
|
||||
}
|
||||
|
||||
commitURL := extractGitHubCommitURL(p)
|
||||
|
||||
// basePushEvent builds a PushEvent populated with the fields shared by all
|
||||
// webhook sources.
|
||||
func basePushEvent(source Source, ref, before, after string) *PushEvent {
|
||||
return &PushEvent{
|
||||
Source: SourceGitHub,
|
||||
Ref: p.Ref,
|
||||
Before: p.Before,
|
||||
After: p.After,
|
||||
Branch: extractBranch(p.Ref),
|
||||
RepoName: p.Repository.FullName,
|
||||
CloneURL: p.Repository.CloneURL,
|
||||
HTMLURL: p.Repository.HTMLURL,
|
||||
CommitURL: commitURL,
|
||||
Pusher: p.Pusher.Name,
|
||||
}, nil
|
||||
Source: source,
|
||||
Ref: ref,
|
||||
Before: before,
|
||||
After: after,
|
||||
Branch: extractBranch(ref),
|
||||
}
|
||||
}
|
||||
|
||||
func parseGitLabPush(payload []byte) (*PushEvent, error) {
|
||||
var p GitLabPushPayload
|
||||
// giteaPushEvent converts a Gitea push payload to a normalized PushEvent.
|
||||
func giteaPushEvent(p GiteaPushPayload) *PushEvent {
|
||||
event := basePushEvent(SourceGitea, p.Ref, p.Before, p.After)
|
||||
event.RepoName = p.Repository.FullName
|
||||
event.CloneURL = p.Repository.CloneURL
|
||||
event.HTMLURL = p.Repository.HTMLURL
|
||||
event.CommitURL = extractGiteaCommitURL(p)
|
||||
event.Pusher = p.Pusher.Username
|
||||
|
||||
unmarshalErr := json.Unmarshal(payload, &p)
|
||||
if unmarshalErr != nil {
|
||||
return nil, unmarshalErr
|
||||
}
|
||||
return event
|
||||
}
|
||||
|
||||
commitURL := extractGitLabCommitURL(p)
|
||||
// gitlabPushEvent converts a GitLab push payload to a normalized PushEvent.
|
||||
func gitlabPushEvent(p GitLabPushPayload) *PushEvent {
|
||||
event := basePushEvent(SourceGitLab, p.Ref, p.Before, p.After)
|
||||
event.RepoName = p.Project.PathWithNamespace
|
||||
event.CloneURL = p.Project.GitHTTPURL
|
||||
event.HTMLURL = p.Project.WebURL
|
||||
event.CommitURL = extractGitLabCommitURL(p)
|
||||
event.Pusher = p.UserName
|
||||
|
||||
return &PushEvent{
|
||||
Source: SourceGitLab,
|
||||
Ref: p.Ref,
|
||||
Before: p.Before,
|
||||
After: p.After,
|
||||
Branch: extractBranch(p.Ref),
|
||||
RepoName: p.Project.PathWithNamespace,
|
||||
CloneURL: p.Project.GitHTTPURL,
|
||||
HTMLURL: p.Project.WebURL,
|
||||
CommitURL: commitURL,
|
||||
Pusher: p.UserName,
|
||||
}, nil
|
||||
return event
|
||||
}
|
||||
|
||||
// githubPushEvent converts a GitHub push payload to a normalized PushEvent.
|
||||
func githubPushEvent(p GitHubPushPayload) *PushEvent {
|
||||
event := basePushEvent(SourceGitHub, p.Ref, p.Before, p.After)
|
||||
event.RepoName = p.Repository.FullName
|
||||
event.CloneURL = p.Repository.CloneURL
|
||||
event.HTMLURL = p.Repository.HTMLURL
|
||||
event.CommitURL = extractGitHubCommitURL(p)
|
||||
event.Pusher = p.Pusher.Name
|
||||
|
||||
return event
|
||||
}
|
||||
|
||||
// extractBranch extracts the branch name from a git ref.
|
||||
|
||||
Reference in New Issue
Block a user