Found while working #175 on a fresh environment: make fmt fails
with script/fmt: goimports: not found after a successful make bootstrap. script/fmt runs gofmt, goimports, and npx prettier, but script/bootstrap only installs git, make, go,
and golangci-lint. script/bootstrap's contract is to install ALL
dependencies idempotently, so this is a bootstrap gap.
Remediation: install a pinned goimports in script/bootstrap
(e.g. go install golang.org/x/tools/cmd/goimports@vX.Y.Z with an
exact version constant, integrity covered by the Go module checksum
database). While there, decide whether node/prettier availability
for the static/js formatting step also needs a bootstrap guard,
since script/fmt assumes npx prettier exists.
Definition of done:
on a machine without goimports, make bootstrap followed by make fmt succeeds
the installed version is pinned exactly (no @latest), with a
version comment per REPO_POLICIES.md
lands via PR from a feature branch off main
Found while working #175 on a fresh environment: `make fmt` fails
with `script/fmt: goimports: not found` after a successful
`make bootstrap`. `script/fmt` runs `gofmt`, `goimports`, and
`npx prettier`, but `script/bootstrap` only installs git, make, go,
and golangci-lint. `script/bootstrap`'s contract is to install ALL
dependencies idempotently, so this is a bootstrap gap.
Remediation: install a pinned `goimports` in `script/bootstrap`
(e.g. `go install golang.org/x/tools/cmd/goimports@vX.Y.Z` with an
exact version constant, integrity covered by the Go module checksum
database). While there, decide whether node/prettier availability
for the `static/js` formatting step also needs a bootstrap guard,
since `script/fmt` assumes `npx prettier` exists.
Definition of done:
- on a machine without `goimports`, `make bootstrap` followed by
`make fmt` succeeds
- the installed version is pinned exactly (no `@latest`), with a
version comment per `REPO_POLICIES.md`
- lands via PR from a feature branch off `main`
clawbot
added this to the 1.1.0 milestone 2026-08-07 18:47:47 +02:00
script/bootstrap now installs goimports when missing: go install golang.org/x/tools/cmd/goimports pinned at v0.49.0 (integrity via the Go module checksum database), placing the binary in /usr/local/bin so it is on PATH. v0.49.0 matches Go 1.25 (go.mod); v0.50.0 would force a Go 1.26 toolchain download.
Verified on a fresh golang:1.25 container lacking goimports: make bootstrap then make fmt succeeds.
Node/prettier left out of scope: npx prettier is separately unpinned and needs node; guarding it properly is a larger, separate change, and make check runs only gofmt so main stays green. Recommend a follow-up issue.
Model: opus-4-8
Fixed in https://git.eeqj.de/sneak/upaas/pulls/196 (base `next`).
`script/bootstrap` now installs `goimports` when missing: `go install golang.org/x/tools/cmd/goimports` pinned at `v0.49.0` (integrity via the Go module checksum database), placing the binary in `/usr/local/bin` so it is on PATH. `v0.49.0` matches Go 1.25 (`go.mod`); `v0.50.0` would force a Go 1.26 toolchain download.
Verified on a fresh `golang:1.25` container lacking goimports: `make bootstrap` then `make fmt` succeeds.
Node/prettier left out of scope: `npx prettier` is separately unpinned and needs node; guarding it properly is a larger, separate change, and `make check` runs only `gofmt` so `main` stays green. Recommend a follow-up issue.
Model: opus-4-8
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while working #175 on a fresh environment:
make fmtfailswith
script/fmt: goimports: not foundafter a successfulmake bootstrap.script/fmtrunsgofmt,goimports, andnpx prettier, butscript/bootstraponly installs git, make, go,and golangci-lint.
script/bootstrap's contract is to install ALLdependencies idempotently, so this is a bootstrap gap.
Remediation: install a pinned
goimportsinscript/bootstrap(e.g.
go install golang.org/x/tools/cmd/goimports@vX.Y.Zwith anexact version constant, integrity covered by the Go module checksum
database). While there, decide whether node/prettier availability
for the
static/jsformatting step also needs a bootstrap guard,since
script/fmtassumesnpx prettierexists.Definition of done:
goimports,make bootstrapfollowed bymake fmtsucceeds@latest), with aversion comment per
REPO_POLICIES.mdmainclawbot referenced this issue2026-09-03 18:29:27 +02:00
clawbot referenced this issue2026-09-03 18:29:58 +02:00
Fixed in #196 (base
next).script/bootstrapnow installsgoimportswhen missing:go install golang.org/x/tools/cmd/goimportspinned atv0.49.0(integrity via the Go module checksum database), placing the binary in/usr/local/binso it is on PATH.v0.49.0matches Go 1.25 (go.mod);v0.50.0would force a Go 1.26 toolchain download.Verified on a fresh
golang:1.25container lacking goimports:make bootstrapthenmake fmtsucceeds.Node/prettier left out of scope:
npx prettieris separately unpinned and needs node; guarding it properly is a larger, separate change, andmake checkruns onlygofmtsomainstays green. Recommend a follow-up issue.Model: opus-4-8