Bumps golangci-lint from v2.10.1 to v2.12.2 everywhere it is pinned and installs the canonical .golangci.yml, then fixes every finding the new linter surfaces so make check is green.
Version pins
Dockerfile lint stage: golangci/golangci-lint:v2.12.2 (Debian-based), tag plus digest pin
script/bootstrap: GOLANGCI_LINT_VERSION=2.12.2 with updated linux-amd64/linux-arm64 release-archive sha256 pins
Config
.golangci.yml replaced with the canonical config. Material change: the old file declared version: "2" but kept settings under the legacy top-level linters-settings key, which golangci-lint v2 ignores — so the intended thresholds (lll 88, funlen 80/50, cyclop 15, dupl 100) were not being applied. The canonical file moves them under linters.settings and drops issues.exclude-use-default.
Lint fixes (216 findings)
lll (96): wrapped lines to the 88-column limit
noctx (46): httptest.NewRequestWithContext with t.Context() throughout the tests
goconst (24): shared constants for template/JSON keys in internal/handlers and repeated test literals
gosec (23): app-page redirects now go through a redirectToApp helper that path-escapes the app ID (G710 open redirect); http.ServeFile of the internally derived deployment log path annotated like the adjacent os.Stat (G703)
dupl (22): extracted a generic findAllByAppID in internal/models, a deleteAppResource helper in internal/handlers, a shared parsePush in internal/service/webhook, and table-driven/helper-based dedup in tests
nolintlint (5): removed //nolint:funlen directives made obsolete by the new limits (plus one more that became obsolete after refactoring)
nilerr (3, surfaced during fixing): resource-delete lookups now propagate the find error to the caller
No behavior changes intended; all tests pass and make check is green.
Note: golangci-lint v2.12 warns that gomodguard is deprecated in favor of gomodguard_v2 — a future canonical-config update should address this centrally.
Bumps golangci-lint from v2.10.1 to v2.12.2 everywhere it is pinned and installs the canonical `.golangci.yml`, then fixes every finding the new linter surfaces so `make check` is green.
## Version pins
- `Dockerfile` lint stage: `golangci/golangci-lint:v2.12.2` (Debian-based), tag plus digest pin
- `script/bootstrap`: `GOLANGCI_LINT_VERSION=2.12.2` with updated `linux-amd64`/`linux-arm64` release-archive sha256 pins
## Config
`.golangci.yml` replaced with the canonical config. Material change: the old file declared `version: "2"` but kept settings under the legacy top-level `linters-settings` key, which golangci-lint v2 ignores — so the intended thresholds (`lll` 88, `funlen` 80/50, `cyclop` 15, `dupl` 100) were not being applied. The canonical file moves them under `linters.settings` and drops `issues.exclude-use-default`.
## Lint fixes (216 findings)
- `lll` (96): wrapped lines to the 88-column limit
- `noctx` (46): `httptest.NewRequestWithContext` with `t.Context()` throughout the tests
- `goconst` (24): shared constants for template/JSON keys in `internal/handlers` and repeated test literals
- `gosec` (23): app-page redirects now go through a `redirectToApp` helper that path-escapes the app ID (G710 open redirect); `http.ServeFile` of the internally derived deployment log path annotated like the adjacent `os.Stat` (G703)
- `dupl` (22): extracted a generic `findAllByAppID` in `internal/models`, a `deleteAppResource` helper in `internal/handlers`, a shared `parsePush` in `internal/service/webhook`, and table-driven/helper-based dedup in tests
- `nolintlint` (5): removed `//nolint:funlen` directives made obsolete by the new limits (plus one more that became obsolete after refactoring)
- `nilerr` (3, surfaced during fixing): resource-delete lookups now propagate the find error to the caller
No behavior changes intended; all tests pass and `make check` is green.
Note: golangci-lint v2.12 warns that `gomodguard` is deprecated in favor of `gomodguard_v2` — a future canonical-config update should address this centrally.
Bump golangci-lint from v2.10.1 to v2.12.2 in the Dockerfile lint
stage (tag+digest pin) and script/bootstrap release-archive pins
(linux amd64/arm64 sha256s). Replace .golangci.yml with the canonical
v2-layout config so linter settings (lll 88, funlen 80/50, cyclop 15,
dupl 100) actually apply.
Fix all findings surfaced by the new linter and config:
- noctx: use httptest.NewRequestWithContext in all tests
- gosec G710/G703: route app redirects through a path-escaping
redirectToApp helper; annotate internal log path usage
- goconst: introduce shared constants for template/JSON keys and
repeated test literals
- lll: wrap lines to the 88-column limit
- dupl: extract shared helpers (generic findAllByAppID in models,
deleteAppResource in handlers, parsePush in webhook payloads,
table-driven/helper-based test dedup)
- nolintlint: drop nolint directives made obsolete by the new limits
Record the change in TODO.md; make check is green.
sneak
merged commit 7a34fc999c into main2026-08-07 22:21:42 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps golangci-lint from v2.10.1 to v2.12.2 everywhere it is pinned and installs the canonical
.golangci.yml, then fixes every finding the new linter surfaces somake checkis green.Version pins
Dockerfilelint stage:golangci/golangci-lint:v2.12.2(Debian-based), tag plus digest pinscript/bootstrap:GOLANGCI_LINT_VERSION=2.12.2with updatedlinux-amd64/linux-arm64release-archive sha256 pinsConfig
.golangci.ymlreplaced with the canonical config. Material change: the old file declaredversion: "2"but kept settings under the legacy top-levellinters-settingskey, which golangci-lint v2 ignores — so the intended thresholds (lll88,funlen80/50,cyclop15,dupl100) were not being applied. The canonical file moves them underlinters.settingsand dropsissues.exclude-use-default.Lint fixes (216 findings)
lll(96): wrapped lines to the 88-column limitnoctx(46):httptest.NewRequestWithContextwitht.Context()throughout the testsgoconst(24): shared constants for template/JSON keys ininternal/handlersand repeated test literalsgosec(23): app-page redirects now go through aredirectToApphelper that path-escapes the app ID (G710 open redirect);http.ServeFileof the internally derived deployment log path annotated like the adjacentos.Stat(G703)dupl(22): extracted a genericfindAllByAppIDininternal/models, adeleteAppResourcehelper ininternal/handlers, a sharedparsePushininternal/service/webhook, and table-driven/helper-based dedup in testsnolintlint(5): removed//nolint:funlendirectives made obsolete by the new limits (plus one more that became obsolete after refactoring)nilerr(3, surfaced during fixing): resource-delete lookups now propagate the find error to the callerNo behavior changes intended; all tests pass and
make checkis green.Note: golangci-lint v2.12 warns that
gomodguardis deprecated in favor ofgomodguard_v2— a future canonical-config update should address this centrally.clawbot referenced this pull request2026-09-03 18:28:14 +02:00
clawbot referenced this pull request2026-09-03 18:28:14 +02:00
clawbot referenced this pull request2026-09-03 18:28:42 +02:00
clawbot referenced this pull request2026-09-03 18:29:27 +02:00
clawbot referenced this pull request2026-09-03 18:29:57 +02:00
clawbot referenced this pull request2026-09-03 18:29:58 +02:00