Updates golangci-lint to v2.12.2 everywhere it is pinned and installs the canonical .golangci.yml, then remediates every finding the new linter/config surfaces so make check is green.
Version bump
Dockerfile lint stage: golangci/golangci-lint:v2.11.3-alpine -> v2.12.2-alpine (digest-pinned, date comment updated)
Makefiledeps target: go install moved from the old v1 module path at @latest to the pinned github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2
.golangci.yml replaced with the canonical config (v2 schema; settings under linters.settings so the thresholds actually apply; default: all with the standard six disables)
script/bootstrap installs golangci-lint via the system package manager and carries no version pin, so it is unchanged
CI (.gitea/workflows/check.yml) only runs script/cibuild, so it needed no change
Lint remediation
The canonical config surfaced ~3,300 findings across 56k lines. All are fixed, behavior-preserving; incorporates and supersedes the per-package mechanical passes already merged to main (refs #61). Highlights:
err113: dynamic errors replaced with package sentinels + %w wrapping; comparisons via errors.Is
goprintffuncname: printf-style helpers renamed with an f suffix (ui.Writer message methods, cli.ReportErrorf, database.Fatalf) and all call sites updated
contextcheck/noctx: context.Context threaded through blob.Packer and the scanner call sites; context-aware exec/sql variants
funlen/cyclop/gocognit/dupl: oversized and duplicated functions split into focused helpers (production and test code)
tests: t.Parallel() added where safe (global logger init kept in the serial phase for -race), t.TempDir()/t.Helper() adopted, several suites converted to external test packages
gosec: bounded integer conversions, ReadHeaderTimeout on the test HTTP server; remaining warnings suppressed per-site with justifications
remaining nolint directives are rare, targeted, and each carries a reason (e.g. nilnil not-found contract in the repository layer, fx module globals, on-disk snake_case struct tags)
removed the deprecated log.LogOptions alias (callers migrated to log.Options)
make check (tests with -race, lint, fmt-check) passes.
Updates golangci-lint to v2.12.2 everywhere it is pinned and installs the canonical `.golangci.yml`, then remediates every finding the new linter/config surfaces so `make check` is green.
## Version bump
- `Dockerfile` lint stage: `golangci/golangci-lint:v2.11.3-alpine` -> `v2.12.2-alpine` (digest-pinned, date comment updated)
- `Makefile` `deps` target: `go install` moved from the old v1 module path at `@latest` to the pinned `github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2`
- `.golangci.yml` replaced with the canonical config (v2 schema; settings under `linters.settings` so the thresholds actually apply; `default: all` with the standard six disables)
- `script/bootstrap` installs golangci-lint via the system package manager and carries no version pin, so it is unchanged
- CI (`.gitea/workflows/check.yml`) only runs `script/cibuild`, so it needed no change
## Lint remediation
The canonical config surfaced ~3,300 findings across 56k lines. All are fixed, behavior-preserving; incorporates and supersedes the per-package mechanical passes already merged to `main` (refs #61). Highlights:
- `err113`: dynamic errors replaced with package sentinels + `%w` wrapping; comparisons via `errors.Is`
- `goprintffuncname`: printf-style helpers renamed with an `f` suffix (`ui.Writer` message methods, `cli.ReportErrorf`, `database.Fatalf`) and all call sites updated
- `revive` stutter renames: `blob.Handler`, `blob.WithReader`, `blob.ChunkPosition`, `storage.URL`, `storage.Info`; missing doc comments added
- `contextcheck`/`noctx`: `context.Context` threaded through `blob.Packer` and the scanner call sites; context-aware `exec`/`sql` variants
- `funlen`/`cyclop`/`gocognit`/`dupl`: oversized and duplicated functions split into focused helpers (production and test code)
- tests: `t.Parallel()` added where safe (global logger init kept in the serial phase for `-race`), `t.TempDir()`/`t.Helper()` adopted, several suites converted to external test packages
- `gosec`: bounded integer conversions, `ReadHeaderTimeout` on the test HTTP server; remaining warnings suppressed per-site with justifications
- remaining `nolint` directives are rare, targeted, and each carries a reason (e.g. `nilnil` not-found contract in the repository layer, fx module globals, on-disk snake_case struct tags)
- removed the deprecated `log.LogOptions` alias (callers migrated to `log.Options`)
`make check` (tests with `-race`, lint, fmt-check) passes.
Fix every finding surfaced by the canonical .golangci.yml with
golangci-lint v2.12.2 (refs #61), behavior-preserving throughout:
- err113: dynamic errors replaced with package-level sentinels and %w
wrapping; direct comparisons converted to errors.Is
- goprintffuncname: printf-style helpers renamed with an f suffix
(ui.Writer message methods, cli.ReportErrorf, database.Fatalf,
vaultik stdoutf) and all call sites updated
- revive: stuttering type names renamed (blob.Handler, blob.WithReader,
blob.ChunkPosition, storage.URL, storage.Info), doc comments added,
unused parameters blanked, package comments added
- contextcheck/noctx: ctx threaded through blob.Packer
(AddChunk/Flush/FinalizeBlob/PackChunks) and scanner call sites;
context-aware exec and sql variants used
- funlen/cyclop/gocognit/nestif/dupl: oversized or duplicated
functions split into focused helpers across production and test code
- paralleltest/tparallel/thelper/usetesting/testpackage: tests
parallelized where safe (global log.Initialize kept in the serial
phase), helpers marked, t.TempDir adopted, external test packages
where only exported API is used
- gosec: integer conversions clamped or justified, header timeouts
added, remaining findings suppressed with per-site justifications
- mnd/goconst/lll/wsl_v5/nlreturn/noinlineerr/errcheck and other
mechanical findings fixed directly
Remove the deprecated log.LogOptions alias (callers migrated to
log.Options). make check is green.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Updates golangci-lint to v2.12.2 everywhere it is pinned and installs the canonical
.golangci.yml, then remediates every finding the new linter/config surfaces somake checkis green.Version bump
Dockerfilelint stage:golangci/golangci-lint:v2.11.3-alpine->v2.12.2-alpine(digest-pinned, date comment updated)Makefiledepstarget:go installmoved from the old v1 module path at@latestto the pinnedgithub.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2.golangci.ymlreplaced with the canonical config (v2 schema; settings underlinters.settingsso the thresholds actually apply;default: allwith the standard six disables)script/bootstrapinstalls golangci-lint via the system package manager and carries no version pin, so it is unchanged.gitea/workflows/check.yml) only runsscript/cibuild, so it needed no changeLint remediation
The canonical config surfaced ~3,300 findings across 56k lines. All are fixed, behavior-preserving; incorporates and supersedes the per-package mechanical passes already merged to
main(refs #61). Highlights:err113: dynamic errors replaced with package sentinels +%wwrapping; comparisons viaerrors.Isgoprintffuncname: printf-style helpers renamed with anfsuffix (ui.Writermessage methods,cli.ReportErrorf,database.Fatalf) and all call sites updatedrevivestutter renames:blob.Handler,blob.WithReader,blob.ChunkPosition,storage.URL,storage.Info; missing doc comments addedcontextcheck/noctx:context.Contextthreaded throughblob.Packerand the scanner call sites; context-awareexec/sqlvariantsfunlen/cyclop/gocognit/dupl: oversized and duplicated functions split into focused helpers (production and test code)t.Parallel()added where safe (global logger init kept in the serial phase for-race),t.TempDir()/t.Helper()adopted, several suites converted to external test packagesgosec: bounded integer conversions,ReadHeaderTimeouton the test HTTP server; remaining warnings suppressed per-site with justificationsnolintdirectives are rare, targeted, and each carries a reason (e.g.nilnilnot-found contract in the repository layer, fx module globals, on-disk snake_case struct tags)log.LogOptionsalias (callers migrated tolog.Options)make check(tests with-race, lint, fmt-check) passes.