All checks were successful
check / check (pull_request) Successful in 3m11s
Three findings remain that cannot be fixed without making a repo-wide naming decision, so each carries a per-site //nolint directive with its justification. revive var-naming (internal/log, internal/crypto, internal/types): fixing these means renaming packages across the whole codebase, which is the repo owner's call, not a lint fix. Neither stdlib log nor stdlib crypto is imported anywhere in the repo, so nothing is actually shadowed today. The rename decision is tracked in issue #76. revive reports a package-name failure only once per package directory, on whichever file it happens to lint first, so every file of the affected packages carries the directive and lists nolintlint alongside revive so the ones that lose the race are not reported as unused. No gosec directives are needed: the pinned golangci-lint v2.12.2 that CI and the Dockerfile use reports nothing at the term.IsTerminal conversions in internal/log and internal/ui or at the os.Remove calls in internal/vaultik/verify.go, so suppressing there would itself fail nolintlint as an unused directive. Verification is script/cibuild, which builds the hash-pinned lint image: it exits 0, with make lint reporting "0 issues" under the canonical .golangci.yml (sha256 021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb, unmodified), plus make fmt-check, make test and the release build. That also unblocks issue #59. make check is not a valid gate here: script/lint runs whatever golangci-lint is on PATH rather than the pinned version, which is tracked in issue #78. Also corrects the capacity comment in collectBatchFlushData: an empty file contributes no chunk mappings, so the pending-file count is a rough starting capacity, not a lower bound. TODO.md: record this work, note that the previous next step (reconciling uncommitted ARCHITECTURE.md edits) needed no work because the tree is clean, and move the next step on to the stale-branch triage.