Deprecated gomodguard linter in the org-standard .golangci.yml (needs an upstream decision) #98

Closed
opened 2026-08-09 05:01:01 +02:00 by clawbot · 5 comments
Collaborator

@sneak — this needs your call, because the fix is not in this repository's power. Assigning to you rather than acting.

The warning

Every pinned lint run (golangci-lint v2.12.2, as used by script/cibuild) emits:

The linter 'gomodguard' is deprecated (since v2.12.0) ... Replaced by gomodguard_v2

It has shown up in every PR this cycle (#91, #92, #95, #96). It is currently harmless noise, but a deprecated linter is an action item, not background noise — it will eventually be removed and the config will start failing rather than warning.

Why I am not fixing it

The setting lives in .golangci.yml, which REPO_POLICIES.md says is standardized and must NEVER be modified by an agent, only manually by the user, and which must match the canonical copy at https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml. The current file is pinned on main via #86 at sha256 021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb.

Editing it here would (a) violate that policy and (b) desynchronise this repo from the org standard, which is worse than the warning. So this is an upstream change to the prompts repo that then propagates to every repo, not a webhooker change.

Options

  1. Update the canonical .golangci.yml in the prompts repo to use gomodguard_v2, then pull the new file into this repo and re-pin its sha256. Correct and durable; touches every repo that consumes the standard, so it wants to be done deliberately.
  2. Drop gomodguard from the canonical config if it is not actually earning its place — it guards against blocked module imports, which may be redundant with the dependency policy in GO_PACKAGE_DEFAULTS.md.
  3. Do nothing for now and accept the warning until golangci-lint removes the linter outright, then handle it under time pressure.

Recommendation

Option 1. It is a mechanical rename in one file, the replacement is the maintainers' own designated successor, and doing it now means it lands as a quiet no-op change rather than an emergency when a future golangci-lint version drops the old name and every repo's script/cibuild goes red at once.

Definition of done

  • The canonical .golangci.yml in prompts no longer references the deprecated gomodguard.
  • This repo's .golangci.yml is refreshed from the canonical copy, with the new sha256 recorded wherever the current one is documented.
  • script/cibuild green with the v2.12.2 pin unchanged, and the deprecation warning gone.
@sneak — this needs your call, because the fix is not in this repository's power. Assigning to you rather than acting. ## The warning Every pinned lint run (golangci-lint v2.12.2, as used by `script/cibuild`) emits: ``` The linter 'gomodguard' is deprecated (since v2.12.0) ... Replaced by gomodguard_v2 ``` It has shown up in every PR this cycle (#91, #92, #95, #96). It is currently harmless noise, but a deprecated linter is an action item, not background noise — it will eventually be removed and the config will start failing rather than warning. ## Why I am not fixing it The setting lives in `.golangci.yml`, which `REPO_POLICIES.md` says is standardized and **must NEVER be modified by an agent, only manually by the user**, and which must match the canonical copy at `https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`. The current file is pinned on `main` via #86 at sha256 `021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb`. Editing it here would (a) violate that policy and (b) desynchronise this repo from the org standard, which is worse than the warning. So this is an upstream change to the `prompts` repo that then propagates to every repo, not a webhooker change. ## Options 1. **Update the canonical `.golangci.yml` in the `prompts` repo** to use `gomodguard_v2`, then pull the new file into this repo and re-pin its sha256. Correct and durable; touches every repo that consumes the standard, so it wants to be done deliberately. 2. **Drop `gomodguard` from the canonical config** if it is not actually earning its place — it guards against blocked module imports, which may be redundant with the dependency policy in `GO_PACKAGE_DEFAULTS.md`. 3. **Do nothing for now** and accept the warning until golangci-lint removes the linter outright, then handle it under time pressure. ## Recommendation Option 1. It is a mechanical rename in one file, the replacement is the maintainers' own designated successor, and doing it now means it lands as a quiet no-op change rather than an emergency when a future golangci-lint version drops the old name and every repo's `script/cibuild` goes red at once. ## Definition of done - The canonical `.golangci.yml` in `prompts` no longer references the deprecated `gomodguard`. - This repo's `.golangci.yml` is refreshed from the canonical copy, with the new sha256 recorded wherever the current one is documented. - `script/cibuild` green with the v2.12.2 pin unchanged, and the deprecation warning gone.
sneak was assigned by clawbot 2026-08-09 05:01:01 +02:00
Author
Collaborator

The upstream fix already exists and is waiting: sneak/prompts#47, "Migrate canonical .golangci.yml from gomodguard to gomodguard_v2", open since 2026-08-10 and unmerged. That is option 1 from the body, implemented. Nothing further is needed in this repo until it lands and the pinned copy is re-synced.

Recording it here because six separate workers have independently rediscovered and re-reported this deprecation warning while gating on the Docker lint stage today. It surfaces on every lint run in the repo, so without a pointer to the existing PR each one spends effort deciding whether to file it.

Not a 1.0.0 blocker: make lint reports 0 issues. and the warning does not affect the tag. Left assigned to you, since merging sneak/prompts#47 is the only remaining action and agents are forbidden from editing .golangci.yml locally.

The upstream fix already exists and is waiting: https://git.eeqj.de/sneak/prompts/pulls/47, "Migrate canonical `.golangci.yml` from gomodguard to gomodguard_v2", open since 2026-08-10 and unmerged. That is option 1 from the body, implemented. Nothing further is needed in this repo until it lands and the pinned copy is re-synced. Recording it here because six separate workers have independently rediscovered and re-reported this deprecation warning while gating on the Docker lint stage today. It surfaces on every lint run in the repo, so without a pointer to the existing PR each one spends effort deciding whether to file it. Not a `1.0.0` blocker: `make lint` reports `0 issues.` and the warning does not affect the tag. Left assigned to you, since merging https://git.eeqj.de/sneak/prompts/pulls/47 is the only remaining action and agents are forbidden from editing `.golangci.yml` locally.
Author
Collaborator

Resolved upstream: the shared .golangci.yml in sneak/prompts moved from gomodguard to gomodguard_v2 (sneak/prompts#55, merged 2026-09-09). What remains here is copying the updated file into this repo unchanged, queued for when webhooker resumes (paused under the current priority rule). Reassigned to clawbot: nothing here waits on sneak.

Model: opus-5-5

Resolved upstream: the shared `.golangci.yml` in `sneak/prompts` moved from `gomodguard` to `gomodguard_v2` (https://git.eeqj.de/sneak/prompts/pulls/55, merged 2026-09-09). What remains here is copying the updated file into this repo unchanged, queued for when webhooker resumes (paused under the current priority rule). Reassigned to clawbot: nothing here waits on sneak. Model: opus-5-5
sneak was unassigned by clawbot 2026-09-23 07:59:11 +02:00
clawbot self-assigned this 2026-09-23 07:59:11 +02:00
Author
Collaborator

Plan, now that the shared config has moved on (sneak/prompts#55):

  • Replace .golangci.yml with the canonical copy from https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml, byte for byte, as REPO_POLICIES.md says to fetch it; no local edit to it.
  • The canonical copy has also gained depguard rules (test-support code kept out of the shipped binary) and drops the deprecated wsl and gomodguard by name. Whatever the new rules report in this repo is fixed in the code, never by changing the config.
  • Done when make lint reports no deprecation warning and 0 issues., and make check passes.

This also covers #248, which asks for the same thing and is closed in favour of this issue.

Model: opus-5-5

Plan, now that the shared config has moved on (https://git.eeqj.de/sneak/prompts/pulls/55): - Replace `.golangci.yml` with the canonical copy from `https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`, byte for byte, as `REPO_POLICIES.md` says to fetch it; no local edit to it. - The canonical copy has also gained `depguard` rules (test-support code kept out of the shipped binary) and drops the deprecated `wsl` and `gomodguard` by name. Whatever the new rules report in this repo is fixed in the code, never by changing the config. - Done when `make lint` reports no deprecation warning and `0 issues.`, and `make check` passes. This also covers https://git.eeqj.de/sneak/webhooker/issues/248, which asks for the same thing and is closed in favour of this issue. Model: opus-5-5
Author
Collaborator

#503 replaces .golangci.yml with the shared copy, unchanged (sha256 a79b63a254602a5318db5d0e9a06bc71b84bf0c1d896305229d8bfed1d1b1776). The deprecated gomodguard is gone in favour of gomodguard_v2, and the new depguard rule finds nothing in this repo, so no code changed.

Judgement call: the shared file allows a repo to add its own test-support packages to the depguard deny list; this repo has none, so nothing was added.

Model: opus-5-5

https://git.eeqj.de/sneak/webhooker/pulls/503 replaces `.golangci.yml` with the shared copy, unchanged (sha256 `a79b63a254602a5318db5d0e9a06bc71b84bf0c1d896305229d8bfed1d1b1776`). The deprecated `gomodguard` is gone in favour of `gomodguard_v2`, and the new `depguard` rule finds nothing in this repo, so no code changed. Judgement call: the shared file allows a repo to add its own test-support packages to the `depguard` deny list; this repo has none, so nothing was added. Model: opus-5-5
Author
Collaborator

Covered by #504, which re-vendors the shared files from the newer sneak/prompts commit dd4027b.

Model: opus-5-5

Covered by https://git.eeqj.de/sneak/webhooker/issues/504, which re-vendors the shared files from the newer `sneak/prompts` commit `dd4027b`. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#98