Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
70 changes: 43 additions & 27 deletions .golangci.yaml
Original file line number Diff line number Diff line change
@@ -1,31 +1,27 @@
# https://golangci-lint.run/docs/configuration/file/
version: "2"

run:
timeout: 5m

issues:
whole-files: true
max-same-issues: 50

severity:
default: error
max-same-issues: 0 # 0 = unlimited; default 3
max-issues-per-linter: 0 # 0 = unlimited; default 50

uniq-by-line: false # default true hides other linters' findings on the same line

formatters:
enable:
- gci
- gofmt
# goimports rides along with gofumpt because it alone drops unused imports.
- gofumpt
- goimports
- golines

settings:
gofmt:
rewrite-rules:
- pattern: "interface{}"
replacement: "any"
gofumpt:
extra-rules: true
extra:
group-params: true
clothe-returns: true
balance-calls: true
golines:
max-len: 120

Expand All @@ -42,9 +38,7 @@ linters:
# Additional
- bodyclose
- canonicalheader
- copyloopvar
- depguard
- dupword
- durationcheck
- errchkjson
- errname
Expand All @@ -55,11 +49,9 @@ linters:
- gocognit
- goconst
- gocritic
- goheader
- gomodguard_v2
- goprintffuncname
- gosec
- intrange
- loggercheck
- mirror
- misspell
Expand Down Expand Up @@ -90,30 +82,54 @@ linters:
- usestdlibvars
- usetesting
- wastedassign
- whitespace
- wsl_v5

settings:
govet:
enable:
- deepequalerrors
- nilness
- reflectvaluecompare
- sortslice
- unusedwrite

modernize:
disable:
- omitzero
nolintlint:
require-specific: true
require-explanation: true

depguard:
rules:
main:
deny:
- pkg: github.com/pkg/errors
desc: Should be replaced by standard lib errors package
- pkg: golang.org/x/exp/slices
desc: Should be replaced by standard lib slices package
- pkg: github.com/go-resty/resty$
desc: Use github.com/go-resty/resty/v2 instead
- pkg: github.com/aws/smithy-go/ptr$
desc: Use github.com/aws/aws-sdk-go-v2/aws instead

gomodguard_v2:
# A local `replace` that reaches main breaks the tagged release build.
# Only sees directly imported modules; an indirect dep's replace slips through.
local-replace-directives: true

# Bar for an entry: archived or known-vulnerable, AND still reached for
# directly today because old tutorials point there.
blocked:
- module: github.com/Azure/azure-sdk-for-go
reason: Track 1 (services/, storage/, profiles/) retired 2023-09-30; use the sdk/ modules (track 2)
- module: github.com/aws/aws-sdk-go
recommendations:
- github.com/aws/aws-sdk-go-v2
reason: End-of-support since 2025-07-31; no further updates, including security fixes
- module: github.com/dgrijalva/jwt-go
recommendations:
- github.com/golang-jwt/jwt/v5
reason: Unmaintained; golang-jwt is the community continuation
- module: github.com/golang/mock
recommendations:
- go.uber.org/mock
reason: Archived upstream; go.uber.org/mock is the maintained fork
- module: github.com/satori/go.uuid
recommendations:
- github.com/google/uuid
reason: Unmaintained; on Go 1.27+ prefer the stdlib uuid package

exclusions:
rules:
Expand Down
7 changes: 6 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ make check-tidy # verify go.mod/go.sum are tidy
make release-snapshot # goreleaser release --snapshot --clean (test release locally)
```

Tool versions are pinned in [mise.toml](./mise.toml) (Go 1.26.4, golangci-lint 2.12.2, goreleaser 2.16.0, prek 0.4.6).
Tool versions are pinned in [mise.toml](./mise.toml) (Go 1.26.4, golangci-lint 2.13.1, goreleaser 2.16.0, prek 0.4.6).
Run `mise install` to set up the exact toolchain. [.pre-commit-config.yaml](./.pre-commit-config.yaml)
is the single source of truth for what gets checked: `prek` runs it on `git commit` (staged files),
and `make check` runs the same hooks over **all** tracked files, which is what CI runs. `check-tidy`,
Expand Down Expand Up @@ -107,6 +107,11 @@ bin/mint # compiled binary (gitignored)
`check-rev` guard) — `golangci-lint` itself only warns and exits 0, which would let CI pass having
linted nothing. The pre-commit hook already runs
lint on every commit, so running it by hand is only needed to re-check a different rev.
- Lint config changes do not require fixing the whole codebase. `whole-files: true` +
`--new-from-rev` is a ratchet: a PR fixes the lint of the files it touches, and untouched
files carry their debt until someone edits them. After changing `.golangci.yaml`, run
`golangci-lint run ./...` once (no `--new-from-rev`) to see how much debt the change adds
repo-wide — read the number, don't fix it.
- **Release workflow** — push a tag matching `v*.*.*` to automatically trigger GoReleaser CI; creates GitHub Release with multi-platform binaries.
- **Local snapshot testing** — run `goreleaser release --snapshot --clean` to validate build configuration before publishing.

Expand Down
2 changes: 1 addition & 1 deletion mise.toml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
[tools]
go = "1.26.4"
golangci-lint = "2.12.2"
golangci-lint = "2.13.1"
goreleaser = "2.16.0"
prek = "0.4.6"
Loading