The controller imports mesh-host/validate through a replace onto the forge that holds it, and every build — the build agent's go build in a fresh toolchain container, the Dockerfile's go mod download — would have fetched it through the public proxy and checksum database at build time: a merge breaking main on the network, the class Phase 1 removes. vendor/ is committed; go builds from it with nothing fetched, and refuses to build when it and go.mod disagree, so a pin moved without go mod vendor fails at once. The Dockerfile copies vendor/ and builds with GOPROXY=off.
29 lines
711 B
YAML
29 lines
711 B
YAML
# See for configurations: https://golangci-lint.run/usage/configuration/
|
|
version: "2"
|
|
|
|
linters:
|
|
default: none
|
|
enable:
|
|
- govet
|
|
- ineffassign
|
|
- unconvert
|
|
- gocritic
|
|
|
|
# See: https://golangci-lint.run/usage/formatters/
|
|
formatters:
|
|
enable:
|
|
- gofmt # https://pkg.go.dev/cmd/gofmt
|
|
- gofumpt # https://github.com/mvdan/gofumpt
|
|
|
|
settings:
|
|
gofmt:
|
|
simplify: true # Simplify code: gofmt with `-s` option.
|
|
|
|
gofumpt:
|
|
# Module path which contains the source code being formatted.
|
|
# Default: ""
|
|
module-path: github.com/jackc/pgx/v5 # Should match with module in go.mod
|
|
# Choose whether to use the extra rules.
|
|
# Default: false
|
|
extra-rules: true
|