The controller imports mesh-host/validate through a replace onto the forge that holds it, and every build — the build agent's go build in a fresh toolchain container, the Dockerfile's go mod download — would have fetched it through the public proxy and checksum database at build time: a merge breaking main on the network, the class Phase 1 removes. vendor/ is committed; go builds from it with nothing fetched, and refuses to build when it and go.mod disagree, so a pin moved without go mod vendor fails at once. The Dockerfile copies vendor/ and builds with GOPROXY=off.
44 lines
871 B
YAML
44 lines
871 B
YAML
version: "2"
|
|
linters:
|
|
settings:
|
|
staticcheck:
|
|
# The merged staticcheck linter pulls in more check families than this
|
|
# repo has ever run; keep it to the set that was in force before.
|
|
checks:
|
|
- SA*
|
|
- S1*
|
|
exclusions:
|
|
generated: lax
|
|
presets:
|
|
- comments
|
|
- common-false-positives
|
|
- legacy
|
|
- std-error-handling
|
|
rules:
|
|
- linters:
|
|
- errcheck
|
|
text: Unsubscribe
|
|
- linters:
|
|
- errcheck
|
|
text: Drain
|
|
- linters:
|
|
- errcheck
|
|
text: msg.Ack
|
|
- linters:
|
|
- errcheck
|
|
text: watcher.Stop
|
|
paths:
|
|
- third_party$
|
|
- builtin$
|
|
- examples$
|
|
issues:
|
|
max-issues-per-linter: 0
|
|
max-same-issues: 0
|
|
formatters:
|
|
exclusions:
|
|
generated: lax
|
|
paths:
|
|
- third_party$
|
|
- builtin$
|
|
- examples$
|