.golangci.yml
⎇
Raw
1version: "2"
2
3linters:
4 default: none
5 enable:
6 - errcheck
7 - govet
8 - staticcheck
9 - unused
10 - ineffassign
11 - gosec
12 - bodyclose
13 - noctx
14 settings:
15 errcheck:
16 # Best-effort cleanup and response writes. A failure here has no
17 # useful handler; the caller already logs or returns the main error.
18 exclude-functions:
19 - (io.Closer).Close
20 - (*os.File).Close
21 - (*database/sql.Rows).Close
22 - (*database/sql.Tx).Rollback
23 - (*mime/multipart.Form).RemoveAll
24 - os.Remove
25 - os.RemoveAll
26 - (net/http.ResponseWriter).Write
27 - (*encoding/json.Encoder).Encode
28 - (github.com/yuin/goldmark/util.BufWriter).WriteString
29 - (github.com/gliderlabs/ssh.Session).Exit
30 - io.Copy
31 - io.WriteString
32 - fmt.Fprintf
33 gosec:
34 excludes:
35 - G104 # errcheck covers unchecked errors
36 - G115 # int conversions are byte packing and bounded lengths
37 - G120 # bodies are already capped by http.MaxBytesReader in bodyLimit
38 - G124 # Secure is set from BASE_URL; theme/sort cookies must not be HttpOnly
39 - G202 # table names are compile-time constants, values are bound
40 - G204 # running git with request args is the core of this program
41 - G301 # world-readable data dir is intended
42 - G304 # paths are built from validated repo names
43 - G306 # avatars and artifacts are served publicly
44 - G702 # taint analysis: same as G204
45 - G703 # taint analysis: same as G304
46 - G706 # log injection: log lines are for the operator
47 - G710 # redirect targets are built from validated repo names
48 exclusions:
49 rules:
50 - path: _test\.go
51 linters: [gosec, errcheck, noctx, bodyclose]
52 - path: internal/web/views/
53 text: "ST1001" # gomponents is written with a dot import
54 - path: internal/ci/
55 linters: [bodyclose] # doJSON and putArchive close the body before returning
56 - path: internal/web/(ci|git)\.go
57 text: "G705" # SVG badge from a fixed enum; git pkt-line bytes are not HTML
58
59formatters:
60 enable:
61 - gofumpt
62 settings:
63 gofumpt:
64 module-path: hearthforge
65 extra:
66 group-params: true
67