.golangci.yml
⎇
Raw
1version: "2"
2
3linters:
4 default: none
5 enable:
6 - errcheck
7 - govet
8 - staticcheck
9 - unused
10 - ineffassign
11 - gosec
12 - bodyclose
13 - noctx
14 settings:
15 errcheck:
16 # Best-effort cleanup and response writes. A failure here has no useful
17 # handler; the caller already logs or returns the main error.
18 exclude-functions:
19 - (io.Closer).Close
20 - (*os.File).Close
21 - (*database/sql.Rows).Close
22 - (*archive/zip.ReadCloser).Close
23 - (*database/sql.Tx).Rollback
24 - os.Remove
25 - os.RemoveAll
26 - (net/http.ResponseWriter).Write
27 - (*encoding/json.Encoder).Encode
28 - io.Copy
29 - io.WriteString
30 - fmt.Fprintf
31 gosec:
32 excludes:
33 - G104 # errcheck covers unchecked errors
34 - G124 # cookies set HttpOnly and SameSite; Secure would break plain-HTTP self-hosting
35 - G203 # the only template.HTML is rendered template output, not user input
36 - G204 # running yt-dlp, ffmpeg and ffprobe with request args is the core of this program
37 - G301 # library and temp directories are meant to be world-readable
38 - G302 # the managed yt-dlp and deno binaries have to be executable
39 - G304 # paths come from LibraryService.resolveItemDir, which rejects escapes
40 - G702 # taint analysis: same as G204
41 - G703 # taint analysis: same as G304
42 - G706 # log injection: log lines are for the operator
43 - G710 # localReferer keeps only a local path, see its test
44 exclusions:
45 rules:
46 - path: _test\.go
47 linters: [gosec, errcheck, noctx, bodyclose]
48 # The repository layer is deliberately context-free: SQLite is local and
49 # every query is short. noctx still guards the outbound HTTP calls.
50 - path: internal/(repository|database)/
51 linters: [noctx]
52 # These error strings are the flash message shown to the user, so they are
53 # written as sentences on purpose.
54 - path: internal/handler/settings\.go
55 text: "ST1005"
56
57formatters:
58 enable:
59 - gofumpt
60 settings:
61 gofumpt:
62 module-path: vidarchive
63 extra:
64 group-params: true
65