.golangci.yml
⎇
Raw
1version: "2"
2
3linters:
4 default: none
5 enable:
6 - errcheck
7 - govet
8 - staticcheck
9 - unused
10 - ineffassign
11 - gosec
12 - bodyclose
13 - noctx
14 settings:
15 errcheck:
16 # Best-effort cleanup and response writes. A failure here has no useful
17 # handler; the caller already logs or returns the main error.
18 exclude-functions:
19 - (io.Closer).Close
20 - (*os.File).Close
21 - (*database/sql.Rows).Close
22 - (*database/sql.Tx).Rollback
23 - os.Remove
24 - os.RemoveAll
25 - (net/http.ResponseWriter).Write
26 - (*encoding/json.Encoder).Encode
27 - io.Copy
28 - io.WriteString
29 - fmt.Fprintf
30 gosec:
31 excludes:
32 - G104 # errcheck covers unchecked errors
33 - G124 # cookies set HttpOnly and SameSite; Secure would break plain-HTTP self-hosting
34 - G203 # the only template.HTML is rendered template output, not user input
35 - G204 # running yt-dlp, ffmpeg and ffprobe with request args is the core of this program
36 - G301 # library and temp directories are meant to be world-readable
37 - G304 # paths come from LibraryService.resolveItemDir, which rejects escapes
38 - G702 # taint analysis: same as G204
39 - G703 # taint analysis: same as G304
40 - G706 # log injection: log lines are for the operator
41 - G710 # localReferer keeps only a local path, see its test
42 exclusions:
43 rules:
44 - path: _test\.go
45 linters: [gosec, errcheck, noctx, bodyclose]
46 # The repository layer is deliberately context-free: SQLite is local and
47 # every query is short. noctx still guards the outbound HTTP calls.
48 - path: internal/(repository|database)/
49 linters: [noctx]
50 # These error strings are the flash message shown to the user, so they are
51 # written as sentences on purpose.
52 - path: internal/handler/settings\.go
53 text: "ST1005"
54
55formatters:
56 enable:
57 - gofumpt
58 settings:
59 gofumpt:
60 module-path: vidarchive
61 extra:
62 group-params: true
63