From bb1f298af6e40b4aa1aab7b34c181bfa31343b3d Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Tue, 6 Oct 2026 08:33:32 +0000 Subject: [PATCH] chore(sync): synced file(s) with cplieger/ci --- .golangci.yaml | 19 ++++++++----------- cliff.toml | 2 +- scripts/collect-licenses.sh | 6 +++--- scripts/repin-sha.sh | 1 - tests/image-smoke.sh | 3 +-- 5 files changed, 13 insertions(+), 18 deletions(-) diff --git a/.golangci.yaml b/.golangci.yaml index dd77c94..f004145 100644 --- a/.golangci.yaml +++ b/.golangci.yaml @@ -84,8 +84,7 @@ linters: presets: # `comments` preset removed: revive's `exported` (every exported symbol # needs a doc comment starting with its name) and `package-comments` - # (every package needs a doc comment) are now enforced org-wide. - # All consumer repos were updated before this change was propagated. + # (every package needs a doc comment) are enforced. - std-error-handling - common-false-positives - legacy @@ -97,14 +96,12 @@ linters: # (gocyclo + gocognit). Both over-fire on idiomatic Go test code: a # thorough table-driven / property / fuzz test is a loop + t.Run closures # + per-case assertion guards, which gocognit's nesting model scores high - # without that being a smell. A 2026-06 audit put clean gold-standard - # libraries' flagship tests at cognitive 36-72 (atomicfile TestPendingFile - # is 72) and ~320 test funcs org-wide over 15; gating those would force - # ~320 //nolint or the splitting of cohesive table tests, degrading the - # suites. golangci also can't set a test-only threshold (min-complexity is - # global), so the prod gate of 15 can't coexist with a lenient test bar. - # Test complexity is judged in context instead: the test-review agent's - # smell catalog (Eager Test, Conditional Test Logic) plus human review. + # without that being a smell: clean table tests score cognitive 36-72, + # and gating them would force a //nolint or the splitting of cohesive + # table tests. golangci also can't set a test-only threshold + # (min-complexity is global), so the prod gate of 15 can't coexist with a + # lenient test bar. Test complexity is judged in review instead (Eager + # Test, Conditional Test Logic). - path: _test\.go linters: - dupl @@ -186,7 +183,7 @@ formatters: # builds one identical string ("G702: Command injection via taint analysis") # for every site and the processor keeps three of them. # -# Measured 2026-08-27: a corpus where standalone gosec reported 15 G702 +# Measured: a corpus where standalone gosec reported 15 G702 # findings reported 3 through golangci-lint, and which 3 survived depended on # processing order — which is also what made a `//nolint:gosec` directive on a # taint finding fail `nolintlint` as "unused" on some runs and not others. diff --git a/cliff.toml b/cliff.toml index 8eda21d..ab0b868 100644 --- a/cliff.toml +++ b/cliff.toml @@ -43,7 +43,7 @@ header = "" # author's indent depth decided whether a table survived (2 spaces became # mush, 6 spaces became a code block) with nothing telling them which they # picked. Unquoted, a fenced block in the commit footer reaches the reader as -# a fenced block. Authoring rules for footers are in git-commits.md. +# a fenced block. # # 3. `set_global` is required, and an attribute filter cannot replace it. # breaking_description falls back to the SUBJECT when a commit has no diff --git a/scripts/collect-licenses.sh b/scripts/collect-licenses.sh index 2111a0a..d376f5a 100755 --- a/scripts/collect-licenses.sh +++ b/scripts/collect-licenses.sh @@ -1,9 +1,9 @@ #!/bin/sh # Synced from cplieger/ci/configs/collect-licenses.sh. Change it there. -# Copy every linked Go module's license files into the /usr/share/licenses tree of -# attribution.md section 4. usage: collect-licenses.sh --name IMAGE [--out DIR] [--src DIR] [PACKAGE ...] +# Copy every linked Go module's license files into the image's /usr/share/licenses +# tree. usage: collect-licenses.sh --name IMAGE [--out DIR] [--src DIR] [PACKAGE ...] # A module with no license file fails the build rather than being skipped, because a -# missing text is a section 4(a) breach and the fix is a human decision. +# missing notice is a redistribution breach and the fix is a human decision. set -eu OUT=/out/usr/share/licenses diff --git a/scripts/repin-sha.sh b/scripts/repin-sha.sh index 3fc8659..a210d68 100644 --- a/scripts/repin-sha.sh +++ b/scripts/repin-sha.sh @@ -2,7 +2,6 @@ # Synced from cplieger/ci/configs/repin-sha.sh. Change it there. # Recompute a Dockerfile sha256 integrity pin after Renovate moved its version # literal, run from postUpgradeTasks because no datasource publishes a sha256. -# Marker convention and enrollment: ci-renovate.md, "Automated sha-pin recompute". # A marker it cannot honour exits non-zero rather than skipping, because a silent # miss reproduces the stale-pin build failure the pin exists to catch. set -eu diff --git a/tests/image-smoke.sh b/tests/image-smoke.sh index 242b585..e78c2f7 100644 --- a/tests/image-smoke.sh +++ b/tests/image-smoke.sh @@ -3,8 +3,7 @@ # Runtime image smoke-test harness: start the assembled image, wait for the # container's own HEALTHCHECK to report healthy, fail fast on an early exit, dump the # container log tail only on failure. Per-app knobs and hooks come from -# tests/image-smoke.conf beside this script; smoke-tests.md "Pattern B" documents -# every knob, every hook and what each tier proves. +# tests/image-smoke.conf beside this script. set -eu IMG="${1:?usage: image-smoke.sh }"