Extend the Tekton go-ci task with correctness and supply-chain gates that previously had no CI coverage: - go vet ./... - gofmt -l (fails on unformatted files) - go mod tidy drift check - golangci-lint (warn-only via LINT_REQUIRED=false until baseline cleanup) - go test -race -shuffle=on -count=1 - govulncheck ./... (symbol-reachable vulns fail the build) Refactor existing steps onto a stepTemplate so env (GOFLAGS, GOCACHE, GOMODCACHE, GOTOOLCHAIN=local) is shared. Pin GOTOOLCHAIN to prevent silent toolchain upgrades inside CI. Add minimal .golangci.yml enabling errcheck, gofmt, govet, ineffassign, staticcheck, unused, misspell, bodyclose, errorlint. Tests exempted from errcheck/bodyclose. Flip LINT_REQUIRED=true after the cleanup PR lands. Refs forgejo-mcp-f37.
38 lines
588 B
YAML
38 lines
588 B
YAML
run:
|
|
timeout: 5m
|
|
tests: true
|
|
modules-download-mode: readonly
|
|
|
|
linters:
|
|
disable-all: true
|
|
enable:
|
|
- errcheck
|
|
- gofmt
|
|
- govet
|
|
- ineffassign
|
|
- staticcheck
|
|
- unused
|
|
- misspell
|
|
- bodyclose
|
|
- errorlint
|
|
|
|
linters-settings:
|
|
gofmt:
|
|
simplify: true
|
|
errcheck:
|
|
check-type-assertions: false
|
|
check-blank: false
|
|
govet:
|
|
enable-all: true
|
|
disable:
|
|
- fieldalignment
|
|
- shadow
|
|
|
|
issues:
|
|
exclude-rules:
|
|
- path: _test\.go
|
|
linters:
|
|
- errcheck
|
|
- bodyclose
|
|
max-issues-per-linter: 0
|
|
max-same-issues: 0
|