-
Notifications
You must be signed in to change notification settings - Fork 45
Expand file tree
/
Copy path.golangci.yml
More file actions
78 lines (78 loc) · 1.94 KB
/
Copy path.golangci.yml
File metadata and controls
78 lines (78 loc) · 1.94 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
version: "2"
output:
formats:
text:
path: stdout
linters:
default: none
enable:
- errcheck
- forbidigo
- gosec
- govet
- importas
- ineffassign
- misspell
- protogetter
- revive
- staticcheck
- thelper
- unconvert
- unused
- wastedassign
- whitespace
settings:
revive:
severity: warning
staticcheck:
# The golangci-lint default check set, minus the QF family: QF checks
# are editor refactoring suggestions, not problems.
checks:
[
"all",
"-ST1000",
"-ST1003",
"-ST1016",
"-ST1020",
"-ST1021",
"-ST1022",
"-QF*",
]
gosec:
# Only run SQL-injection rules. Revisit if specific risks emerge.
includes:
- G201 # SQL query construction using format string (fmt.Sprintf)
- G202 # SQL query construction using string concatenation
forbidigo:
# SQL safety.
analyze-types: false
forbid:
- pattern: 'goqu\.L\("[^"'']*''[^'']*\?[^'']*'''
msg: "Don't put ? inside a single-quoted string in goqu.L — breaks prepared mode. Use make_interval(secs => ?)-style functions instead."
- pattern: '\w+,\s*_,\s*err\s*[:=]+[^=]*\.ToSQL\(\)'
msg: "Don't discard params from ToSQL(); capture and pass via …Context(ctx, …, query, params...)."
- pattern: 'goqu\.From\('
msg: "Use dialect.From(...) not goqu.From(...). The latter uses goqu's default dialect (? placeholders) which PostgreSQL rejects in prepared mode."
exclusions:
generated: lax
presets:
- comments
- common-false-positives
- legacy
- std-error-handling
paths:
- third_party$
- builtin$
- examples$
severity:
default: error
formatters:
enable:
- gofmt
- goimports
exclusions:
generated: lax
paths:
- third_party$
- builtin$
- examples$