Repository navigation
build: upgrade golangci-lint to v2.14.0 - #3380
Merged
Merged
Conversation
Resolve new modernization findings and document narrow false-positive suppressions. Verify Go 1.26.8 and 1.27.1 support and remove obsolete export-data compatibility guidance. Refresh cached linter binaries when the repository pin changes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The upgrade is internally consistent, suppressions are narrowly justified, and modernization changes preserve existing behavior.
Review effort: Balanced
Findings: None
What changed in this PR
Upgrades golangci-lint to v2.14.0 and resolves its new findings without changing MCP behavior.
Changes:
- Updates CI, local tooling, and contributor documentation.
- Modernizes error, reflection, atomic, iteration, and formatting idioms.
- Adds narrowly scoped, justified linter suppressions.
| File | Description |
|---|---|
script/lint |
Updates the pin and refreshes stale binaries. |
.github/workflows/lint.yml |
Updates the CI linter version. |
CONTRIBUTING.md |
Documents current Go/linter compatibility. |
pkg/toolvalidation/readonlyhint.go |
Justifies deprecated parser usage. |
pkg/inventory/server_tool.go |
Modernizes reverse middleware iteration. |
pkg/http/transport/user_agent_test.go |
Suppresses intentional test echo finding. |
pkg/http/transport/etag_test.go |
Modernizes atomics and documents test echo. |
pkg/http/middleware/token_test.go |
Marks synthetic token fixtures. |
pkg/http/middleware/scope_challenge_test.go |
Marks synthetic OAuth fixture. |
pkg/http/middleware/pat_scope_test.go |
Marks synthetic PAT fixture. |
pkg/github/secret_scanning.go |
Documents intentional authorized secret output. |
pkg/github/projects.go |
Modernizes typed error matching. |
pkg/github/projects_resolver.go |
Documents indexing invariant. |
pkg/github/projects_batch.go |
Modernizes typed error matching. |
pkg/github/projects_batch_test.go |
Uses typed atomic counters. |
pkg/github/projects_batch_mutation.go |
Modernizes reflection assertion. |
pkg/github/copilot.go |
Writes formatted output directly. |
pkg/github/actions.go |
Modernizes accepted-error matching. |
pkg/errors/error.go |
Modernizes rate-limit error matching. |
pkg/buffer/buffer_test.go |
Writes formatted test data directly. |
internal/oauth/testutil_test.go |
Documents intentional test redirect. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Upgrade all golangci-lint pins from v2.9.0 to v2.14.0, the latest stable 2.x release, and resolve new findings without changing tool names, schemas, behavior, or outputs. Lint and race tests pass on Go 1.26.8 and Go 1.27.1.
Why
Follow-up to #3370, which deferred this upgrade due to findings in existing code. v2.14.0 reads Go 1.27 export data successfully, so the old documented workaround is obsolete.
What changed
script/lint, the lint workflow, and contributor guidance; refresh cached local linter binaries when their version differs from the pin.Default-output baseline runs reported 28 findings due to repeated-issue caps. Uncapped runs (
--max-issues-per-linter 0 --max-same-issues 0) found 36 findings, identical on both requested toolchains:security_eventsscope requirements and private-untrusted IFC labels remain intact.errors.AsTypechecks for API and project resolution errors.reflect.TypeAssertfor batch mutation results, retaining failed-assertion handling.atomic.Int32Add/Load operations in project batch and ETag tests.slices.Backwardpreserves reverse middleware wrapping order.fmt.Fprintfwrites directly into strings.Builder; formatted text unchanged.Rules disabled by this PR: none.
.golangci.ymlis unchanged; no whole linter is disabled. Existing exclusions/settings (including modernizenewexprand staticcheckQF1008/ST1000) remain unchanged. Each newnolintidentifies the analyzer rule and concrete justification beside the statement or fixture.MCP impact
Names, schemas, outputs, toolsnaps, and behavior remain unchanged; implementation modernizations are equivalent.
Prompts tested (tool changes only)
Security / limits
No runtime authorization, filtering, security policies, or limits change. Suppressions are confined to proven invariants, intentional authorized outputs, and synthetic test fixtures.
Tool renaming
deprecated_tool_aliases.goNames and aliases are unchanged.
Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.
Lint & tests
./script/lint./script/testBoth scripts passed on both toolchains. Final lint commands used a session-local TMPDIR to isolate golangci-lint's lock from concurrent workspaces, without bypassing analysis or protections.
GOTOOLCHAIN=go1.26.8 TMPDIR=/home/sammorrowdrums/.copilot/session-state/4d0e0c47-9ddb-4caf-820c-e946d7269905/files/tmp script/lintGOTOOLCHAIN=go1.26.8 script/testgo test -race ./...GOTOOLCHAIN=go1.27.1 TMPDIR=/home/sammorrowdrums/.copilot/session-state/4d0e0c47-9ddb-4caf-820c-e946d7269905/files/tmp script/lintGOTOOLCHAIN=go1.27.1 script/testgo test -race ./...TMPDIR=/home/sammorrowdrums/.copilot/session-state/4d0e0c47-9ddb-4caf-820c-e946d7269905/files/tmp bin/golangci-lint run --max-issues-per-linter 0 --max-same-issues 0script/generate-docsgit diff --exit-code -- README.md docs/remote-server.md docs/insiders-features.md docs/feature-flags.md docs/tool-renaming.md pkg/github/__toolsnaps__ .golangci.ymlgit diff --checkLive PAT-dependent e2e tests were not run; no live GitHub mutations were needed. Snapshot update mode was not used.
Docs
Updated CONTRIBUTING.md with the v2.14.0 pin and verified Go 1.26/1.27 support, removing obsolete export-data workaround guidance. Generated tool docs are unchanged.