Follow-up to #1339. After the errcheck wave is fixed (branch fix/ci-main-red, errcheck now 0), the CI "Lint Code" job will still be red: 2,769 non-errcheck findings remain repo-wide under the strict .golangci.yml v2 config that landed 2026-06-09 (commit b54f06d), which is what turned main's CI red on 2026-06-11.
Breakdown (local run, golangci-lint 2.11.4; counts match live CI run 28541474929 annotations almost exactly, small govet/gosec deltas likely from the CI-pinned 2.10.1):
- godot 1187
- misspell 604 (note: repo convention uses "cancelled" spelling matching DB status vocabulary; those need targeted per-line justification or an ignore-words config decision, NOT blind respelling)
- gocritic 446
- govet 365 (mostly fieldalignment)
- unparam 36
- noctx 34
- errorlint 29
- gosec 23 (review individually; severity error in config)
- staticcheck 20
- others 25
Per the no-masking-CI-debt directive: fix for real in batches (per-linter batch PRs work well; godot and fieldalignment are highly mechanical), no only-new-issues, no blanket nolint. Suggest sequence: gosec + errorlint + noctx first (correctness/security value), then staticcheck/unparam/gocritic, then the mechanical godot/misspell/fieldalignment sweeps.
Also noted while in there: the "Security Scanning" job failure on main should clear once the pgx v5.9.2 bump from #1339 merges; re-check after merge for any additional CVEs.
Follow-up to #1339. After the errcheck wave is fixed (branch
fix/ci-main-red, errcheck now 0), the CI "Lint Code" job will still be red: 2,769 non-errcheck findings remain repo-wide under the strict.golangci.ymlv2 config that landed 2026-06-09 (commit b54f06d), which is what turned main's CI red on 2026-06-11.Breakdown (local run, golangci-lint 2.11.4; counts match live CI run 28541474929 annotations almost exactly, small govet/gosec deltas likely from the CI-pinned 2.10.1):
Per the no-masking-CI-debt directive: fix for real in batches (per-linter batch PRs work well; godot and fieldalignment are highly mechanical), no
only-new-issues, no blanket nolint. Suggest sequence: gosec + errorlint + noctx first (correctness/security value), then staticcheck/unparam/gocritic, then the mechanical godot/misspell/fieldalignment sweeps.Also noted while in there: the "Security Scanning" job failure on main should clear once the pgx v5.9.2 bump from #1339 merges; re-check after merge for any additional CVEs.