Visitar URL original
build: upgrade golangci-lint to v2.14.0 by SamMorrowDrums · Pull Request #3380 · github/github-mcp-server · GitHub
Skip to content

build: upgrade golangci-lint to v2.14.0 - #3380

Merged
SamMorrowDrums merged 1 commit into
mainfrom
sammorrowdrums-golangci-lint-2-14-upgrade
Oct 2, 2026
Merged

SamMorrowDrums merged 1 commit into
mainfrom
sammorrowdrums-golangci-lint-2-14-upgrade

Conversation

@SamMorrowDrums

Copy link
Copy Markdown
Collaborator

Summary

Upgrade all golangci-lint pins from v2.9.0 to v2.14.0, the latest stable 2.x release, and resolve new findings without changing tool names, schemas, behavior, or outputs. Lint and race tests pass on Go 1.26.8 and Go 1.27.1.

Why

Follow-up to #3370, which deferred this upgrade due to findings in existing code. v2.14.0 reads Go 1.27 export data successfully, so the old documented workaround is obsolete.

What changed

  • Pin v2.14.0 in script/lint, the lint workflow, and contributor guidance; refresh cached local linter binaries when their version differs from the pin.
  • Apply equivalent modernization fixes, add narrow justified suppressions, and remove obsolete Go 1.27 compatibility guidance.

Default-output baseline runs reported 28 findings due to repeated-issue caps. Uncapped runs (--max-issues-per-linter 0 --max-same-issues 0) found 36 findings, identical on both requested toolchains:

Linter Rule Go 1.26.8 Go 1.27.1 Resolution
gosec G101 7 7 Narrow literal-scoped suppressions in token extraction, PAT scope and scope challenge tests: synthetic fixtures cannot authenticate; values and behavior preserved.
gosec G117 2 2 Line-scoped suppressions for intentional secret-scanning alert serialization: existing security_events scope requirements and private-untrusted IFC labels remain intact.
gosec G602 1 1 Line-scoped suppression documents the resolver invariant: exactly one field per input name in order, or an error, proving the index is in bounds.
gosec G705 2 2 Line-scoped suppressions in ETag/user-agent test servers: intentional echoes verify isolation; no browser consumes these responses.
gosec G710 1 1 Line-scoped suppression in fake OAuth server: redirects to the test client's callback, not external user input.
modernize errorsastype 12 12 Equivalent errors.AsType checks for API and project resolution errors.
modernize reflecttypeassert 1 1 Equivalent reflect.TypeAssert for batch mutation results, retaining failed-assertion handling.
modernize atomictypes 4 4 Equivalent atomic.Int32 Add/Load operations in project batch and ETag tests.
modernize slicesbackward 1 1 slices.Backward preserves reverse middleware wrapping order.
staticcheck QF1012 4 4 fmt.Fprintf writes directly into strings.Builder; formatted text unchanged.
staticcheck SA1019 1 1 Line-scoped suppression: AST validator intentionally scans all source regardless of build tags without loading packages; switching to package loading changes its contract.

Rules disabled by this PR: none. .golangci.yml is unchanged; no whole linter is disabled. Existing exclusions/settings (including modernize newexpr and staticcheck QF1008/ST1000) remain unchanged. Each new nolint identifies the analyzer rule and concrete justification beside the statement or fixture.

MCP impact

  • No tool or API changes
  • Tool schema or behavior changed
  • New tool added

Names, schemas, outputs, toolsnaps, and behavior remain unchanged; implementation modernizations are equivalent.

Prompts tested (tool changes only)

  • N/A: no tool interface or behavior changes.

Security / limits

  • No security or limits impact
  • Auth / permissions considered
  • Data exposure, filtering, or token/size limits considered

No runtime authorization, filtering, security policies, or limits change. Suppressions are confined to proven invariants, intentional authorized outputs, and synthetic test fixtures.

Tool renaming

  • I am renaming tools as part of this PR (e.g. a part of a consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR

Names and aliases are unchanged.

Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.

Lint & tests

  • Linted locally with ./script/lint
  • Tested locally with ./script/test

Both scripts passed on both toolchains. Final lint commands used a session-local TMPDIR to isolate golangci-lint's lock from concurrent workspaces, without bypassing analysis or protections.

Exact command Result
GOTOOLCHAIN=go1.26.8 TMPDIR=/home/sammorrowdrums/.copilot/session-state/4d0e0c47-9ddb-4caf-820c-e946d7269905/files/tmp script/lint Passed: 0 issues
GOTOOLCHAIN=go1.26.8 script/test Passed: full go test -race ./...
GOTOOLCHAIN=go1.27.1 TMPDIR=/home/sammorrowdrums/.copilot/session-state/4d0e0c47-9ddb-4caf-820c-e946d7269905/files/tmp script/lint Passed: 0 issues; no export-data failure
GOTOOLCHAIN=go1.27.1 script/test Passed: full go test -race ./...
TMPDIR=/home/sammorrowdrums/.copilot/session-state/4d0e0c47-9ddb-4caf-820c-e946d7269905/files/tmp bin/golangci-lint run --max-issues-per-linter 0 --max-same-issues 0 Passed: 0 uncapped issues on Go 1.27.1
script/generate-docs Passed: generated documentation unchanged
git diff --exit-code -- README.md docs/remote-server.md docs/insiders-features.md docs/feature-flags.md docs/tool-renaming.md pkg/github/__toolsnaps__ .golangci.yml Passed: no generated-doc, toolsnap, or linter-config changes
git diff --check Passed

Live PAT-dependent e2e tests were not run; no live GitHub mutations were needed. Snapshot update mode was not used.

Docs

  • Not needed
  • Updated (README / docs / examples)

Updated CONTRIBUTING.md with the v2.14.0 pin and verified Go 1.26/1.27 support, removing obsolete export-data workaround guidance. Generated tool docs are unchanged.

Resolve new modernization findings and document narrow false-positive suppressions. Verify Go 1.26.8 and 1.27.1 support and remove obsolete export-data compatibility guidance. Refresh cached linter binaries when the repository pin changes.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@SamMorrowDrums
SamMorrowDrums marked this pull request as ready for review October 2, 2026 09:51
@SamMorrowDrums
SamMorrowDrums requested a review from a team as a code owner October 2, 2026 09:51
Copilot AI balanced review requested due to automatic review settings October 2, 2026 09:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The upgrade is internally consistent, suppressions are narrowly justified, and modernization changes preserve existing behavior.

Review effort: Balanced
Findings: None

What changed in this PR

Upgrades golangci-lint to v2.14.0 and resolves its new findings without changing MCP behavior.

Changes:

  • Updates CI, local tooling, and contributor documentation.
  • Modernizes error, reflection, atomic, iteration, and formatting idioms.
  • Adds narrowly scoped, justified linter suppressions.
File Description
script/​lint Updates the pin and refreshes stale binaries.
.github/​workflows/​lint.yml Updates the CI linter version.
CONTRIBUTING.md Documents current Go/linter compatibility.
pkg/​toolvalidation/​readonlyhint.go Justifies deprecated parser usage.
pkg/​inventory/​server_tool.go Modernizes reverse middleware iteration.
pkg/​http/​transport/​user_agent_test.go Suppresses intentional test echo finding.
pkg/​http/​transport/​etag_test.go Modernizes atomics and documents test echo.
pkg/​http/​middleware/​token_test.go Marks synthetic token fixtures.
pkg/​http/​middleware/​scope_challenge_test.go Marks synthetic OAuth fixture.
pkg/​http/​middleware/​pat_scope_test.go Marks synthetic PAT fixture.
pkg/​github/​secret_scanning.go Documents intentional authorized secret output.
pkg/​github/​projects.go Modernizes typed error matching.
pkg/​github/​projects_resolver.go Documents indexing invariant.
pkg/​github/​projects_batch.go Modernizes typed error matching.
pkg/​github/​projects_batch_test.go Uses typed atomic counters.
pkg/​github/​projects_batch_mutation.go Modernizes reflection assertion.
pkg/​github/​copilot.go Writes formatted output directly.
pkg/​github/​actions.go Modernizes accepted-error matching.
pkg/​errors/​error.go Modernizes rate-limit error matching.
pkg/​buffer/​buffer_test.go Writes formatted test data directly.
internal/​oauth/​testutil_test.go Documents intentional test redirect.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@SamMorrowDrums
SamMorrowDrums merged commit fbeba3c into main Oct 2, 2026
21 checks passed
@SamMorrowDrums
SamMorrowDrums deleted the sammorrowdrums-golangci-lint-2-14-upgrade branch October 2, 2026 10:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants