Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
# Request review from the repository owner for all changes.
* @markus621
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest
strategy:
matrix:
go: [ '1.23.6' ]
go: [ '1.26' ]
steps:
- uses: actions/checkout@v3

Expand Down
217 changes: 37 additions & 180 deletions .golangci.yml
Original file line number Diff line number Diff line change
@@ -1,202 +1,61 @@
version: "2"

run:
go: "1.22"
concurrency: 4
go: "1.26"
timeout: 5m
tests: false
issues-exit-code: 1
modules-download-mode: readonly
allow-parallel-runners: true

issues:
exclude-use-default: false
max-issues-per-linter: 100
max-same-issues: 4
max-issues-per-linter: 0
max-same-issues: 0
new: false
exclude-files:
- ".+_test.go"
exclude-dirs:
- "vendor$"
fix: false

output:
formats:
- format: line-number
sort-results: true
text:
print-linter-name: true
print-issued-lines: true

linters-settings:
govet:
check-shadowing: true
enable:
- asmdecl
- assign
- atomic
- atomicalign
- bools
- buildtag
- cgocall
- composites
- copylocks
- deepequalerrors
- errorsas
- findcall
- framepointer
- httpresponse
- ifaceassert
- loopclosure
- lostcancel
- nilfunc
- nilness
- printf
- reflectvaluecompare
- shadow
- shift
- sigchanyzer
- sortslice
- stdmethods
- stringintconv
- structtag
- testinggoroutine
- tests
- unmarshal
- unreachable
- unsafeptr
- unusedresult
- unusedwrite
disable:
- fieldalignment
gofmt:
simplify: true
errcheck:
check-type-assertions: true
check-blank: true
gocyclo:
min-complexity: 30
misspell:
locale: US
prealloc:
simple: true
range-loops: true
for-loops: true
unparam:
check-exported: false
gci:
skip-generated: true
custom-order: false
gosec:
includes:
- G101 # Look for hard coded credentials
- G102 # Bind to all interfaces
- G103 # Audit the use of unsafe block
- G104 # Audit errors not checked
- G106 # Audit the use of ssh.InsecureIgnoreHostKey
- G107 # Url provided to HTTP request as taint input
- G108 # Profiling endpoint automatically exposed on /debug/pprof
- G109 # Potential Integer overflow made by strconv.Atoi result conversion to int16/32
- G110 # Potential DoS vulnerability via decompression bomb
- G111 # Potential directory traversal
- G112 # Potential slowloris attack
- G113 # Usage of Rat.SetString in math/big with an overflow (CVE-2022-23772)
- G114 # Use of net/http serve function that has no support for setting timeouts
- G201 # SQL query construction using format string
- G202 # SQL query construction using string concatenation
- G203 # Use of unescaped data in HTML templates
- G204 # Audit use of command execution
- G301 # Poor file permissions used when creating a directory
- G302 # Poor file permissions used with chmod
- G303 # Creating tempfile using a predictable path
- G304 # File path provided as taint input
- G305 # File traversal when extracting zip/tar archive
- G306 # Poor file permissions used when writing to a new file
- G307 # Deferring a method which returns an error
- G401 # Detect the usage of DES, RC4, MD5 or SHA1
- G402 # Look for bad TLS connection settings
- G403 # Ensure minimum RSA key length of 2048 bits
- G404 # Insecure random number source (rand)
- G501 # Import blocklist: crypto/md5
- G502 # Import blocklist: crypto/des
- G503 # Import blocklist: crypto/rc4
- G504 # Import blocklist: net/http/cgi
- G505 # Import blocklist: crypto/sha1
- G601 # Implicit memory aliasing of items from a range statement
excludes:
- G101 # Look for hard coded credentials
- G102 # Bind to all interfaces
- G103 # Audit the use of unsafe block
- G104 # Audit errors not checked
- G106 # Audit the use of ssh.InsecureIgnoreHostKey
- G107 # Url provided to HTTP request as taint input
- G108 # Profiling endpoint automatically exposed on /debug/pprof
- G109 # Potential Integer overflow made by strconv.Atoi result conversion to int16/32
- G110 # Potential DoS vulnerability via decompression bomb
- G111 # Potential directory traversal
- G112 # Potential slowloris attack
- G113 # Usage of Rat.SetString in math/big with an overflow (CVE-2022-23772)
- G114 # Use of net/http serve function that has no support for setting timeouts
- G201 # SQL query construction using format string
- G202 # SQL query construction using string concatenation
- G203 # Use of unescaped data in HTML templates
- G204 # Audit use of command execution
- G301 # Poor file permissions used when creating a directory
- G302 # Poor file permissions used with chmod
- G303 # Creating tempfile using a predictable path
- G304 # File path provided as taint input
- G305 # File traversal when extracting zip/tar archive
- G306 # Poor file permissions used when writing to a new file
- G307 # Deferring a method which returns an error
- G401 # Detect the usage of DES, RC4, MD5 or SHA1
- G402 # Look for bad TLS connection settings
- G403 # Ensure minimum RSA key length of 2048 bits
- G404 # Insecure random number source (rand)
- G501 # Import blocklist: crypto/md5
- G502 # Import blocklist: crypto/des
- G503 # Import blocklist: crypto/rc4
- G504 # Import blocklist: net/http/cgi
- G505 # Import blocklist: crypto/sha1
- G601 # Implicit memory aliasing of items from a range statement
exclude-generated: true
severity: medium
confidence: medium
concurrency: 12
config:
global:
nosec: true
"#nosec": "#my-custom-nosec"
show-ignored: true
audit: true
G101:
pattern: "(?i)passwd|pass|password|pwd|secret|token|pw|apiKey|bearer|cred"
ignore_entropy: false
entropy_threshold: "80.0"
per_char_threshold: "3.0"
truncate: "32"
G104:
fmt:
- Fscanf
G111:
pattern: "http\\.Dir\\(\"\\/\"\\)|http\\.Dir\\('\\/'\\)"
G301: "0750"
G302: "0600"
G306: "0600"

lll:
line-length: 130
tab-width: 1
staticcheck:
go: "1.15"
# SAxxxx checks in https://staticcheck.io/docs/configuration/options/#checks
# Default: ["*"]
checks: [ "*", "-SA1019" ]
formatters:
exclusions:
paths:
- vendors/
enable:
- gofmt
- goimports

linters:
disable-all: true
settings:
staticcheck:
checks:
- all
- -S1023
- -ST1000
- -ST1003
- -ST1020
gosec:
excludes:
- G104
- G115
- G301
- G304
- G306
- G501
- G505
exclusions:
paths:
- vendors/
default: none
enable:
- govet
- gofmt
- errcheck
- misspell
- gocyclo
- ineffassign
- goimports
- nakedret
- unparam
- unused
- prealloc
Expand All @@ -207,5 +66,3 @@ linters:
- errorlint
- bodyclose
- gosec
- lll
fast: false
42 changes: 42 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
# Agent instructions

## Project map

- `golang/` contains the Go-language fluent API, Go formatter, and Go syntax policy in `golang/config.go`.
- `typescript/` contains the TypeScript and TSX fluent API and language policy.
- `python/` contains the Python 3.10+ fluent API, built-in type builders, and language policy.
- `types/` defines the public `Token` interface.
- `internal/gen/` walks token values and applies language-neutral layout rules to semantic token styles.
- `internal/models/` implements reusable token renderers. `internal/config/` defines the language policy contract; language-specific rules belong in the corresponding language package, never as literals or branches in `internal/`.
- `README.md` links the language-specific API guides in `golang/`, `typescript/`, and `python/`. Keep examples consistent with each adapter’s exported constructors.

## Working in this repository

- Work from the repository root. The module path is `go.osspkg.com/gogen` and `go.mod` requires Go 1.26.
- Preserve the boundary between language packages and reusable `internal` packages. Keep keyword inventories, identifier rules, literal quoting, operator classification, and comment styles in the language package config.
- Extend `internal/config.Config` only with language-neutral capabilities needed by multiple language adapters. Do not add branches for Go (or another target language) to `internal/gen` or `internal/models`.
- Token implementations satisfy `types.Token` by rendering to an `io.Writer`; propagate writer and render errors.
- `golang.Render` formats output by default. `SetRawMode` and `SetDefaultMode` change package-wide Go rendering behavior; account for that shared state when changing Go rendering code. TypeScript and Python render readable source directly, without formatters. Python targets 3.10+ and indents suites with four spaces.
- Each adapter’s `ID` and `Op` validate against its own language rules. Update focused examples or tests when changing validation or exported constructors.

## Persistent project memory

Use the Chroma collection `chat_gogen_memory` for durable repository context.

- Before querying, adding, updating, or deleting memory, ensure the collection exists. Call `chroma_list_collections`; if it is missing, create exactly `chat_gogen_memory` with the default embedding configuration. Do not ask for permission to create it.
- For non-trivial implementation, debugging, architecture, API, or infrastructure work, query the collection with a concise semantic description of the task before making important decisions.
- If a query fails because the collection is missing, list collections, create it if needed, and retry once. For other memory failures, continue from repository evidence and do not invent retrieved information.
- After non-trivial work, store durable decisions or lessons that are likely to help future work. Query for related entries first; update an existing entry when refining a decision and add a new one only when it is distinct.
- Keep one concise, self-contained fact per document. Do not store transcripts, routine command output, facts directly recoverable from source or docs, speculation, or secrets.
- Treat memory as supplemental. Explicit instructions, current source and tests, and current documentation take precedence over it.

## Validation commands

Run these from the repository root:

- `make tests` runs the repository test task through `goppy`.
- `make lint` runs the configured lint task through `goppy`.
- `make build` runs the configured amd64 build through `goppy`.
- `make ci` is the GitHub Actions workflow and runs the pre-commit targets, including license, lint, tests, and build.

`make ci` also runs `make install`, which installs `goppy@latest` and invokes `goppy setup-lib`. This may require network access and affect local setup; inspect `git status` after running it. CI is configured for Go 1.26 in `.github/workflows/ci.yml`.
20 changes: 20 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# Contributing

## Prerequisites

- Go 1.26 or newer
- `goppy` for the repository's Makefile tasks

## Checks

Run checks from the repository root:

```sh
make tests
make lint
make build
```

Before opening a pull request, run the relevant checks and include the user-visible behavior and validation results in the description. Keep changes focused and add regression tests for behavior changes.

`make ci` runs the same workflow used by GitHub Actions. It also installs `goppy@latest` and invokes `goppy setup-lib`, which may require network access and modify local setup.
6 changes: 3 additions & 3 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ SHELL=/bin/bash

.PHONY: install
install:
go install go.osspkg.com/goppy/v2/cmd/goppy@latest
go install go.osspkg.com/goppy/v3/cmd/goppy@latest
goppy setup-lib

.PHONY: lint
Expand All @@ -24,8 +24,8 @@ tests:
goppy test

.PHONY: pre-commit
pre-commit: install license lint tests build
pre-commit: license lint tests build

.PHONY: ci
ci: pre-commit
ci: install pre-commit

Loading
Loading