Skip to content

chore: promote dev to main (top-down dep tree sweep)#5

Merged
Snider merged 4 commits intomainfrom
dev
Apr 30, 2026
Merged

chore: promote dev to main (top-down dep tree sweep)#5
Snider merged 4 commits intomainfrom
dev

Conversation

@Snider
Copy link
Copy Markdown
Contributor

@Snider Snider commented Apr 30, 2026

Routine dev→main promotion as part of the cross-repo top-down dep tree sweep. Local dev contains all main content plus current sonar polish + restructure work (v0.14.0).

Snider added 4 commits April 30, 2026 12:30
…submodules

Lift Go module into go/ subtree for cross-language repo symmetry (matches
core/api v0.12.0 shape). Module path stays dappco.re/go/go-scm — consumers
see no change. Adds go.work + external/<deps> submodules for dev workspace
mode; CI uses GOWORK=off (already set in .woodpecker.yml).
Production fixes (10 files): cmd/{collect,forge,gitea,scm}/main.go,
collect/bitcointalk.go, jobrunner/journal.go,
internal/ax/stringsx/stringsx.go, marketplace/builder.go,
pkg/api/provider.go, repos/service.go.

Test files skipped per brief — 5 findings remain
(internal/ax/osx/osx_test.go × 2 errcheck, agentci_test SA1012,
collect_test.go × 2 SA1012, jsonx_test SA1026).
Mirrors api shape: .github/workflows/ci.yml runs test+coverage (Codecov),
golangci-lint --tests=false, and sonarcloud-scan-action to
dappcore_go-scm. README gets the badge block (CI / quality gate / cov /
security / maintainability / reliability / smells / NCLOC / pkg.go.dev /
license).

GOPROXY=direct GOSUMDB=off env in workflow to dodge the proxy.golang.org
stale-zip pattern that broke api's first run.

Internal Woodpecker pipeline at ci.lthn.sh continues unchanged.
5.5 sonar lane on go-scm — addresses 177 outstanding code smells.

Bulk pattern: S1192 duplicated-string-literal extracts ("agentci.X",
"collect.Y", etc.) lifted to package-level constants so error keys are
authored once. Several S138/S3776 cognitive-complexity hot spots in
collect/excavate.go and forge/* split into helper functions; behaviour
preserved (verified by go test -count=1 -short ./... clean).

Follow-up to v0.13.0 (post-restructure) sonar polish. No exported API
changes; constant names are deliberately verbose so the duplication
they replaced remains greppable from the new symbol.

Closes Mantis #1214 (go-scm portion).
@Snider Snider merged commit f19ed19 into main Apr 30, 2026
6 checks passed
@sonarqubecloud
Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
3 Security Hotspots
4.0% Duplication on New Code (required ≤ 3%)

See analysis details on SonarQube Cloud

@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 30, 2026

Welcome to Codecov 🎉

Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests.

ℹ️ You can also turn on project coverage checks and project coverage reporting on Pull Request comment

Thanks for integrating Codecov - We've got you covered ☂️

@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant