feat: add opt-in recommended check defaults - #66
Merged
Conversation
alxxjohn
marked this pull request as ready for review
July 27, 2026 15:57
alxxjohn
added a commit
that referenced
this pull request
Jul 27, 2026
🤖 I have created a release *beep* *boop* --- ## [1.3.0](v1.2.2...v1.3.0) (2026-07-27) ### Features * add abstraction quality checks ([fc5a7ec](fc5a7ec)) * add change safety diff detectors ([ebc2f80](ebc2f80)) * add change safety PR summary metrics ([5b10ecd](5b10ecd)) * add delivery governance checks ([eb1b803](eb1b803)) * add local quality precision rules ([dd75b79](dd75b79)) * add local quality precision rules ([00c493e](00c493e)) * add observability and operations checks ([3e8713c](3e8713c)) * add operability, design, and delivery governance checks ([#70](#70)) ([a52199a](a52199a)) * add opt-in recommended check defaults ([1680b21](1680b21)) * add opt-in recommended check defaults ([#66](#66)) ([67510e3](67510e3)) * add production readiness rule families ([d58e8eb](d58e8eb)) * Add production reliability and data-readiness checks across languages ([#67](#67)) ([c243ead](c243ead)) * add refused bequest smell detection ([053cb1a](053cb1a)) * add refused bequest smell detection ([#72](#72)) ([4423aa4](4423aa4)) * add structural smell quality rules ([eefd8bd](eefd8bd)) * change safety testability refactors ([#69](#69)) ([9081ad3](9081ad3)) * deepen code smell and maintainability precision checks ([#71](#71)) ([d554347](d554347)) * deepen reliability parity checks ([fc8d769](fc8d769)) * expand production readiness language coverage ([588bf19](588bf19)) * scaffold change safety checks ([0b313d9](0b313d9)) ### Bug Fixes * dogfood production readiness coverage ([1110f4f](1110f4f)) * restore change testability detectors ([88f6df0](88f6df0)) * satisfy strict lint for change safety ([311716c](311716c)) * satisfy strict lint for operability governance ([abc9fd1](abc9fd1)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR makes CodeGuard's recommended check-family defaults explicitly opt-in
while preserving existing behavior for live SDK and configuration consumers.
It also clarifies the default-policy contract, composes enterprise policy from
strict policy, improves validation coverage, and tunes duplicate-code
thresholds to reduce noisy findings across real repositories.
What changed
Opt-in recommended check policy
checks.use_recommended_defaults.checks.disabledfor explicit final-precedence exclusions.qualitydesignsecuritypromptsciperformanceandsupply_chainremain opt-in.contextandcontractsretain their existing scan-mode-aware behavior.checks.disabledare applied last and override both recommendedactivation and explicit section enablement.
Example:
Backward compatibility
use_recommended_defaultsis absent or false.remain available.
CheckConfigalias can affect rare unkeyed Go composite literals; keyed literals remain
the supported robust form.
Validation and defaults
checks.disabledentries.supply_chain.Profile design
release/automation requirements.
documentation.
Duplicate-code threshold tuning
The previous thresholds were aggressive enough to flag conventional
boilerplate and small incidental similarities across multiple repositories.
These values keep strict and AI-focused profiles more sensitive while reducing
pressure to introduce premature or overly generic abstractions.
SDK and documentation
ExampleConfig()andApplyDefaults().names, and profile independence.
repository-relative links.
Why
CodeGuard previously had several related notions of defaults: a complete
starter configuration, missing-field normalization, and policy profiles.
Because ordinary Go booleans cannot distinguish an omitted value from explicit
false after decoding, silently enabling existing check families would risk
changing behavior in live SDK integrations.
The new field provides a deliberate migration path: consumers opt into the
recommended baseline, retain existing behavior otherwise, and can explicitly
disable individual families with deterministic precedence.
The duplicate-code adjustment addresses a second real-world default-policy
issue: very small token thresholds frequently identify language idioms,
serializers, adapters, or test setup rather than abstractions that genuinely
share a reason to change.
Test strategy
Added and updated tests covering:
Verification
go test ./...— 15 packages passed, 0 failedgo vet ./...— passedmake fmt-check— passedmake codeguard-ci— completed with no failures; only existing repositorywarnings remain
git diff --check— clean