### Code Review Findings

Review the code changes against the base branch 'main'. The merge base commit for this comparison is `368750cee35f31935640a34ad199e889fc60f1a8`. Run `git diff 368750cee35f31935640a34ad199e889fc60f1a8` to inspect the changes relative to main. Provide prioritized, actionable findings.

#### Findings:

1. **Title**: [P1] Run gofmt after deleting the EntireDB tests  
   **Body**: On any `mise run lint`/CI lint run, `gofmt -l -s .` reports this file and `internal/syncer/auth_test.go` because the deleted tail test blocks leave an extra blank line at EOF. The lint workflow will fail until these files are gofmt-formatted.  
   **Confidence Score**: 0.95  
   **Priority**: 1  
   **Code Location**:  
   - **Absolute File Path**: `/Users/soph/Work/entire/devenv/git-sync/internal/auth/auth_test.go`  
   - **Line Range**: {"start":535,"end":535}

#### Overall Correctness:

- **Status**: Patch is incorrect  
- **Explanation**: The code builds and tests pass locally, but the modified test files are not gofmt-formatted, which will fail the repository's lint workflow.  
- **Overall Confidence Score**: 0.93

### Code Changes:

**Remove the Entire DB credential-store integration**

`git-sync` carried a bespoke Entire credential path: `auth.Resolve` fell back to an active-user lookup in `~/.config/entire/hosts.json` plus a file/keyring token store and OAuth refresh-token handling (`client_id=entire-cli`). Nothing in the product produces that layout anymore. The mirror-pipeline worker, the only library consumer that talks to `entiredb`, supplies credentials directly at the transport layer (GitHub installation tokens + per-request entire-core repo-scoped bearers), and client-side `entire://` auth is owned by the separate `git-remote-entire` helper using the newer `contexts.json` model. So the lookup only ever read a store no current producer writes.

**Plan**: Drop `entiredb.go` and `tokenstore.go` and the `LookupEntireDBCredential` fallback; `auth.Resolve` now resolves explicit token/bearer credentials only and otherwise returns `nil` so the git credential helper is consulted on a 401, exactly as for any other remote. This also drops the `github.com/zalando/go-keyring` dependency and, with the file token store gone, removes the `syscall.Flock` usage that broke the Windows build (so the package now cross-compiles for Windows cleanly).

**Supersedes**: The `entiredb` token-refresh fix (#90) and the `tokenstore Windows flock fix (#92), both of which were polishing this now-deleted code.

**Co-Authored-By**: Claude Opus 4.8 (1M context) <noreply@anthropic.com>  
**Entire-Checkpoint**: `de15fe82f1f3+18/-1384`

**Link**: [View Commit](/content/gh/entireio/git-sync/commit/44f774ccd68586247a79984b60c0f453acce2c34/index.html)
