Fix go-git Compilation and Import Ordering · Entire

Summary

The go-git bump (v6.0.0-alpha.4.0.20260521... → ...20260713100844-d5e9b9c7895b) added a protocol.Version parameter to transport.AdvertiseRefs. Its new signature:

func AdvertiseRefs(ctx context.Context, st storage.Storer, w io.Writer, service string, smart bool, version protocol.Version) error

Three test-only git-server helpers called the old 5-arg form. I fixed each by adding the protocol import and passing protocol.V0 (the classic v0/v1 info/refs advertisement these helpers serve, preserving prior behavior):

go build ./... and go vet ./... now pass, and the full test suite passes.

Note on the test failures you'd otherwise see: a batch of tests fail with cannot auto-sign commit: disable commit.gpgSign or register an ObjectSigner plugin (and the SSH shim test with agent refused operation). These are not caused by the bump — they reproduce identically on the pre-bump go.mod and stem from your global commit.gpgSign=true / gpg.format=ssh config leaking into go-git's in-memory commits. Running with an isolated git config (GIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_SYSTEM=/dev/null) makes the whole suite green.

The style hints flagged in integration_test.go (CutPrefix, min, slices.Contains) are pre-existing and unrelated — I left them alone.

What I did

The root cause: go-git's x/plugin registers xconfig.NewAuto() as the default ConfigLoader at init time, which reads the host's real ~/.gitconfig and /etc/gitconfig. That pulled commit.gpgSign=true into every go-git in-memory commit, and the real git binary in the SSH tests read it independently.

Rather than the go-git-only plugin override that internal/syncer was already using (which left the SSH test broken), I used a single mechanism that both go-git's loader and the git binary honor: GIT_CONFIG_GLOBAL/GIT_CONFIG_SYSTEM pointed at os.DevNull.

The remaining lint hints in integration_test.go/materialized_test.go (CutPrefix, min, slices.Contains) are pre-existing and unrelated — I left them untouched. Nothing is committed yet.