Move internalbridge under internal/ so it is truly unimportable

main

Commit

Soph3mo ago

internalbridge lived at the module root, so despite its name it was a public, importable package: external callers could construct an internalbridge.Config via SyncConfig/ProbeConfig and call Run/Probe directly, skipping the stable API's Validate() entirely. The stable types are aliases into it (type RefKind = internalbridge.RefKind ...), which also froze it into the v1 surface.

Move it to internal/internalbridge. The Go internal-package rule now bars any out-of-module importer (compiler-enforced), closing the Validate() bypass, while the root-package type aliases keep resolving for external users (an alias to an internal type stays usable through the alias). Package name is unchanged, so only the three in-module import paths move; no call sites change.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 3f11cafef6f1