`.dockerignore`, `.gitignore`, `.golangci.yml` and the workflow are their
copies at that commit. This repo's own entries are kept after the
canonical content: the anchored `/attrsum` binary, the Go entries in
`.gitignore`, and tabs for `*.go` in the new `.editorconfig`.
`REPO_POLICIES.md` is new. The workflow keeps `fetch-depth: 0`, which the
policies require of a repo that stamps a tag-derived version.
The lint phase moves to golangci-lint v2.14.0, which finds nothing in
the code. `script/fmt` now runs goimports with `go run` at its pinned
commit. A version-checked install by `script/bootstrap` would have to be
found on `PATH`, and the CI runner's `PATH` lacks Go's bin directory.
Model: opus-5-5
attrsum --version now prints the git tag or short commit. make build
stamps it with -X from git describe, and the Dockerfile takes the VERSION
build argument when given, otherwise git describe --tags --always on the
.git in the build context, failing if .git is present and no version
comes out. A new .dockerignore, the canonical one, keeps .git/config out
of the context, and also this repo's host-built /attrsum. CI checks out
full history so it sees the 1.0.0 tag and stamps what a full clone does.
script/docker is replaced with the canonical copy.
Model: opus-5-5