`.dockerignore`, `.gitignore`, `.golangci.yml` and the workflow are their
copies at that commit. This repo's own entries are kept after the
canonical content: the anchored `/attrsum` binary, the Go entries in
`.gitignore`, and tabs for `*.go` in the new `.editorconfig`.
`REPO_POLICIES.md` is new. The workflow keeps `fetch-depth: 0`, which the
policies require of a repo that stamps a tag-derived version.
The lint phase moves to golangci-lint v2.14.0. `script/bootstrap`
installs goimports with `go install` at its pinned commit unless the
installed binary already has the pinned version, read with
`go version -m`. It and `script/fmt` put Go's bin directory on `PATH`
first, since the CI runner's `PATH` lacks it.
Model: opus-5-5
The Dockerfile gets a lint phase on the pinned golangci-lint v2.12.2
image and a test phase on the Debian Go image. The tests run as an
unprivileged user, because root reads a file with mode 0000 and the
permission test then fails. The build stage copies a file from each
phase, so no build finishes unless both pass, and it no longer runs
make check. script/lint and script/test each build their phase,
uncached and tagged; script/cibuild bootstraps, runs script/check, then
builds the image. script/bootstrap no longer installs golangci-lint.
README.md and TODO.md describe the new setup.
Model: opus-5-5
golangci-lint v2 ignores a top-level linters-settings block without a
warning, so limits such as the 88-column line length were never
applied. .golangci.yml is now the canonical copy from sneak/prompts,
verbatim, which keeps its settings under linters.settings and also
configures depguard and gomodguard_v2. golangci-lint is pinned at
v2.12.2 by commit in the Dockerfile and script/bootstrap. The long
lines in attrsum.go are rewrapped and one nolint directive moves to
its own line; behaviour is unchanged.
Model: opus-5-5
attrsum --version now prints the git tag or short commit. make build
stamps it with -X from git describe, and the Dockerfile takes the VERSION
build argument when given, otherwise git describe --tags --always on the
.git in the build context, failing if .git is present and no version
comes out. A new .dockerignore, the canonical one, keeps .git/config out
of the context, and also this repo's host-built /attrsum. CI checks out
full history so it sees the 1.0.0 tag and stamps what a full clone does.
script/docker is replaced with the canonical copy.
Model: opus-5-5
Add the standard STRTA scaffold, mirroring the conformant Go repos:
- script/ POSIX-sh entrypoints (bootstrap, setup, projectname, test,
lint, fmt, fmt-check, check, docker, cibuild, precommit,
install-precommit).
- Makefile rewritten as thin shims: .PHONY plus the nine standard
targets each delegating to script/NAME; repo-specific build, clean,
and try targets retained.
- .golangci.yml matching the org-standard Go lint config.
- Dockerfile whose build runs make check then make build, so the image
fails on any check failure.
- .gitea/workflows/check.yml running script/cibuild.
make fmt-check and make test are green. make check is not yet green
because of pre-existing lint findings in the application code, which
are out of scope for this scaffold change; hence refs (not closes).