Files
attrsum/Dockerfile
T
clawbot 15f0c263c8
check / check (push) Successful in 3m27s
Make the golangci-lint settings take effect: v2 config layout, linter pinned at v2.12.2 (closes #10)
golangci-lint v2 ignores a top-level linters-settings block without a
warning, so limits such as the 88-column line length were never
applied. .golangci.yml is now the canonical copy from sneak/prompts,
verbatim, which keeps its settings under linters.settings and also
configures depguard and gomodguard_v2. golangci-lint is pinned at
v2.12.2 by commit in the Dockerfile and script/bootstrap. The long
lines in attrsum.go are rewrapped and one nolint directive moves to
its own line; behaviour is unchanged.

Model: opus-5-5
2026-10-06 00:00:51 +00:00

59 lines
2.1 KiB
Docker

# Build stage
# golang 1.25-alpine, 2026-02-28
FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4ced AS builder
RUN apk add --no-cache git make gcc musl-dev binutils-gold
# golangci-lint v2.12.2, 2026-10-05
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5
# goimports v0.42.0
RUN go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
# Run the checks as an unprivileged user. Root bypasses file mode bits, which
# would make the permission tests (expecting EACCES on a 0000 file) spuriously
# pass with no error. Caches live under /tmp (world-writable) so the user needs
# no home directory of its own.
ENV GOCACHE=/tmp/gocache
ENV XDG_CACHE_HOME=/tmp/xdgcache
RUN adduser -D -u 1000 builder && chown -R builder:builder /src /go
USER builder
# Run all checks - build fails if any check fails
RUN make check
# Build the binary (still as the unprivileged user: it owns /src, so git VCS
# stamping sees consistent ownership).
#
# The version stamped into the binary: the VERSION build argument when one
# is given, otherwise `git describe --tags --always` of the .git the build
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
# one, the short commit when no tag is reachable. A context that carries .git
# and still yields no version fails the build. With neither, as from a source
# tarball, the binary reports dev.
ARG VERSION
RUN version="${VERSION:-$(git describe --tags --always)}"; \
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
[ "$version" = unknown ]; }; then \
echo "version is '$version' although .git is present" >&2; \
exit 1; \
fi; \
make build VERSION="${version:-dev}"
# Runtime stage
# alpine 3.21, 2026-02-28
FROM alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
RUN apk add --no-cache ca-certificates tzdata
WORKDIR /app
COPY --from=builder /src/attrsum /app/attrsum
ENTRYPOINT ["/app/attrsum"]