build: re-vendor canonical files from prompts dd4027b (closes #257)
check / check (push) Successful in 4m6s
check / check (push) Successful in 4m6s
The canonical files are fetched whole from sneak/prompts at dd4027b. Kept after the canonical content: the livednstest deny entry in .golangci.yml, /bin in .dockerignore, this repo's own .gitignore lines and a [*.go] tab section in .editorconfig. The workflow keeps its concurrency block and persist-credentials: false. Lint and test are phases of the Dockerfile (golangci-lint v2.14.0; tests on the Debian Go 1.25.7 image as an ordinary user, with the same flags); the build stage depends on both and stamps the version the canonical way. Dockerfile.lint is gone; the prettier stages of Dockerfile.fmt moved into the Dockerfile. Every scripted docker build passes --no-cache; script/cibuild bootstraps, runs script/check, then builds the image. script/fmt-check absorbs fmt-check-go and fmt-check-markdown. Model: opus-5-5
This commit was merged in pull request #259.
This commit is contained in:
+12
-17
@@ -1,28 +1,23 @@
|
||||
#!/bin/sh
|
||||
# script/lint: run the linter. golangci-lint is never installed or run
|
||||
# on the host: it runs via docker only, one way, everywhere. This
|
||||
# builds Dockerfile.lint, which COPYs the repo into the digest-pinned
|
||||
# golangci-lint image and lints as a build step, so a successful build
|
||||
# means a clean lint.
|
||||
# script/lint: run the linter. Linting is a phase of the Dockerfile and
|
||||
# this builds that phase alone; the linter is never installed or run on
|
||||
# a developer host, where a shared result cache and a host-global lock
|
||||
# make its answer untrustworthy.
|
||||
#
|
||||
# --no-cache-filter=lint forces the lint stage (source copy + linter
|
||||
# run) to execute on every invocation. Without it an unchanged tree
|
||||
# returns success in well under a second having linted nothing. The
|
||||
# deps stage (base image + go mod download) stays cached, and no global
|
||||
# cache invalidation is performed. --progress=plain keeps the linter's
|
||||
# own output visible.
|
||||
# The phase is not the last stage in the file, so it is built only when
|
||||
# --target names it. --no-cache because a cached lint layer is a lint
|
||||
# that did not run. The tag makes each build replace the previous image
|
||||
# instead of leaving a dangling one behind.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
docker build \
|
||||
--progress=plain \
|
||||
--no-cache-filter=lint \
|
||||
docker build --no-cache \
|
||||
--target lint \
|
||||
-f Dockerfile.lint \
|
||||
.
|
||||
-t "$("$SCRIPT_DIR/projectname")-lint" .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
Reference in New Issue
Block a user