A plain `docker build .`, which is how upaas builds, stamped `dev`:
`.dockerignore` left out `.git` and the builder declared
`ARG VERSION=dev`. `.dockerignore` now sends `.git` without
`.git/config`, which can hold a credential, and lists no tracked file,
which git in the build would count as deleted and mark `-dirty`.
`ARG VERSION` has no default. The Makefile takes a non-empty `VERSION`
from the command line or the environment, so a build arg still wins
(`script/docker` keeps passing one); otherwise `git describe` runs in
the builder. A new `make version` prints the version, and the builder
fails when the context carries `.git`, directory or file, and it comes
out empty, `dev` or `unknown`.
Model: opus-5-5
make fmt and make fmt-check now cover every Markdown file with prettier
(4-space tabs, proseWrap always), as template-app-go does: prettier is
pinned by package.json and yarn.lock and runs in a docker build on a
digest-pinned node image, never on the host. The check is forced to run
with --no-cache-filter, as script/lint is.
script/fmt-check is split into a Go half and a Markdown half because the
Dockerfile lint stage cannot run docker: that stage now runs the Go half
and script/cibuild runs the Markdown half after the build. *.md leaves
.dockerignore so documents reach the build context.
README.md, TESTING.md and TODO.md are reformatted by make fmt; apart from
the README Entrypoints entries, its make fmt line under Building and the
TODO entry, that diff is mechanical.
Model: opus-5-5