All checks were successful
check / check (push) Successful in 36s
`script/bootstrap` guarded its pinned `go install` calls with `missing()`, which only tests whether a binary is on `PATH`. On any machine that already had some `golangci-lint`, the install was skipped and the commit pin had no effect: a v1.x binary cannot parse this repo's v2-schema `.golangci.yml`, and a different v2.x can silently disagree with CI. The same reasoning made the v2.12.2 pin bump inert on every already-provisioned machine. Install both pinned tools unconditionally. `go install` at a fixed commit ref is idempotent and cheap with a warm module cache, so skipping it saved nothing. The `missing()` presence check is kept for `git`, `make`, and `go`, which really are system-package presence checks. Also warn when `PATH` resolves either tool somewhere other than the directory `go install` writes to, since a shadowing copy earlier on `PATH` is what `make lint` and `make fmt` would actually run. This is a warning, not a failure: the remedy is the user's `PATH`. The pins themselves are unchanged and still match the Dockerfile.