All checks were successful
check / check (push) Successful in 1m17s
golangci-lint is no longer installed or run on the host. script/lint is now a thin wrapper that builds the new root Dockerfile.lint, which COPYs the repo into the digest-pinned golangci/golangci-lint:v2.12.2 image and lints as a build step, so a successful build is a clean lint. This works even where the docker daemon is remote and bind mounts are impossible. Dockerfile.lint is split into a deps stage (base image, go mod download) and a lint stage (source copy, linter run). script/lint passes --no-cache-filter=lint so the lint stage executes on every invocation: caching is explicitly waived for linting, and a cached build lints nothing. The deps stage stays cached and no global cache invalidation is performed. --progress=plain keeps the linter's own output visible. golangci-lint config verify is deliberately omitted: it fetches its JSON schema over a live, unpinned HTTPS call, which would make linting network-dependent and defeat hash-pinning. script/bootstrap no longer installs golangci-lint and warns instead when docker is absent. The goimports install stays, since script/fmt and script/fmt-check still run it on the host. The root Dockerfile ran make check in its builder stage, which would now recurse into script/lint and shell out to docker build with no daemon available. It gains its own lint stage on the same pinned image, invoked directly, with the builder depending on it via COPY --from=lint and running make fmt-check, make test and make build.
28 lines
1.0 KiB
Docker
28 lines
1.0 KiB
Docker
# Lint-only image: used by script/lint. golangci-lint is never run on
|
|
# the host — the repo is COPYed into the build context and the linter
|
|
# runs as a build step, so a successful build IS a clean lint. This
|
|
# also works where the docker daemon is remote and bind mounts are
|
|
# impossible.
|
|
#
|
|
# `golangci-lint config verify` is deliberately NOT run here: it
|
|
# fetches its JSON schema over a live, unpinned HTTPS call, which would
|
|
# make linting network-dependent and defeat hash-pinning.
|
|
#
|
|
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-10
|
|
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS deps
|
|
|
|
WORKDIR /src
|
|
|
|
# Dependencies first, so this stage stays cached across lint runs.
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
# Everything below is invalidated on every run by the
|
|
# --no-cache-filter=lint that script/lint passes: caching is explicitly
|
|
# waived for linting, and a cached build lints nothing.
|
|
FROM deps AS lint
|
|
|
|
COPY . .
|
|
|
|
RUN golangci-lint run --config .golangci.yml ./...
|