Compare commits

..

2 Commits

Author SHA1 Message Date
2d6ca4b815 trigger CI
All checks were successful
check / check (push) Successful in 1m29s
2026-03-03 06:02:57 +01:00
4482529f6a Split Dockerfile: pre-built golangci-lint stage for faster CI (#26)
Closes [#22](#22)

## Changes

### Makefile
- Added `fmt-check` target: checks gofmt formatting without modifying files
- Added `hooks` target: installs pre-commit git hook
- Updated `check` target: now runs `fmt-check lint test`
- Removed redundant gofmt check from `lint` target (now in `fmt-check`)
- Added `.PHONY` declarations for all phony targets
- Updated `tools` target to use `go install`

### Dockerfile
- **Lint stage**: Uses pre-built `golangci/golangci-lint:v1.64.8` (sha256-pinned)
  - Runs `make fmt-check` and `make lint` for fast feedback
- **Build stage**: Uses `golang:1.24-bookworm` (sha256-pinned, matches go.mod 1.24.0)
  - `COPY --from=lint` forces BuildKit to actually run the lint stage
  - Runs `make test` then `make build`
- **Runtime stage**: Uses `debian:bookworm-slim` (sha256-pinned)
- All base images updated from ancient/unpinned versions to current sha256-pinned images
- Removed vendoring/source tarball per CLAUDE.md policy

### CI
- Added `.gitea/workflows/check.yml`: runs `docker build .` on push to main and PRs

## Image Versions
| Stage | Image | Digest |
|-------|-------|--------|
| lint | golangci/golangci-lint:v1.64.8 | sha256:2987913e...5cb8 |
| build | golang:1.24-bookworm | sha256:1a6d4452...77ac |
| runtime | debian:bookworm-slim | sha256:74d56e39...4421 |

## Verification
`docker build .` passes locally — all stages (lint, test, build) execute correctly.

<!-- session: agent:sdlc-manager:subagent:bcf4d5ff-f487-4dcb-aa85-1c0e039bbb3b -->

Co-authored-by: clawbot <clawbot@noreply.git.eeqj.de>
Reviewed-on: #26
Co-authored-by: clawbot <clawbot@noreply.example.org>
Co-committed-by: clawbot <clawbot@noreply.example.org>
2026-03-02 21:11:17 +01:00
2 changed files with 2 additions and 3 deletions

View File

@@ -2,13 +2,11 @@ name: check
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- run: docker build .

View File

@@ -86,3 +86,4 @@ WTFPL (aka public domain):
0. You just DO WHAT THE FUCK YOU WANT TO.
```