- Add fmt-check target for gofmt format verification without modifying files
- Add hooks target to install pre-commit git hook
- Update check target to include fmt-check (check: fmt-check lint test)
- Remove redundant gofmt check from lint target (now in fmt-check)
- Add .PHONY declarations for all phony targets
- Update tools target to use go install
- Lint stage: golangci/golangci-lint:v1.64.8 (sha256-pinned)
Runs make fmt-check and make lint for fast feedback
- Build stage: golang:1.24-bookworm (sha256-pinned, matches go.mod 1.24.0)
COPY --from=lint forces BuildKit to run lint stage
Runs make test, then make build
- Runtime stage: debian:bookworm-slim (sha256-pinned)
- All base images updated from ancient versions to current
- Removed vendoring/source tarball (per CLAUDE.md: avoid vendoring)
All images sha256-pinned with version+date comments
✅
COPY --from=lint BuildKit dependency exists
✅
.golangci.yml not modified
✅
No test weakening
✅
Go version matches go.mod (1.24)
✅
fmt-check Makefile target added
✅
hooks Makefile target added
✅
CI workflow (.gitea/workflows/check.yml) added
✅
check target updated to fmt-check lint test
✅
docker build . passes
✅
Details
Dockerfile — Clean three-stage split:
Lint stage: Uses pre-built golangci/golangci-lint:v1.64.8 (sha256-pinned, dated 2025-03-17). Runs fmt-check and lint for fast feedback.
Build stage: Uses golang:1.24-bookworm (sha256-pinned). COPY --from=lint /src/go.sum /dev/null correctly forces BuildKit to execute the lint stage. Runs test then build.
Runtime stage: Uses debian:bookworm-slim (sha256-pinned). Minimal — just the binary, CA certs, and proper ENV syntax.
Makefile — fmt-check correctly uses gofmt -l without modification. lint no longer duplicates the gofmt check. hooks installs a pre-commit hook. .PHONY declarations added. tools modernized to go install.
CI — Simple docker build . on push to main and PRs. Correct.
Good cleanup: removed vendoring/source tarball, updated ENV syntax, removed stale go get commands.
- Pin actions/checkout to commit SHA (v4.2.2) to prevent tag mutation attacks
- Remove branch filters so CI runs on push to all branches, not just main
Pinned actions/checkout by commit SHA (11bd71901bbe5b1630ceea73d27597364c9af683, v4.2.2) — tags are mutable and an RCE vector
Removed branch filters on push/pull_request triggers — CI now runs on all branches, not just main
docker build . passes locally ✅
Only .gitea/workflows/check.yml was modified.
**Rework complete** — CI workflow fixes applied:
1. **Pinned `actions/checkout` by commit SHA** (`11bd71901bbe5b1630ceea73d27597364c9af683`, v4.2.2) — tags are mutable and an RCE vector
2. **Removed branch filters** on push/pull_request triggers — CI now runs on all branches, not just `main`
`docker build .` passes locally ✅
Only `.gitea/workflows/check.yml` was modified.
<!-- session: agent:sdlc-manager:subagent:2ba892e8-d97a-466d-aded-749d9e676ffc -->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #22
Changes
Makefile
fmt-checktarget: checks gofmt formatting without modifying fileshookstarget: installs pre-commit git hookchecktarget: now runsfmt-check lint testlinttarget (now infmt-check).PHONYdeclarations for all phony targetstoolstarget to usego installDockerfile
golangci/golangci-lint:v1.64.8(sha256-pinned)make fmt-checkandmake lintfor fast feedbackgolang:1.24-bookworm(sha256-pinned, matches go.mod 1.24.0)COPY --from=lintforces BuildKit to actually run the lint stagemake testthenmake builddebian:bookworm-slim(sha256-pinned)CI
.gitea/workflows/check.yml: runsdocker build .on push to main and PRsImage Versions
Verification
docker build .passes locally — all stages (lint, test, build) execute correctly.Review: PASS ✅
All requirements from issue #22 verified:
COPY --from=lintBuildKit dependency exists.golangci.ymlnot modifiedfmt-checkMakefile target addedhooksMakefile target added.gitea/workflows/check.yml) addedchecktarget updated tofmt-check lint testdocker build .passesDetails
Dockerfile — Clean three-stage split:
golangci/golangci-lint:v1.64.8(sha256-pinned, dated 2025-03-17). Runsfmt-checkandlintfor fast feedback.golang:1.24-bookworm(sha256-pinned).COPY --from=lint /src/go.sum /dev/nullcorrectly forces BuildKit to execute the lint stage. Runstestthenbuild.debian:bookworm-slim(sha256-pinned). Minimal — just the binary, CA certs, and proper ENV syntax.Makefile —
fmt-checkcorrectly usesgofmt -lwithout modification.lintno longer duplicates the gofmt check.hooksinstalls a pre-commit hook..PHONYdeclarations added.toolsmodernized togo install.CI — Simple
docker build .on push to main and PRs. Correct.Good cleanup: removed vendoring/source tarball, updated ENV syntax, removed stale
go getcommands.docker build .verified locally — all stages pass (lint, test, build).@clawbot REWORK. checks should run on all branches, not just main, and the
actions/checkoutimage is not pinned by hash like is required.Rework complete — CI workflow fixes applied:
actions/checkoutby commit SHA (11bd71901bbe5b1630ceea73d27597364c9af683, v4.2.2) — tags are mutable and an RCE vectormaindocker build .passes locally ✅Only
.gitea/workflows/check.ymlwas modified.