Current templates: safe.directory, golangci-lint v2.14.0, fetch-depth 0, the policy's last stage (closes #50)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
Brings keyfunc to the current sneak/prompts templates: REPO_POLICIES.md and .golangci.yml are the template copies, the lint phase runs golangci-lint v2.14.0 on the template digest (its one new finding fixed), and .dockerignore gains the template line for submodule configs. The stage that compiles keyfunc marks /src safe for git, so a context sent as a tar stream still stamps the tag or short commit. The last stage is now a development environment, as the policy asks of a non-server repo: run the tool as docker run IMAGE keyfunc .... The CI checkout fetches tags. Deviation: .gitea/workflows/check.yml differs from the template copy by fetch-depth: 0, which REPO_POLICIES.md requires. Model: opus-5-5
This commit was merged in pull request #56.
This commit is contained in:
+27
-29
@@ -1,11 +1,11 @@
|
||||
# The lint phase, the test phase and the build. script/lint and
|
||||
# script/test each build one phase alone; a plain `docker build .` builds
|
||||
# both, because the build stage copies a file from each. Formatting is
|
||||
# checked on the host by script/fmt-check, not here.
|
||||
# The lint phase, the test phase and a development environment.
|
||||
# script/lint and script/test each build one phase alone; a plain
|
||||
# `docker build .` builds both, because the last stage copies a file from
|
||||
# each. Formatting is checked on the host by script/fmt-check, not here.
|
||||
|
||||
# Lint phase
|
||||
# golangci/golangci-lint:v2.12.2, 2026-09-07
|
||||
FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
|
||||
# golangci/golangci-lint:v2.14.0, 2026-10-04
|
||||
FROM golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f AS lint
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
@@ -16,13 +16,12 @@ COPY . .
|
||||
|
||||
RUN golangci-lint run --config .golangci.yml ./...
|
||||
|
||||
# Test phase
|
||||
# golang:1.26-alpine, 2026-09-07. It carries Go 1.26.8, the version
|
||||
# script/bootstrap installs on the host; change both together.
|
||||
FROM golang@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS test
|
||||
|
||||
# -race needs cgo, and cgo needs a C toolchain.
|
||||
RUN apk add --no-cache gcc musl-dev
|
||||
# Test phase. -race needs cgo and so a C compiler, which the Debian Go
|
||||
# image ships.
|
||||
# golang:1.26.8-trixie, 2026-10-04. It carries Go 1.26.8, the version
|
||||
# script/bootstrap installs on the host; change both together, and the
|
||||
# same image in the last stage.
|
||||
FROM golang@sha256:eae2aaa6add2936cbf350dd0d2628b363461542f0c4b3c0b558957e0f2997379 AS test
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
@@ -35,21 +34,27 @@ RUN go test -timeout 90s -race -cover ./... || \
|
||||
{ echo "--- Rerunning with -v for details ---"; \
|
||||
go test -timeout 90s -race -v ./...; exit 1; }
|
||||
|
||||
# Build stage. Nothing is wanted from either phase above; the copies
|
||||
# are what make BuildKit build them first, so this stage cannot run
|
||||
# unless lint and test passed.
|
||||
# golang:1.26-alpine, 2026-09-07
|
||||
FROM golang@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS builder
|
||||
# Development environment, and the last stage: a plain `docker build .`
|
||||
# builds this one. It holds the source tree in /src, what
|
||||
# script/bootstrap installs, and keyfunc built from that tree on the
|
||||
# PATH. Nothing is wanted from either phase above; the copies are what
|
||||
# make BuildKit build them first, so this stage cannot run unless lint
|
||||
# and test passed.
|
||||
# golang:1.26.8-trixie, 2026-10-04
|
||||
FROM golang@sha256:eae2aaa6add2936cbf350dd0d2628b363461542f0c4b3c0b558957e0f2997379
|
||||
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
COPY --from=test /src/go.sum /dev/null
|
||||
|
||||
RUN apk add --no-cache make git
|
||||
# A tar-stream context keeps the sender's file owners, which git refuses.
|
||||
RUN git config --system --add safe.directory /src
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
# script/bootstrap needs only script/ and the dependency manifests.
|
||||
COPY script/ script/
|
||||
COPY go.mod go.sum package.json yarn.lock ./
|
||||
RUN script/bootstrap
|
||||
|
||||
COPY . .
|
||||
|
||||
@@ -64,11 +69,4 @@ RUN version="${VERSION:-$(git describe --tags --always || echo dev)}"; \
|
||||
echo "no version could be derived although the build context carries .git" >&2; \
|
||||
exit 1; \
|
||||
fi; \
|
||||
make build VERSION="$version"
|
||||
|
||||
# alpine:3.23, 2026-09-07
|
||||
FROM alpine@sha256:fd791d74b68913cbb027c6546007b3f0d3bc45125f797758156952bc2d6daf40
|
||||
|
||||
COPY --from=builder /src/keyfunc /usr/local/bin/keyfunc
|
||||
|
||||
ENTRYPOINT ["keyfunc"]
|
||||
make build VERSION="$version" && mv keyfunc /usr/local/bin/keyfunc
|
||||
|
||||
Reference in New Issue
Block a user