From 6163f265e19121ed24521f903e271d999e9403af Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Fri, 2 Oct 2026 03:04:50 +0000 Subject: [PATCH] Stamp the git tag or short commit in a plain docker build (closes #35) .dockerignore left out .git, so make build inside the image fell back to "dev". The build context now carries .git, without its config, which can hold a credential in the remote URL. The build stage takes the VERSION build argument when one is given, otherwise git describe --tags --always, and fails if the context carries .git and no version comes out. Model: opus-5-5 --- .dockerignore | 3 ++- Dockerfile | 14 +++++++++++++- 2 files changed, 15 insertions(+), 2 deletions(-) diff --git a/.dockerignore b/.dockerignore index 9d848e1..9aacf28 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,3 +1,4 @@ -.git +# .git is sent so the build can stamp the version, without its config. +.git/config .gitea /keyfunc diff --git a/Dockerfile b/Dockerfile index e48ab65..fcea34f 100644 --- a/Dockerfile +++ b/Dockerfile @@ -16,7 +16,19 @@ COPY . . RUN make fmt-check RUN make test -RUN make build + +# The version stamped into the binary: the VERSION build argument when one +# is given, otherwise `git describe --tags --always` of the .git in the +# build context. A context that carries .git and still yields no version +# fails the build; with neither, as from a source tarball, it is "dev". +ARG VERSION +RUN version="${VERSION:-$(git describe --tags --always || echo dev)}"; \ + if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \ + [ "$version" = unknown ]; }; then \ + echo "no version could be derived although the build context carries .git" >&2; \ + exit 1; \ + fi; \ + make build VERSION="$version" # alpine:3.23, 2026-09-07 FROM alpine@sha256:fd791d74b68913cbb027c6546007b3f0d3bc45125f797758156952bc2d6daf40