Stamp the git tag or short commit in a plain docker build (closes #35)
check / check (push) Successful in 1m6s

.dockerignore left out .git, so make build inside the image fell back to
"dev". The build context now carries .git, without its config, which can
hold a credential in the remote URL. The build stage takes the VERSION
build argument when one is given, otherwise git describe --tags --always,
and fails if the context carries .git and no version comes out.

Model: opus-5-5
This commit was merged in pull request #36.
This commit is contained in:
2026-10-02 06:12:05 +02:00
parent dd14677145
commit 7f7fe33cd6
2 changed files with 15 additions and 2 deletions
+2 -1
View File
@@ -1,3 +1,4 @@
.git # .git is sent so the build can stamp the version, without its config.
.git/config
.gitea .gitea
/keyfunc /keyfunc
+13 -1
View File
@@ -16,7 +16,19 @@ COPY . .
RUN make fmt-check RUN make fmt-check
RUN make test RUN make test
RUN make build
# The version stamped into the binary: the VERSION build argument when one
# is given, otherwise `git describe --tags --always` of the .git in the
# build context. A context that carries .git and still yields no version
# fails the build; with neither, as from a source tarball, it is "dev".
ARG VERSION
RUN version="${VERSION:-$(git describe --tags --always || echo dev)}"; \
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
[ "$version" = unknown ]; }; then \
echo "no version could be derived although the build context carries .git" >&2; \
exit 1; \
fi; \
make build VERSION="$version"
# alpine:3.23, 2026-09-07 # alpine:3.23, 2026-09-07
FROM alpine@sha256:fd791d74b68913cbb027c6546007b3f0d3bc45125f797758156952bc2d6daf40 FROM alpine@sha256:fd791d74b68913cbb027c6546007b3f0d3bc45125f797758156952bc2d6daf40