Linting has a file of its own, Dockerfile.lint. The policy has no separate lint file: lint and test are phases (stages) of the one Dockerfile, and the final stage depends on both through COPY --from=lint /src/go.sum /dev/null and COPY --from=test /src/go.sum /dev/null, so a plain docker build . cannot pass with a red gate.
script/test runs go vet and go test on the host. The policy's script/test builds the test phase.
No docker build in script/ passes --no-cache, and script/cibuild builds untagged. The policy requires both on every build in script/: a cached check layer is a check that did not run.
script/cibuild runs the linter and then a bare docker build .. The policy's runs script/bootstrap, then script/check, then builds the image with the version computed on the host.
Work, on a branch cut from next, PR to next:
Replace REPO_POLICIES.md with the copy on the next branch of sneak/prompts (https://git.eeqj.de/sneak/prompts/raw/branch/next/prompts/REPO_POLICIES.md), unchanged. It comes from next, not main, because main still forbids git describe in a build stage, which sneak reversed on 2026-10-02 (#35) and this repo already follows.
Dockerfile: a lint phase on the pinned golangci/golangci-lint image (the digest Dockerfile.lint uses now) running golangci-lint run --config .golangci.yml ./...; a test phase on the pinned Go image running the tests with the policy's verbose rerun on failure (if -race needs a C toolchain there, add it with apk add); the build stage depends on both through the two COPY --from= lines and no longer runs make fmt-check or make test. The version stamping from #35 stays as it is.
Delete Dockerfile.lint.
script/lint, script/test, script/docker and script/cibuild: byte-identical copies of the same files on the next branch of sneak/prompts (https://git.eeqj.de/sneak/prompts/raw/branch/next/script/<name>).
Every comment, and the README Entrypoints section, describe what the scripts now do; nothing mentions Dockerfile.lint any more.
Definition of done
Dockerfile.lint is gone; REPO_POLICIES.md and the four scripts equal the sneak/promptsnext copies.
A deliberate lint finding, and separately a deliberate failing test (neither committed), each make make check, script/cibuild and a plain docker build . fail.
make check and script/cibuild pass on a fresh clone; the image's --version still shows the tag or short commit.
Model: opus-5-5
`REPO_POLICIES.md` here is the copy of 2026-08-19. The current policy (https://git.eeqj.de/sneak/prompts/src/branch/next/prompts/REPO_POLICIES.md, 2026-10-02) changed how the gates run, and keyfunc does not follow it:
- Linting has a file of its own, `Dockerfile.lint`. The policy has no separate lint file: lint and test are phases (stages) of the one `Dockerfile`, and the final stage depends on both through `COPY --from=lint /src/go.sum /dev/null` and `COPY --from=test /src/go.sum /dev/null`, so a plain `docker build .` cannot pass with a red gate.
- `script/test` runs `go vet` and `go test` on the host. The policy's `script/test` builds the `test` phase.
- No `docker build` in `script/` passes `--no-cache`, and `script/cibuild` builds untagged. The policy requires both on every build in `script/`: a cached check layer is a check that did not run.
- `script/cibuild` runs the linter and then a bare `docker build .`. The policy's runs `script/bootstrap`, then `script/check`, then builds the image with the version computed on the host.
Work, on a branch cut from `next`, PR to `next`:
- Replace `REPO_POLICIES.md` with the copy on the `next` branch of `sneak/prompts` (https://git.eeqj.de/sneak/prompts/raw/branch/next/prompts/REPO_POLICIES.md), unchanged. It comes from `next`, not `main`, because `main` still forbids `git describe` in a build stage, which sneak reversed on 2026-10-02 (https://git.eeqj.de/sneak/keyfunc/issues/35) and this repo already follows.
- `Dockerfile`: a `lint` phase on the pinned `golangci/golangci-lint` image (the digest `Dockerfile.lint` uses now) running `golangci-lint run --config .golangci.yml ./...`; a `test` phase on the pinned Go image running the tests with the policy's verbose rerun on failure (if `-race` needs a C toolchain there, add it with `apk add`); the build stage depends on both through the two `COPY --from=` lines and no longer runs `make fmt-check` or `make test`. The version stamping from https://git.eeqj.de/sneak/keyfunc/issues/35 stays as it is.
- Delete `Dockerfile.lint`.
- `script/lint`, `script/test`, `script/docker` and `script/cibuild`: byte-identical copies of the same files on the `next` branch of `sneak/prompts` (`https://git.eeqj.de/sneak/prompts/raw/branch/next/script/<name>`).
- Every comment, and the README Entrypoints section, describe what the scripts now do; nothing mentions `Dockerfile.lint` any more.
## Definition of done
- `Dockerfile.lint` is gone; `REPO_POLICIES.md` and the four scripts equal the `sneak/prompts` `next` copies.
- A deliberate lint finding, and separately a deliberate failing test (neither committed), each make `make check`, `script/cibuild` and a plain `docker build .` fail.
- `make check` and `script/cibuild` pass on a fresh clone; the image's `--version` still shows the tag or short commit.
Model: opus-5-5
clawbot
self-assigned this 2026-10-03 14:11:31 +02:00
Built in #43: lint and test are now phases of the Dockerfile that the image build depends on, Dockerfile.lint is gone, and REPO_POLICIES.md and the four scripts are the copies from the next branch of sneak/prompts.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/keyfunc/pulls/43: lint and test are now phases of the `Dockerfile` that the image build depends on, `Dockerfile.lint` is gone, and `REPO_POLICIES.md` and the four scripts are the copies from the `next` branch of `sneak/prompts`.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
REPO_POLICIES.mdhere is the copy of 2026-08-19. The current policy (https://git.eeqj.de/sneak/prompts/src/branch/next/prompts/REPO_POLICIES.md, 2026-10-02) changed how the gates run, and keyfunc does not follow it:Dockerfile.lint. The policy has no separate lint file: lint and test are phases (stages) of the oneDockerfile, and the final stage depends on both throughCOPY --from=lint /src/go.sum /dev/nullandCOPY --from=test /src/go.sum /dev/null, so a plaindocker build .cannot pass with a red gate.script/testrunsgo vetandgo teston the host. The policy'sscript/testbuilds thetestphase.docker buildinscript/passes--no-cache, andscript/cibuildbuilds untagged. The policy requires both on every build inscript/: a cached check layer is a check that did not run.script/cibuildruns the linter and then a baredocker build .. The policy's runsscript/bootstrap, thenscript/check, then builds the image with the version computed on the host.Work, on a branch cut from
next, PR tonext:REPO_POLICIES.mdwith the copy on thenextbranch ofsneak/prompts(https://git.eeqj.de/sneak/prompts/raw/branch/next/prompts/REPO_POLICIES.md), unchanged. It comes fromnext, notmain, becausemainstill forbidsgit describein a build stage, which sneak reversed on 2026-10-02 (#35) and this repo already follows.Dockerfile: alintphase on the pinnedgolangci/golangci-lintimage (the digestDockerfile.lintuses now) runninggolangci-lint run --config .golangci.yml ./...; atestphase on the pinned Go image running the tests with the policy's verbose rerun on failure (if-raceneeds a C toolchain there, add it withapk add); the build stage depends on both through the twoCOPY --from=lines and no longer runsmake fmt-checkormake test. The version stamping from #35 stays as it is.Dockerfile.lint.script/lint,script/test,script/dockerandscript/cibuild: byte-identical copies of the same files on thenextbranch ofsneak/prompts(https://git.eeqj.de/sneak/prompts/raw/branch/next/script/<name>).Dockerfile.lintany more.Definition of done
Dockerfile.lintis gone;REPO_POLICIES.mdand the four scripts equal thesneak/promptsnextcopies.make check,script/cibuildand a plaindocker build .fail.make checkandscript/cibuildpass on a fresh clone; the image's--versionstill shows the tag or short commit.Model: opus-5-5
Built in #43: lint and test are now phases of the
Dockerfilethat the image build depends on,Dockerfile.lintis gone, andREPO_POLICIES.mdand the four scripts are the copies from thenextbranch ofsneak/prompts.Model: opus-5-5