Dockerfile has a lint phase on the pinned golangci-lint image (the digest Dockerfile.lint used) and a test phase on the pinned Go image, running the tests with -race and the verbose rerun on failure. The build stage copies go.sum from each phase, so a plain docker build . builds both and fails when either fails. It no longer runs make fmt-check or make test; the version stamping is unchanged.
Dockerfile.lint is deleted.
REPO_POLICIES.md, script/lint, script/test, script/docker and script/cibuild are byte-identical to the copies on the next branch of sneak/prompts.
The script/bootstrap comment and missing-Docker message, and the README Entrypoints section, describe what the scripts now do. The issue's line leaves the README TODO list.
Not visible in the diff:
go vet no longer runs as a step of its own; the linter runs it (govet is among the linters .golangci.yml enables).
Formatting is no longer checked in the image build, only on the host by script/fmt-check, which script/check and so script/cibuild run.
make test now needs Docker on the host, not Go. script/cibuild still needs Go there, for script/bootstrap and script/fmt-check.
Disclosures:
Judgement call: the test phase installs gcc and musl-dev with an unpinned apk add, as the issue allows; the alpine Go image refuses -race without cgo.
Judgement call: the test command is the policy's canonical Dockerfile form, without -count=1; a build stage holds no earlier test result to replay.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/keyfunc/issues/38.
- `Dockerfile` has a `lint` phase on the pinned golangci-lint image (the digest `Dockerfile.lint` used) and a `test` phase on the pinned Go image, running the tests with `-race` and the verbose rerun on failure. The build stage copies `go.sum` from each phase, so a plain `docker build .` builds both and fails when either fails. It no longer runs `make fmt-check` or `make test`; the version stamping is unchanged.
- `Dockerfile.lint` is deleted.
- `REPO_POLICIES.md`, `script/lint`, `script/test`, `script/docker` and `script/cibuild` are byte-identical to the copies on the `next` branch of `sneak/prompts`.
- The `script/bootstrap` comment and missing-Docker message, and the README Entrypoints section, describe what the scripts now do. The issue's line leaves the README TODO list.
Not visible in the diff:
- `go vet` no longer runs as a step of its own; the linter runs it (`govet` is among the linters `.golangci.yml` enables).
- Formatting is no longer checked in the image build, only on the host by `script/fmt-check`, which `script/check` and so `script/cibuild` run.
- `make test` now needs Docker on the host, not Go. `script/cibuild` still needs Go there, for `script/bootstrap` and `script/fmt-check`.
Disclosures:
- Judgement call: the test phase installs `gcc` and `musl-dev` with an unpinned `apk add`, as the issue allows; the alpine Go image refuses `-race` without cgo.
- Judgement call: the test command is the policy's canonical `Dockerfile` form, without `-count=1`; a build stage holds no earlier test result to replay.
Model: opus-5-5
clawbot
self-assigned this 2026-10-04 01:49:47 +02:00
Linting and testing are now the lint and test phases of the one
Dockerfile, and the build stage copies a file from each, so a plain
docker build . cannot pass while either fails. Dockerfile.lint is gone.
REPO_POLICIES.md, script/lint, script/test, script/docker and
script/cibuild are the current copies from the next branch of
sneak/prompts: every docker build there is uncached and tagged,
script/test builds the test phase instead of running go vet and go test
on the host, and script/cibuild bootstraps, runs script/check, then
builds the image with the version from the host. The test phase
installs gcc and musl-dev because -race needs cgo. The version stamping
is unchanged. The issue's line leaves the README TODO list.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #38.
Dockerfilehas alintphase on the pinned golangci-lint image (the digestDockerfile.lintused) and atestphase on the pinned Go image, running the tests with-raceand the verbose rerun on failure. The build stage copiesgo.sumfrom each phase, so a plaindocker build .builds both and fails when either fails. It no longer runsmake fmt-checkormake test; the version stamping is unchanged.Dockerfile.lintis deleted.REPO_POLICIES.md,script/lint,script/test,script/dockerandscript/cibuildare byte-identical to the copies on thenextbranch ofsneak/prompts.script/bootstrapcomment and missing-Docker message, and the README Entrypoints section, describe what the scripts now do. The issue's line leaves the README TODO list.Not visible in the diff:
go vetno longer runs as a step of its own; the linter runs it (govetis among the linters.golangci.ymlenables).script/fmt-check, whichscript/checkand soscript/cibuildrun.make testnow needs Docker on the host, not Go.script/cibuildstill needs Go there, forscript/bootstrapandscript/fmt-check.Disclosures:
gccandmusl-devwith an unpinnedapk add, as the issue allows; the alpine Go image refuses-racewithout cgo.Dockerfileform, without-count=1; a build stage holds no earlier test result to replay.Model: opus-5-5
Review passed.
Model: opus-5-5