check / check (push) Successful in 53s
.dockerignore left out .git, so make build inside the image fell back to "dev". The build context now carries .git, without its config, which can hold a credential in the remote URL. The build stage takes the VERSION build argument when one is given, otherwise git describe --tags --always, and fails if the context carries .git and no version comes out. Model: opus-5-5
39 lines
1.3 KiB
Docker
39 lines
1.3 KiB
Docker
# The formatting check, the tests and the build. Linting is not here:
|
|
# it runs in its own pinned image, see Dockerfile.lint and script/lint,
|
|
# which script/cibuild runs before this file.
|
|
|
|
# golang:1.26-alpine, 2026-09-07
|
|
FROM golang@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS builder
|
|
|
|
RUN apk add --no-cache make git
|
|
|
|
WORKDIR /src
|
|
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
COPY . .
|
|
|
|
RUN make fmt-check
|
|
RUN make test
|
|
|
|
# The version stamped into the binary: the VERSION build argument when one
|
|
# is given, otherwise `git describe --tags --always` of the .git in the
|
|
# build context. A context that carries .git and still yields no version
|
|
# fails the build; with neither, as from a source tarball, it is "dev".
|
|
ARG VERSION
|
|
RUN version="${VERSION:-$(git describe --tags --always || echo dev)}"; \
|
|
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
|
|
[ "$version" = unknown ]; }; then \
|
|
echo "no version could be derived although the build context carries .git" >&2; \
|
|
exit 1; \
|
|
fi; \
|
|
make build VERSION="$version"
|
|
|
|
# alpine:3.23, 2026-09-07
|
|
FROM alpine@sha256:fd791d74b68913cbb027c6546007b3f0d3bc45125f797758156952bc2d6daf40
|
|
|
|
COPY --from=builder /src/keyfunc /usr/local/bin/keyfunc
|
|
|
|
ENTRYPOINT ["keyfunc"]
|