Incomplete - do not merge. Preserved so the analysis is not lost.
The Dockerfile declares an ARG CHECK_EPOCH with no default, guards
against it being unset, and expands it into the RUN line so the check
layer is invalidated on every invocation while the script/bootstrap
toolchain layer above it still caches. script/cibuild generates a
per-invocation value.
Known incomplete:
- script/docker was never updated to pass CHECK_EPOCH, so `make docker`
would fail the guard. The Dockerfile header already claims it does.
That claim is currently false.
- Diverges from the canonical upstream shape tracked in prompts #26;
the intended next step was to simplify to match it rather than keep
the bespoke guard.
- No verification was run: neither the two-consecutive-runs proof nor
the deliberate-failure proof required by the issue.
Adopt the Scripts to Rule Them All standard for this Hugo site:
- script/ POSIX-sh entrypoints (bootstrap, setup, projectname, test,
lint, fmt, fmt-check, check, docker, cibuild, precommit,
install-precommit). The correctness check (test/lint) is a clean
`hugo --minify` production build; fmt/fmt-check run prettier over the
repo's own top-level markdown only, leaving content/ untouched.
- Makefile targets reduced to thin shims that call script/NAME, plus a
convenience serve target for `hugo server`.
- Dockerfile on a sha256-pinned alpine base that installs deps via
script/bootstrap and runs `make check`, so the image build fails on
any formatting or Hugo build error; .dockerignore added.
- .gitea/workflows/check.yml runs script/cibuild on push.
- README Entrypoints section documenting the scripts.