Stamp the tag or short commit in a plain docker build (closes #112)
check / check (push) Waiting to run

.dockerignore now sends .git but not .git/config, which can hold a
credential and which git describe does not need. The build stage stamps
main.Gitrev from the VERSION build argument when one is given, otherwise
from git describe --tags --always, and fails if .git is present and no
version comes out. script/docker is replaced by the canonical copy,
which passes VERSION; bin/gitrev.sh uses --tags too, so every entrypoint
stamps the same value for a clean commit.

Model: opus-5-5
This commit is contained in:
2026-10-02 04:10:40 +00:00
parent 0deacfc7ed
commit cbcda41ac1
5 changed files with 96 additions and 6 deletions
+6
View File
@@ -24,6 +24,12 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
# Completed Steps
- 2026-10-02: a plain `docker build .` of a clone now stamps the tag or short
commit into `mfer version` instead of nothing: `.dockerignore` sends `.git`
(not `.git/config`), and the build stage takes the `VERSION` build argument,
otherwise `git describe --tags --always`, failing if `.git` is present and no
version comes out. `script/docker` is the canonical copy, which passes
`VERSION`; `bin/gitrev.sh` uses `--tags` too (#112)
- 2026-09-21: validate manifest entry paths on deserialize so untrusted `.mf`
files cannot make `Checker` stat or read outside `basePath` (#61)
- 2026-09-21: rewrote `script/test` to the canonical pattern (30s timeout,