Pin the remaining developer tool installs (closes #68)
check / check (push) Failing after 2s

gofumpt was pinned only by its version tag. It is now a tool of a
separate module in tools/, so `go tool` builds it from source checked
against the hashes in tools/go.sum, and mfer's own module gains no
dependencies. script/prettier no longer falls back to a prettier on
PATH, and fails when node_modules holds a different version than
package.json pins. The bootstrap comment now says what --frozen-lockfile
really does, package.json drops its made-up version, and the golang
image comment names its exact version.

Model: opus-5-5
This commit is contained in:
2026-10-04 17:09:48 +00:00
parent d3394bd2a2
commit ef56eeeae0
8 changed files with 71 additions and 42 deletions
+2 -2
View File
@@ -10,7 +10,7 @@ COPY . .
# Go half of fmt-check only: this image has no node, so no prettier. The
# markdown half runs in the mdfmt stage below. The image has no gofumpt
# either; script/gofumpt builds the version it pins with `go run`.
# either; script/gofumpt builds the version tools/go.mod requires.
RUN script/gofumpt --check
# The linter directly, not `make lint`: script/lint builds this stage, and
# there is no docker inside this build.
@@ -31,7 +31,7 @@ COPY . .
RUN script/prettier --check
# Build stage — tests and compilation
# golang:1.23 (2026-03-14)
# golang:1.23.12, 2026-03-14
FROM golang@sha256:60deed95d3888cc5e4d9ff8a10c54e5edc008c6ae3fba6187be6fb592e19e8c0 AS builder
# Force BuildKit to run the lint and mdfmt stages by creating stage dependencies