Pin the remaining developer tool installs (closes #68)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
gofumpt was pinned only by its version tag. It is now a tool of a separate module in tools/, so `go tool` builds it from source checked against the hashes in tools/go.sum, and mfer's own module gains no dependencies. script/prettier no longer falls back to a prettier on PATH, and fails when node_modules holds a different version than package.json pins. The bootstrap comment now says what --frozen-lockfile really does, package.json drops its made-up version, and the golang image comment names its exact version. Model: opus-5-5
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
// The developer tools this repo runs with `go tool`, kept out of the mfer
|
||||
// module so they add nothing to what mfer's users download. `go tool` builds
|
||||
// exactly the source whose hashes go.sum here records.
|
||||
module sneak.berlin/go/mfer/tools
|
||||
|
||||
go 1.26.0
|
||||
|
||||
tool mvdan.cc/gofumpt
|
||||
|
||||
require (
|
||||
golang.org/x/mod v0.40.0 // indirect
|
||||
golang.org/x/sync v0.22.0 // indirect
|
||||
golang.org/x/tools v0.49.0 // indirect
|
||||
mvdan.cc/gofumpt v0.12.0 // indirect
|
||||
)
|
||||
Reference in New Issue
Block a user