A bare `docker build .` keyed `make fmt-check-go`, `make lint`, the
prettier check, and `make test` on the build context, so on an unchanged
tree every check layer was a cache hit: the build exited 0 in under a
second having run none of them.
Add `ARG CHECK_EPOCH` immediately above the first check RUN in all three
check stages (lint, mdfmt, builder), and have script/cibuild pass a fresh
`--build-arg CHECK_EPOCH` each run. The changing value busts the cache from
that point down, while `go mod download` and `yarn install` above it stay
cached, so the build does not regress to cold. The false claim in
script/cibuild's header comment is corrected.
Running the checks for real surfaces the pre-existing intermittent
internal/cli test timeout (the gpg-subprocess flake in #62 / #67); that
defect is out of scope here.
Model: opus-4-8
Adds .prettierrc and .prettierignore, a single script/prettier entrypoint shared by fmt and fmt-check so the two cannot drift, and prettier 3.9.6 pinned by yarn.lock integrity hash.
Markdown formatting is now gated in the authoritative Docker build via a new mdfmt stage, since the golangci-lint image has no node. REPO_POLICIES.md is ignored so local tooling cannot drift it from upstream.
Removes the || true that made the previous prettier invocation unable to fail.