Fetches .dockerignore, .editorconfig, the CI workflow, .gitignore,
.golangci.yml, .prettierignore, .prettierrc and REPO_POLICIES.md byte
for byte from sneak/prompts dd4027b, keeping this repo's anchored
host-built artifacts in .dockerignore; the new .golangci.yml disables
gomodguard. The Dockerfile gets a lint phase on golangci-lint v2.14.0
and a test phase on the Debian Go image; the build stage depends on
both and stamps the version as the policy shows. script/test and
script/lint build only their phase, and script/cibuild bootstraps and
runs script/check first. bin/tools goes: script/bootstrap installs
gofumpt and protoc-gen-go into bin/ with go install pinned to a commit,
and bin/.gitignore ignores what lands in bin/.
Model: opus-5-5
Adds .prettierrc and .prettierignore, a single script/prettier entrypoint shared by fmt and fmt-check so the two cannot drift, and prettier 3.9.6 pinned by yarn.lock integrity hash.
Markdown formatting is now gated in the authoritative Docker build via a new mdfmt stage, since the golangci-lint image has no node. REPO_POLICIES.md is ignored so local tooling cannot drift it from upstream.
Removes the || true that made the previous prettier invocation unable to fail.