Fetches .dockerignore, .editorconfig, the CI workflow, .gitignore,
.golangci.yml, .prettierignore, .prettierrc and REPO_POLICIES.md byte
for byte from sneak/prompts dd4027b, keeping this repo's anchored
host-built artifacts in .dockerignore; the new .golangci.yml disables
gomodguard. The Dockerfile gets a lint phase on golangci-lint v2.14.0
and a test phase on the Debian Go image; the build stage depends on
both and stamps the version as the policy shows. script/test and
script/lint build only their phase, and script/cibuild bootstraps and
runs script/check first. bin/tools goes: script/bootstrap installs
gofumpt and protoc-gen-go into bin/ with go install pinned to a commit,
and bin/.gitignore ignores what lands in bin/.
Model: opus-5-5
A bare `docker build .` served the Dockerfile's check steps from the
layer cache on an unchanged tree and exited 0 without running them.
script/cibuild now computes the version on its own line and runs the
same build command as script/docker and the shared policy, --no-cache
included, so every CI build runs the checks. README.md describes
script/cibuild accordingly.
Model: opus-5-5