Fetches .dockerignore, .editorconfig, the CI workflow, .gitignore,
.golangci.yml, .prettierignore, .prettierrc and REPO_POLICIES.md byte
for byte from sneak/prompts dd4027b, keeping this repo's anchored
host-built artifacts in .dockerignore; the new .golangci.yml disables
gomodguard. The Dockerfile gets a lint phase on golangci-lint v2.14.0
and a test phase on the Debian Go image; the build stage depends on
both and stamps the version as the policy shows. script/test and
script/lint build only their phase, and script/cibuild bootstraps and
runs script/check first. bin/tools goes: script/bootstrap installs
gofumpt and protoc-gen-go into bin/ with go install pinned to a commit,
and bin/.gitignore ignores what lands in bin/.
Model: opus-5-5
script/lint now builds only the lint stage of the main Dockerfile
(docker build --no-cache --target lint), whose build runs the linter, so
a successful build is a clean lint. It is uncached because a cached
build runs no linter, and a trap removes the image it tagged; the tag
carries the process ID so concurrent runs do not collide. The lint stage
calls golangci-lint directly, since make lint now needs Docker. Nothing
installs or runs golangci-lint on the host any more: bootstrap and the
Makefile drop the install, and script/fmt drops golangci-lint run --fix.
Model: opus-5-5