script/lint now only builds the new Dockerfile.lint, which copies the
repo into the pinned golangci-lint image and runs the linter as a build
step, so a successful build is a clean lint. It builds with --no-cache,
because a cached build runs no linter, and removes the image it tagged
when it exits. The main Dockerfile lint stage calls golangci-lint
directly, since make lint now needs Docker. Nothing installs or runs
golangci-lint on the host any more: bootstrap and the Makefile drop the
install, and script/fmt drops golangci-lint run --fix. The gofmt check
script/lint repeated stays in script/fmt-check.
Model: opus-5-5
Adds .prettierrc and .prettierignore, a single script/prettier entrypoint shared by fmt and fmt-check so the two cannot drift, and prettier 3.9.6 pinned by yarn.lock integrity hash.
Markdown formatting is now gated in the authoritative Docker build via a new mdfmt stage, since the golangci-lint image has no node. REPO_POLICIES.md is ignored so local tooling cannot drift it from upstream.
Removes the || true that made the previous prettier invocation unable to fail.