script/lint now only builds the new Dockerfile.lint, which copies the
repo into the pinned golangci-lint image and runs the linter as a build
step, so a successful build is a clean lint. It builds with --no-cache,
because a cached build runs no linter, and removes the image it tagged
when it exits. The main Dockerfile lint stage calls golangci-lint
directly, since make lint now needs Docker. Nothing installs or runs
golangci-lint on the host any more: bootstrap and the Makefile drop the
install, and script/fmt drops golangci-lint run --fix. The gofmt check
script/lint repeated stays in script/fmt-check.
Model: opus-5-5