check / check (push) Failing after 3s
gofumpt and protoc-gen-go are tools of a separate Go module in bin/tools, so `go tool` builds them from source checked against bin/tools/go.sum and mfer's own module gains no dependencies. script/bootstrap downloads that module, and unpacks protoc 33.4 into bin/protoc from its release archive after checking the sha256 it holds for the platform. script/generate runs that protoc with the pinned plugin, so mfer/mf.go and its go:generate line go. script/prettier runs only the node_modules prettier, fails when it differs from the package.json pin, finds the node bootstrap installed through nvm by the version in .nvmrc, and runs prettier once. Comment and package.json fixes. Model: opus-5-5
67 lines
2.2 KiB
Plaintext
67 lines
2.2 KiB
Plaintext
# .dockerignore does NOT use .gitignore semantics. Docker matches with
|
|
# moby/patternmatcher: filepath.Match plus `**`, so `*` does not cross
|
|
# `/` and an unprefixed pattern is anchored at the context root. Every
|
|
# depth-independent pattern therefore needs `**/`, or `config/.env` and
|
|
# `certs/server.key` still ship while this file reads as solved. Only
|
|
# genuinely root-anchored entries go unprefixed. Never transplant these
|
|
# into .gitignore, where `**/` is wrong.
|
|
#
|
|
# Matching is case-sensitive, so secrets use character ranges rather
|
|
# than an ALL-CAPS twin, which would still miss `Server.Key`.
|
|
#
|
|
# Extend with this repo's own host-built artifacts, written anchored:
|
|
# `/myapp`, never `**/myapp`, which also matches `cmd/myapp/` and
|
|
# deletes the package directory from the context.
|
|
|
|
# .git is sent without its config. Without a VERSION build argument the
|
|
# stage that compiles runs `git describe --tags --always` on .git, which
|
|
# does not need .git/config; that file can hold a credential, such as a
|
|
# password in a remote URL or the token the CI checkout step stores there.
|
|
.git/config
|
|
|
|
# Agent scratch: one full checkout of the repo per in-flight agent.
|
|
# Anchored because it occurs once where agents run at the repo root.
|
|
# KNOWN GAP: a repo running agents in subdirectories still ships
|
|
# `services/api/.claude/` and must add its own anchored entry.
|
|
.claude
|
|
|
|
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
|
# convention. Re-include a committed template with a negation if the
|
|
# build needs one: `!docs/example.env`.
|
|
**/*.[eE][nN][vV]
|
|
**/.[eE][nN][vV].*
|
|
**/.[eE][nN][vV][rR][cC]
|
|
|
|
# Private keys and the bundles carrying them. Public certificates
|
|
# (*.crt, *.cer) are deliberately absent: they are legitimate inputs.
|
|
**/*.[pP][eE][mM]
|
|
**/*.[kK][eE][yY]
|
|
**/*.[pP]12
|
|
**/*.[pP][fF][xX]
|
|
**/[iI][dD]_[rR][sS][aA]
|
|
**/[iI][dD]_[dD][sS][aA]
|
|
**/[iI][dD]_[eE][cC][dD][sS][aA]
|
|
**/[iI][dD]_[eE][dD]25519
|
|
|
|
# Dependencies: restored inside the image, never copied in.
|
|
**/node_modules
|
|
|
|
# OS metadata.
|
|
**/.DS_Store
|
|
**/Thumbs.db
|
|
|
|
# Editor state: never a build input, and it churns COPY.
|
|
**/*.swp
|
|
**/*.swo
|
|
**/*~
|
|
**/*.bak
|
|
**/.idea
|
|
**/.vscode
|
|
**/*.sublime-*
|
|
|
|
# This repo's own host-built binary (make build).
|
|
/bin/mfer
|
|
|
|
# The protoc script/bootstrap unpacks for script/generate.
|
|
/bin/protoc
|