Dockerfile.backend did not follow the Go multistage lint-stage pattern
REPO_POLICIES.md mandates, and dragged the whole git history into the
build context to resolve a version string.
- Add an `AS lint` stage on the hash-pinned golangci/golangci-lint
image (v2.7.2, the same golangci-lint commit main already pins), which
ships Go, gofmt, make and the linter, so nothing is installed in it.
It runs `make fmt-check` then `make lint`.
- Add `COPY --from=lint /src/go.sum /dev/null` to the build stage so
BuildKit cannot run the two stages in parallel and let a lint failure
through.
- Stop compiling golangci-lint from source in the build stage.
- Drop `COPY .git /repo/.git`; the version now comes from
`ARG VERSION=dev`, passed to the build via `make build VERSION=...`.
- Drop gcc and musl-dev, and the corresponding
`-linkmode external -extldflags -static` in backend/Makefile. The
build is now `CGO_ENABLED=0 go build -trimpath` with
`-ldflags "-s -w -X main.Version=... -X main.Buildarch=..."`, which is
static without a C toolchain.
- backend/Makefile's VERSION is now overridable and degrades to `dev`
when git or .git is unavailable instead of emitting a git error and
building an empty version string.
- Every FROM stays pinned by @sha256 with a version and date comment.
Runtime stage, exposed port and entrypoint are unchanged.