Root make check, and with it the pre-commit hook, now gates the Go
backend too. The backend's Makefile targets are shims over
backend/script/*; script/cibuild builds both images and is the
workflow's only build step.
The root make lint runs golangci-lint only in Docker, by building the
lint stage of Dockerfile.backend without the cache; the .golangci.yml
drift check moved into backend/script/lint. script/bootstrap installs
no linter: it reuses a Go at least as new as backend/go.mod asks for,
otherwise installs the pinned, hash-verified release, and links what it
installs into ~/.local/bin without replacing anything it did not
create. The backend version falls back to dev when VERSION is unset or
empty.
Model: opus-5-5