Run all linting in Docker through script/lint (closes #104)
check / check (push) Successful in 12s
check / check (push) Successful in 12s
make lint calls script/lint, the only way golangci-lint is run. Inside a container it runs the linter; anywhere else it builds Dockerfile.lint, whose last step runs script/lint again. Both Dockerfiles set container=docker to mark the container, since /.dockerenv is missing in build steps and present on hosts that are themselves containers. The Dockerfile lint stage runs make lint. A new CACHEBUST build-arg on every run keeps the lint step from being served from cache; a tmpfs mount keeps Go's and golangci-lint's caches out of that step's layer, so runs do not pile up build cache. script/bootstrap and the nix-shell package lists no longer carry golangci-lint. golangci-lint config verify is not run: it fetches its schema over an unpinned live HTTPS call. Model: opus-4-8 (implementation); opus-5-5 (rework)
This commit was merged in pull request #122.
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
# Dockerfile.lint: the container script/lint builds to run golangci-lint,
|
||||
# which is never installed on the host. Pinned to the same image as the
|
||||
# Dockerfile lint stage: change both pins together, or the two run
|
||||
# different linter versions.
|
||||
#
|
||||
# golangci/golangci-lint:v2.12.2-alpine, 2026-08-07
|
||||
FROM golangci/golangci-lint:v2.12.2-alpine@sha256:91b27804074a0bacea298707f016911e60cf0cdbc6c7bf5ccacb5f0606d18d60
|
||||
|
||||
# pixa is CGO/libvips: the type-aware linters compile every package, so
|
||||
# this image needs the same C libraries the build does.
|
||||
RUN apk add --no-cache build-base vips-dev libheif-dev pkgconfig
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
# Modules first for layer caching; go.mod/go.sum settle this layer's
|
||||
# result, so it may safely be reused between runs.
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY . .
|
||||
|
||||
# Tells script/lint it is inside a container, so it runs the linter.
|
||||
ENV container=docker
|
||||
|
||||
# script/lint passes a different CACHEBUST on every run, and BuildKit
|
||||
# keys every RUN after this ARG on its value, so the lint step always
|
||||
# runs instead of returning a cached success that linted nothing.
|
||||
#
|
||||
# Go's and golangci-lint's caches (/root/.cache, hundreds of MB) go on a
|
||||
# tmpfs that is discarded after the step. Written into the layer, they
|
||||
# would pile up as build cache on every run, since no later run, with
|
||||
# its new CACHEBUST, can reuse that layer.
|
||||
ARG CACHEBUST
|
||||
RUN --mount=type=tmpfs,target=/root/.cache script/lint
|
||||
Reference in New Issue
Block a user