build: run all linting in Docker via Dockerfile.lint (closes #104)

golangci-lint now runs only inside a container, never on the host.
script/lint builds a hash-pinned root Dockerfile.lint; the nix-shell and
host golangci-lint paths are gone. A per-run CACHEBUST build-arg is
folded into the lint step's cache key, so the linter re-executes on every
run and an unchanged tree cannot return a cached success having linted
nothing; script/lint fails a build that did not run the linter.

Dockerfile's lint stage runs golangci-lint directly, since make lint now
builds a container and there is no Docker inside a build. It is the same
image and config. golangci-lint config verify is left out: it fetches its
schema over an unpinned live HTTPS call, which REPO_POLICIES.md forbids.

Model: opus-4-8
This commit is contained in:
2026-09-21 22:48:51 +00:00
parent 3cfcda0730
commit 557b4f621a
4 changed files with 103 additions and 16 deletions
+11
View File
@@ -39,6 +39,17 @@ exhaustion
(IPv4-mapped forms covered); enforcement stays in the dial-time
re-resolution so the DNS-rebinding window remains closed; documented in
`README.md` and `config.example.yml`.
- 2026-09-21 run all linting in Docker via `Dockerfile.lint` +
`script/lint` (closes #104): `script/lint` builds a hash-pinned root
`Dockerfile.lint`, and no host or nix-shell `golangci-lint` path
remains (`script/bootstrap` installs no linter, and the Makefile and
`script/test` nix-shell package lists carry only build/test deps); a
per-run `CACHEBUST` build-arg forces the lint step to execute every
run, so an unchanged tree cannot return a cached green that linted
nothing; `Dockerfile`'s lint stage runs `golangci-lint` directly,
since `make lint` now builds a container and there is no Docker inside
a build; `golangci-lint config verify` stays out, as it fetches its
schema over an unpinned live HTTPS call
- 2026-09-21 http.Server hardening (closes #92): added
`HTTPReadHeaderTimeout` (10s, bounds the slowloris header dribble) and
`HTTPIdleTimeout` (120s, bounds keep-alive reuse) alongside the