build: run all linting in Docker via Dockerfile.lint (closes #104)
golangci-lint now runs only inside a container, never on the host. script/lint builds a hash-pinned root Dockerfile.lint; the nix-shell and host golangci-lint paths are gone. A per-run CACHEBUST build-arg is folded into the lint step's cache key, so the linter re-executes on every run and an unchanged tree cannot return a cached success having linted nothing; script/lint fails a build that did not run the linter. Dockerfile's lint stage runs golangci-lint directly, since make lint now builds a container and there is no Docker inside a build. It is the same image and config. golangci-lint config verify is left out: it fetches its schema over an unpinned live HTTPS call, which REPO_POLICIES.md forbids. Model: opus-4-8
This commit is contained in:
@@ -39,6 +39,17 @@ exhaustion
|
||||
(IPv4-mapped forms covered); enforcement stays in the dial-time
|
||||
re-resolution so the DNS-rebinding window remains closed; documented in
|
||||
`README.md` and `config.example.yml`.
|
||||
- 2026-09-21 run all linting in Docker via `Dockerfile.lint` +
|
||||
`script/lint` (closes #104): `script/lint` builds a hash-pinned root
|
||||
`Dockerfile.lint`, and no host or nix-shell `golangci-lint` path
|
||||
remains (`script/bootstrap` installs no linter, and the Makefile and
|
||||
`script/test` nix-shell package lists carry only build/test deps); a
|
||||
per-run `CACHEBUST` build-arg forces the lint step to execute every
|
||||
run, so an unchanged tree cannot return a cached green that linted
|
||||
nothing; `Dockerfile`'s lint stage runs `golangci-lint` directly,
|
||||
since `make lint` now builds a container and there is no Docker inside
|
||||
a build; `golangci-lint config verify` stays out, as it fetches its
|
||||
schema over an unpinned live HTTPS call
|
||||
- 2026-09-21 http.Server hardening (closes #92): added
|
||||
`HTTPReadHeaderTimeout` (10s, bounds the slowloris header dribble) and
|
||||
`HTTPIdleTimeout` (120s, bounds keep-alive reuse) alongside the
|
||||
|
||||
Reference in New Issue
Block a user