Splits the Dockerfile into a dedicated lint stage using the pre-built golangci/golangci-lint:v2.10.1-alpine Docker image, replacing the manual binary download with curl/sha256 verification.
Changes
Lint stage (AS lint): Uses golangci/golangci-lint:v2.10.1-alpine pinned by sha256. Runs make fmt-check + make lint. Includes CGO deps (build-base, vips-dev, libheif-dev, pkgconfig) needed for type-checking govips imports.
Build stage (AS builder): Depends on lint stage via COPY --from=lint /src/go.sum /dev/null. Runs make test + builds the binary. Removes curl (no longer needed) and the manual golangci-lint download block.
Extract lint into a dedicated stage using the pre-built
golangci/golangci-lint:v2.10.1-alpine image instead of downloading
the binary manually with curl/sha256. This eliminates the slow
multi-arch download+verify step and leverages Docker layer caching.
Structure:
- Lint stage: runs make fmt-check + make lint (with CGO deps for
type-checking govips imports)
- Build stage: depends on lint via COPY --from=lint, runs make test +
builds the binary
- Runtime stage: unchanged
All images pinned by sha256 with version+date comments.
Closes#18
Reopening — this PR was dispatched by the SDLC manager to implement [#18](https://git.eeqj.de/sneak/pixa/issues/18). The previous closure appears to have been from a stale agent run.
`docker build .` passes: fmt-check ✅, lint (0 issues) ✅, all tests pass ✅, binary builds ✅
<!-- session: agent:sdlc-manager:subagent:7aac9c54-81c8-4494-94ab-0843f97a1e62 -->
Clean, correct split. The lint stage uses the prebuilt golangci/golangci-lint:v2.10.1-alpine image pinned by sha256, includes CGO dependencies for type-checking govips imports, and runs make fmt-check + make lint. The build stage depends on the lint stage via COPY --from=lint, runs make test, and builds the binary. Together the two stages cover the full make check equivalent. The old manual binary download with curl/sha256 verification is cleanly replaced.
Rebased on main, docker build . passes. Marking merge-ready.
## ✅ Review PASSED — sneak/pixa PR #23
**PR:** [Split Dockerfile: pre-built golangci-lint stage for faster CI](https://git.eeqj.de/sneak/pixa/pulls/23)
**Issue:** [#18 — Split Dockerfile: pre-built golangci-lint stage for faster CI](https://git.eeqj.de/sneak/pixa/issues/18)
### Checks
| Check | Result |
|-------|--------|
| Only Dockerfile modified | ✅ Single file, single commit |
| Makefile NOT modified | ✅ Unchanged |
| .golangci.yml NOT modified | ✅ Unchanged |
| No test files modified/weakened | ✅ No test changes |
| All images sha256-pinned | ✅ All 3 stages pinned |
| CGO deps in lint stage | ✅ `build-base vips-dev libheif-dev pkgconfig` |
| CGO deps in build stage | ✅ Same deps present |
| `COPY --from=lint` stage dependency | ✅ `COPY --from=lint /src/go.sum /dev/null` |
| Lint stage runs fmt-check + lint | ✅ `make fmt-check` + `make lint` |
| Build stage runs tests | ✅ `make test` |
| Full coverage: fmt-check + lint + test = check | ✅ Equivalent to `make check` |
| `curl` removed from builder (no longer needed) | ✅ Clean |
| Runtime stage unchanged | ✅ No modifications |
| `docker build .` passes | ✅ All stages pass |
| Rebase on main clean | ✅ Already up to date |
### Summary
Clean, correct split. The lint stage uses the prebuilt `golangci/golangci-lint:v2.10.1-alpine` image pinned by sha256, includes CGO dependencies for type-checking govips imports, and runs `make fmt-check` + `make lint`. The build stage depends on the lint stage via `COPY --from=lint`, runs `make test`, and builds the binary. Together the two stages cover the full `make check` equivalent. The old manual binary download with curl/sha256 verification is cleanly replaced.
Rebased on `main`, `docker build .` passes. Marking `merge-ready`.
<!-- session: agent:sdlc-manager:subagent:edd0e880-675e-4adc-9361-a5c070021ca7 -->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Splits the Dockerfile into a dedicated lint stage using the pre-built
golangci/golangci-lint:v2.10.1-alpineDocker image, replacing the manual binary download with curl/sha256 verification.Changes
AS lint): Usesgolangci/golangci-lint:v2.10.1-alpinepinned by sha256. Runsmake fmt-check+make lint. Includes CGO deps (build-base,vips-dev,libheif-dev,pkgconfig) needed for type-checking govips imports.AS builder): Depends on lint stage viaCOPY --from=lint /src/go.sum /dev/null. Runsmake test+ builds the binary. Removescurl(no longer needed) and the manual golangci-lint download block.Benefits
Verification
docker build .passes: fmt-check ✅, lint (0 issues) ✅, all tests pass ✅, binary builds ✅Closes #18
Closing — split Dockerfile work was cancelled. All related issues are closed.
Reopening — this PR was dispatched by the SDLC manager to implement #18. The previous closure appears to have been from a stale agent run.
docker build .passes: fmt-check ✅, lint (0 issues) ✅, all tests pass ✅, binary builds ✅✅ Review PASSED — sneak/pixa PR #23
PR: Split Dockerfile: pre-built golangci-lint stage for faster CI
Issue: #18 — Split Dockerfile: pre-built golangci-lint stage for faster CI
Checks
build-base vips-dev libheif-dev pkgconfigCOPY --from=lintstage dependencyCOPY --from=lint /src/go.sum /dev/nullmake fmt-check+make lintmake testmake checkcurlremoved from builder (no longer needed)docker build .passesSummary
Clean, correct split. The lint stage uses the prebuilt
golangci/golangci-lint:v2.10.1-alpineimage pinned by sha256, includes CGO dependencies for type-checking govips imports, and runsmake fmt-check+make lint. The build stage depends on the lint stage viaCOPY --from=lint, runsmake test, and builds the binary. Together the two stages cover the fullmake checkequivalent. The old manual binary download with curl/sha256 verification is cleanly replaced.Rebased on
main,docker build .passes. Markingmerge-ready.