# Dockerfile.lint: the container script/lint builds to run golangci-lint, # which is never installed on the host. Pinned to the same image as the # Dockerfile lint stage: change both pins together, or the two run # different linter versions. # # golangci/golangci-lint:v2.12.2-alpine, 2026-08-07 FROM golangci/golangci-lint:v2.12.2-alpine@sha256:91b27804074a0bacea298707f016911e60cf0cdbc6c7bf5ccacb5f0606d18d60 WORKDIR /src # pixa is CGO/libvips: the type-aware linters compile every package, so # this image needs the same C libraries the build does. script/bootstrap # installs them and downloads the Go modules. Only script/, go.mod and # go.sum are copied first; they settle this layer's result, so it may # safely be reused between runs. COPY script/ ./script/ COPY go.mod go.sum ./ RUN script/bootstrap COPY . . # Tells script/lint it is inside a container, so it runs the linter. ENV container=docker # script/lint passes a different CACHEBUST on every run, and BuildKit # keys every RUN after this ARG on its value, so the lint step always # runs instead of returning a cached success that linted nothing. # # Go's and golangci-lint's caches (/root/.cache, hundreds of MB) go on a # tmpfs that is discarded after the step. Written into the layer, they # would pile up as build cache on every run, since no later run, with # its new CACHEBUST, can reuse that layer. ARG CACHEBUST RUN --mount=type=tmpfs,target=/root/.cache script/lint