check / check (push) Successful in 12s
make lint calls script/lint, the only way golangci-lint is run. Inside a container it runs the linter; anywhere else it builds Dockerfile.lint, whose last step runs script/lint again. Both Dockerfiles set container=docker to mark the container, since /.dockerenv is missing in build steps and present on hosts that are themselves containers. The Dockerfile lint stage runs make lint. A new CACHEBUST build-arg on every run keeps the lint step from being served from cache; a tmpfs mount keeps Go's and golangci-lint's caches out of that step's layer, so runs do not pile up build cache. script/bootstrap and the nix-shell package lists no longer carry golangci-lint. golangci-lint config verify is not run: it fetches its schema over an unpinned live HTTPS call. Model: opus-4-8 (implementation); opus-5-5 (rework)
35 lines
1.4 KiB
Docker
35 lines
1.4 KiB
Docker
# Dockerfile.lint: the container script/lint builds to run golangci-lint,
|
|
# which is never installed on the host. Pinned to the same image as the
|
|
# Dockerfile lint stage: change both pins together, or the two run
|
|
# different linter versions.
|
|
#
|
|
# golangci/golangci-lint:v2.12.2-alpine, 2026-08-07
|
|
FROM golangci/golangci-lint:v2.12.2-alpine@sha256:91b27804074a0bacea298707f016911e60cf0cdbc6c7bf5ccacb5f0606d18d60
|
|
|
|
# pixa is CGO/libvips: the type-aware linters compile every package, so
|
|
# this image needs the same C libraries the build does.
|
|
RUN apk add --no-cache build-base vips-dev libheif-dev pkgconfig
|
|
|
|
WORKDIR /src
|
|
|
|
# Modules first for layer caching; go.mod/go.sum settle this layer's
|
|
# result, so it may safely be reused between runs.
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
COPY . .
|
|
|
|
# Tells script/lint it is inside a container, so it runs the linter.
|
|
ENV container=docker
|
|
|
|
# script/lint passes a different CACHEBUST on every run, and BuildKit
|
|
# keys every RUN after this ARG on its value, so the lint step always
|
|
# runs instead of returning a cached success that linted nothing.
|
|
#
|
|
# Go's and golangci-lint's caches (/root/.cache, hundreds of MB) go on a
|
|
# tmpfs that is discarded after the step. Written into the layer, they
|
|
# would pile up as build cache on every run, since no later run, with
|
|
# its new CACHEBUST, can reuse that layer.
|
|
ARG CACHEBUST
|
|
RUN --mount=type=tmpfs,target=/root/.cache script/lint
|