check / check (push) Successful in 3m29s
The Dockerfile lint and build stages and Dockerfile.lint each carried their own apk add list, a copy of what script/bootstrap installs. They now copy script/, go.mod and go.sum and run script/bootstrap, so that layer is reused until one of those changes. script/bootstrap gains a C compiler check: the golang image has none, and cgo needs one. The build adds -trimpath and -s -w; CGO_ENABLED=1 stays, as govips links libvips. ARG VERSION moves to just above the build, so a new version reruns neither script/bootstrap nor the tests. Model: opus-5-5