Merge branch 'main' into gomodguard-v2-with-settings
All checks were successful
check / check (push) Successful in 29s
All checks were successful
check / check (push) Successful in 29s
This commit is contained in:
32
TODO.md
32
TODO.md
@@ -21,6 +21,38 @@ fmt-check, and commit.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-08: Moved linting and testing into Docker as phases of the main
|
||||
`Dockerfile`, per the owner ruling on issue 40. `script/lint` and
|
||||
`script/test` build one phase each by name with `--no-cache` — the same answer
|
||||
issue 26 got, so no separate cache-busting mechanism survives — and the final
|
||||
stage copies a harmless file from both, so the image cannot be built unless
|
||||
they pass. This also closes issue 30: a container has its own result cache and
|
||||
its own lock, so a lint verdict can no longer belong to another checkout. No
|
||||
separate lint Dockerfile, and no `golangci-lint config verify` step.
|
||||
`script/check` runs the gates and nothing else, and `script/cibuild`
|
||||
bootstraps first, since it is all CI runs and `script/fmt-check` is native.
|
||||
- 2026-09-08: Kept in-repo agent scratch out of the Docker build context and out
|
||||
of version control: `.claude/` is one full checkout of the repo per in-flight
|
||||
agent, and under `COPY . .` all of it was reaching the image. Also closed the
|
||||
consequence of excluding `.git` — `git describe` yields an empty version
|
||||
inside a build stage without failing, so `script/docker` and `script/cibuild`
|
||||
now compute the version on the host and pass `--build-arg VERSION`.
|
||||
- 2026-09-08: Closed the secret exposure in the canonical `.dockerignore`: a
|
||||
local `.env`, `*.pem` or `*.key` was reaching the build context under
|
||||
`COPY . .`, invisible to every git-based check. The patterns are now written
|
||||
to `.dockerignore`'s own semantics — `**/`-prefixed so they hold at every
|
||||
depth, case-folded with character ranges — and `REPO_POLICIES.md` requires
|
||||
verifying by enumerating the image rather than by reading the file.
|
||||
- 2026-09-08: Made a pinned tool in `script/bootstrap` actually reach the host.
|
||||
`REPO_POLICIES.md` now requires comparing the installed version against the
|
||||
pin rather than testing `PATH` presence, and re-resolving the binary through
|
||||
`PATH` after installing, so a version bump cannot be a silent no-op and a
|
||||
shadowed install cannot report success.
|
||||
- 2026-09-08: Closed the false green in the canonical CI gate: `script/cibuild`
|
||||
and `script/docker` now build with `--no-cache`, so the Dockerfile's check
|
||||
layers cannot be served from cache on an unchanged tree, and the text claiming
|
||||
a bare `docker build .` proves the checks ran is corrected in
|
||||
`REPO_POLICIES.md`, both checklists and the Go styleguide.
|
||||
- 2026-09-03: Added `-count=1` to both `go test` invocations in the canonical Go
|
||||
`make test` example in `REPO_POLICIES.md`, so the target cannot report a
|
||||
cached pass it did not earn, and documented that Go's test-result cache is a
|
||||
|
||||
Reference in New Issue
Block a user