Derive the image version from git; send .git without its config (closes #69, closes #71)
check / check (push) Successful in 23s

The canonical documents told every repo to exclude .git from the build
context, default ARG VERSION to dev and never run git describe in a
build stage, so an image built from a clone with no build argument
reported dev. .dockerignore now sends .git but keeps out .git/config,
which can hold a credential. The Dockerfile example installs git, takes
the VERSION build argument when one is given and otherwise
git describe --tags --always, and fails when .git exists but the version
is empty, dev or unknown. The policy and both checklists state the rule
in the same words, including that a plain docker build . with no build
arguments must succeed.

Model: opus-5-5
This commit was merged in pull request #70.
This commit is contained in:
2026-10-02 04:38:10 +02:00
parent 2ae9391b26
commit 507a57e813
11 changed files with 108 additions and 59 deletions
+4 -3
View File
@@ -52,7 +52,8 @@ RUN script/bootstrap
COPY . .
# The version is computed on the host and passed in, because
# .dockerignore excludes .git.
ARG VERSION=dev
# Nothing here is compiled and a LABEL cannot run git, so the version is
# the VERSION build argument that script/docker and script/cibuild pass;
# a plain `docker build .` leaves it empty.
ARG VERSION
LABEL org.opencontainers.image.version="${VERSION}"