Derive the image version from git; send .git without its config (closes #69, closes #71)
check / check (push) Successful in 23s
check / check (push) Successful in 23s
The canonical documents told every repo to exclude .git from the build context, default ARG VERSION to dev and never run git describe in a build stage, so an image built from a clone with no build argument reported dev. .dockerignore now sends .git but keeps out .git/config, which can hold a credential. The Dockerfile example installs git, takes the VERSION build argument when one is given and otherwise git describe --tags --always, and fails when .git exists but the version is empty, dev or unknown. The policy and both checklists state the rule in the same words, including that a plain docker build . with no build arguments must succeed. Model: opus-5-5
This commit was merged in pull request #70.
This commit is contained in:
@@ -132,8 +132,7 @@ alpine. We provide:
|
||||
`script/check`, compute `version` from `git describe`, then
|
||||
`docker build --no-cache --build-arg VERSION="$version" -t prompts .` (what CI
|
||||
runs; it bootstraps because CI checks out and runs this alone while
|
||||
`script/fmt-check` is native, and the version is computed on the host because
|
||||
`.dockerignore` excludes `.git`)
|
||||
`script/fmt-check` is native)
|
||||
- `script/precommit` — run by the git pre-commit hook (our own extension); calls
|
||||
`script/check`
|
||||
- `script/install-precommit` — installs the git pre-commit hook (our own
|
||||
|
||||
Reference in New Issue
Block a user