Derive the image version from git; send .git without its config (closes #69, closes #71)
check / check (push) Successful in 23s

The canonical documents told every repo to exclude .git from the build
context, default ARG VERSION to dev and never run git describe in a
build stage, so an image built from a clone with no build argument
reported dev. .dockerignore now sends .git but keeps out .git/config,
which can hold a credential. The Dockerfile example installs git, takes
the VERSION build argument when one is given and otherwise
git describe --tags --always, and fails when .git exists but the version
is empty, dev or unknown. The policy and both checklists state the rule
in the same words, including that a plain docker build . with no build
arguments must succeed.

Model: opus-5-5
This commit was merged in pull request #70.
This commit is contained in:
2026-10-02 04:38:10 +02:00
parent 2ae9391b26
commit 507a57e813
11 changed files with 108 additions and 59 deletions
+15 -6
View File
@@ -1,6 +1,6 @@
---
title: New Repo Checklist
last_modified: 2026-09-08
last_modified: 2026-10-02
---
Use this checklist when creating a new repository from scratch. Follow the steps
@@ -67,11 +67,20 @@ Template files can be fetched from:
note that it only covers agents running at the repo root — if this repo
will run them in subdirectories, `services/api/.claude/` needs its own
anchored entry.
- If the image embeds a version in a binary, the version is computed on the
host and passed with `--build-arg VERSION=...`, and `ARG VERSION=dev` is
declared in the stage that compiles. **No stage calls `git describe`** —
`.dockerignore` excludes `.git`, so it yields an empty version without
failing the build.
- If the image embeds a version in a binary: `.dockerignore` lets `.git`
into the build context. It keeps out `.git/config`, which `git describe`
does not need and which can hold a credential: a password in a remote URL,
or the token the CI checkout step stores there. The stage that compiles
has `git` (the Debian Go image has it; an alpine one needs
`apk add --no-cache git`) and takes the version from the `VERSION` build
argument when one is given, otherwise from `git describe --tags --always`.
That gives the tag on a tagged commit; on a later commit, the tag, the
number of commits since it and the short commit (`v1.2.3-4-gabc1234`); and
the short commit when no tag is reachable. `ARG VERSION` has no default,
and the build fails if the context carries `.git` and the version still
comes out empty, `dev` or `unknown`. A plain `docker build .` with no
build arguments must succeed; a Dockerfile that refuses an empty build
argument drops that refusal and keeps the argument.
- The Dockerfile carries a `lint` phase and a `test` phase, each invoking
its tool directly rather than through `make` or `script/`, and the final
stage carries a `COPY --from=` of a harmless file from each so the image