Derive the image version from git; send .git without its config (closes #69, closes #71)
check / check (push) Successful in 23s
check / check (push) Successful in 23s
The canonical documents told every repo to exclude .git from the build context, default ARG VERSION to dev and never run git describe in a build stage, so an image built from a clone with no build argument reported dev. .dockerignore now sends .git but keeps out .git/config, which can hold a credential. The Dockerfile example installs git, takes the VERSION build argument when one is given and otherwise git describe --tags --always, and fails when .git exists but the version is empty, dev or unknown. The policy and both checklists state the rule in the same words, including that a plain docker build . with no build arguments must succeed. Model: opus-5-5
This commit was merged in pull request #70.
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
---
|
||||
title: New Repo Checklist
|
||||
last_modified: 2026-09-08
|
||||
last_modified: 2026-10-02
|
||||
---
|
||||
|
||||
Use this checklist when creating a new repository from scratch. Follow the steps
|
||||
@@ -67,11 +67,20 @@ Template files can be fetched from:
|
||||
note that it only covers agents running at the repo root — if this repo
|
||||
will run them in subdirectories, `services/api/.claude/` needs its own
|
||||
anchored entry.
|
||||
- If the image embeds a version in a binary, the version is computed on the
|
||||
host and passed with `--build-arg VERSION=...`, and `ARG VERSION=dev` is
|
||||
declared in the stage that compiles. **No stage calls `git describe`** —
|
||||
`.dockerignore` excludes `.git`, so it yields an empty version without
|
||||
failing the build.
|
||||
- If the image embeds a version in a binary: `.dockerignore` lets `.git`
|
||||
into the build context. It keeps out `.git/config`, which `git describe`
|
||||
does not need and which can hold a credential: a password in a remote URL,
|
||||
or the token the CI checkout step stores there. The stage that compiles
|
||||
has `git` (the Debian Go image has it; an alpine one needs
|
||||
`apk add --no-cache git`) and takes the version from the `VERSION` build
|
||||
argument when one is given, otherwise from `git describe --tags --always`.
|
||||
That gives the tag on a tagged commit; on a later commit, the tag, the
|
||||
number of commits since it and the short commit (`v1.2.3-4-gabc1234`); and
|
||||
the short commit when no tag is reachable. `ARG VERSION` has no default,
|
||||
and the build fails if the context carries `.git` and the version still
|
||||
comes out empty, `dev` or `unknown`. A plain `docker build .` with no
|
||||
build arguments must succeed; a Dockerfile that refuses an empty build
|
||||
argument drops that refusal and keeps the argument.
|
||||
- The Dockerfile carries a `lint` phase and a `test` phase, each invoking
|
||||
its tool directly rather than through `make` or `script/`, and the final
|
||||
stage carries a `COPY --from=` of a harmless file from each so the image
|
||||
|
||||
Reference in New Issue
Block a user