Gate the build on Docker lint and test phases (closes #40, closes #30)
All checks were successful
check / check (push) Successful in 5m12s
All checks were successful
check / check (push) Successful in 5m12s
Per the owner ruling on issue 40, linting and testing are phases of the main Dockerfile rather than a separate lint file. script/lint and script/test build one phase each by name with caching disabled, and the final stage copies a harmless file from each so the image cannot be built unless both passed. A stage that is not the last is built only when something depends on it or --target names it, so the gates are invoked by name and the edges kept. script/check runs the gates and builds no image of its own; script/cibuild bootstraps first, because CI runs it alone and fmt-check is native. fmt and fmt-check source nvm for the pinned node before calling yarn, which bootstrap installs but leaves off its caller's PATH. Every build in script/ is tagged and uncached. Issue 30 closes too: a container has its own lint cache and lock. Model: opus-5
This commit is contained in:
10
TODO.md
10
TODO.md
@@ -21,6 +21,16 @@ fmt-check, and commit.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-08: Moved linting and testing into Docker as phases of the main
|
||||
`Dockerfile`, per the owner ruling on issue 40. `script/lint` and
|
||||
`script/test` build one phase each by name with `--no-cache` — the same answer
|
||||
issue 26 got, so no separate cache-busting mechanism survives — and the final
|
||||
stage copies a harmless file from both, so the image cannot be built unless
|
||||
they pass. This also closes issue 30: a container has its own result cache and
|
||||
its own lock, so a lint verdict can no longer belong to another checkout. No
|
||||
separate lint Dockerfile, and no `golangci-lint config verify` step.
|
||||
`script/check` runs the gates and nothing else, and `script/cibuild`
|
||||
bootstraps first, since it is all CI runs and `script/fmt-check` is native.
|
||||
- 2026-09-08: Kept in-repo agent scratch out of the Docker build context and out
|
||||
of version control: `.claude/` is one full checkout of the repo per in-flight
|
||||
agent, and under `COPY . .` all of it was reaching the image. Also closed the
|
||||
|
||||
Reference in New Issue
Block a user