Pin host Go tools by commit hash with go install (closes #37)
check / check (push) Waiting to run
check / check (push) Waiting to run
Writes sneak's 2026-09-09 ruling into the script/bootstrap bullet of REPO_POLICIES.md: a Go tool a repo needs on the host is installed with go install pinned to a commit hash, never tracked as a go.mod tool dependency or through a tools.go file. golangci-lint is unchanged; it stays pinned only by its image digest. Model: opus-5-5
This commit is contained in:
@@ -21,6 +21,10 @@ fmt-check, and commit.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `REPO_POLICIES.md` now says how a Go tool a repo needs on the host
|
||||
is pinned (issue 37): installed with `go install` pinned to a commit hash,
|
||||
never tracked as a `go.mod` tool dependency or through a `tools.go` file.
|
||||
golangci-lint is unaffected, since no repo installs it on the host.
|
||||
- 2026-10-04: `package.json` now has `"license": "MIT"`, matching `LICENSE`, so
|
||||
yarn no longer prints "No license field" when `script/bootstrap` runs it
|
||||
inside the Docker phases (issue 76). That was the only yarn warning there.
|
||||
|
||||
@@ -495,6 +495,11 @@ style conventions are in separate documents:
|
||||
|
||||
Keep it POSIX sh: no arrays, no `[[`, no `grep -P`.
|
||||
|
||||
A Go tool a repo needs on the host is installed with `go install` pinned to
|
||||
a commit hash (`go install <package>@<commit hash>`). It is never tracked as
|
||||
a `go.mod` tool dependency or through a `tools.go` file, either of which
|
||||
pulls the tool's own dependencies into the repo's `go.mod` and `go.sum`.
|
||||
|
||||
- When pinning images or packages by hash, add a comment above the reference
|
||||
with the version and date (YYYY-MM-DD).
|
||||
|
||||
|
||||
Reference in New Issue
Block a user