Add CI policy, strengthen hash-pinning rule, add Gitea Actions workflow
check / check (push) Successful in 16s

- All Dockerfiles must run make check as a build step
- Every repo needs a Gitea Actions workflow running docker build on push
- Greatly strengthen the hash-pinning rule: explicitly list all reference
  types, ban curl|bash installs, mark as most important rule in document
- Add model .gitea/workflows/check.yml pinned by commit hash
This commit is contained in:
2026-02-22 16:35:42 +01:00
parent 7f4ed7edbd
commit f43445caea
4 changed files with 40 additions and 8 deletions
+4 -1
View File
@@ -24,7 +24,10 @@ with your task.
fetch from `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore`
if missing
- [ ] `.editorconfig` exists
- [ ] `Dockerfile` and `.dockerignore` exist
- [ ] `Dockerfile` and `.dockerignore` exist; Dockerfile runs `make check` as a
build step
- [ ] Gitea Actions workflow in `.gitea/workflows/` runs `docker build .` on
push
- [ ] Language-specific config:
- [ ] Go: `go.mod`, `go.sum`, `.golangci.yml`
- [ ] JS: `package.json`, `yarn.lock`, `.prettierrc`, `.prettierignore`