Version-stamp convention: follow-ups from the rollout, and one pinning question #72

Open
opened 2026-10-02 14:09:06 +02:00 by clawbot · 0 comments
Collaborator

Follow-ups to the version-stamp convention (sneak/project-management#21), found while rolling it out. Each is small; none blocks the rollout.

For the canonical text on next:

  1. A build context sent as a tar stream keeps the sender's file owners, and git in the build then refuses the checkout ("detected dubious ownership"), so the version step fails. upaas clones as root and is unaffected; other build hosts are not. Recommendation: git config --system --add safe.directory /src in the example's builder stage (webhooker, mfer and currentstat.us already have it).
  2. The styleguide's VERSION ?= $(shell git describe --tags --always) stamps an empty version outside a git checkout. Recommendation: $(or $(shell git describe --tags --always),dev), so every repo falls back to dev the same way.
  3. Only the top-level .git/config is excluded; a submodule's .git/modules/*/config is not.
  4. The example's test stage runs go test -race on the alpine Go image, where -race cannot work (it needs cgo).
  5. make check prints the yarn warning "package.json: No license field".

Waits on the owner: the example installs git with an unpinned RUN apk add --no-cache git, while prompts/REPO_POLICIES.md says every external reference is pinned by hash, no exceptions (the existing apk add vips-dev example has the same gap). Options: (a) allow distribution packages from the pinned base image's own repository unpinned, and say so in the policy; (b) pin package versions (git=2.x.y-rN), which breaks whenever the base image moves; (c) use a base image that already ships git (the Debian Go images do). Recommendation: (a), since the base image itself is pinned by digest.

Model: opus-5-5

Follow-ups to the version-stamp convention (https://git.eeqj.de/sneak/project-management/issues/21), found while rolling it out. Each is small; none blocks the rollout. For the canonical text on `next`: 1. A build context sent as a tar stream keeps the sender's file owners, and git in the build then refuses the checkout ("detected dubious ownership"), so the version step fails. upaas clones as root and is unaffected; other build hosts are not. Recommendation: `git config --system --add safe.directory /src` in the example's builder stage (webhooker, mfer and currentstat.us already have it). 2. The styleguide's `VERSION ?= $(shell git describe --tags --always)` stamps an empty version outside a git checkout. Recommendation: `$(or $(shell git describe --tags --always),dev)`, so every repo falls back to `dev` the same way. 3. Only the top-level `.git/config` is excluded; a submodule's `.git/modules/*/config` is not. 4. The example's test stage runs `go test -race` on the alpine Go image, where `-race` cannot work (it needs cgo). 5. `make check` prints the yarn warning "package.json: No license field". Waits on the owner: the example installs `git` with an unpinned `RUN apk add --no-cache git`, while `prompts/REPO_POLICIES.md` says every external reference is pinned by hash, no exceptions (the existing `apk add vips-dev` example has the same gap). Options: (a) allow distribution packages from the pinned base image's own repository unpinned, and say so in the policy; (b) pin package versions (`git=2.x.y-rN`), which breaks whenever the base image moves; (c) use a base image that already ships `git` (the Debian Go images do). Recommendation: (a), since the base image itself is pinned by digest. Model: opus-5-5
sneak was assigned by clawbot 2026-10-02 14:09:06 +02:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/prompts#72