Follow-ups to the version-stamp convention (sneak/project-management#21), found while rolling it out. Each is small; none blocks the rollout.
For the canonical text on next:
A build context sent as a tar stream keeps the sender's file owners, and git in the build then refuses the checkout ("detected dubious ownership"), so the version step fails. upaas clones as root and is unaffected; other build hosts are not. Recommendation: git config --system --add safe.directory /src in the example's builder stage (webhooker, mfer and currentstat.us already have it).
The styleguide's VERSION ?= $(shell git describe --tags --always) stamps an empty version outside a git checkout. Recommendation: $(or $(shell git describe --tags --always),dev), so every repo falls back to dev the same way.
Only the top-level .git/config is excluded; a submodule's .git/modules/*/config is not.
The example's test stage runs go test -race on the alpine Go image, where -race cannot work (it needs cgo).
make check prints the yarn warning "package.json: No license field".
Waits on the owner: the example installs git with an unpinned RUN apk add --no-cache git, while prompts/REPO_POLICIES.md says every external reference is pinned by hash, no exceptions (the existing apk add vips-dev example has the same gap). Options: (a) allow distribution packages from the pinned base image's own repository unpinned, and say so in the policy; (b) pin package versions (git=2.x.y-rN), which breaks whenever the base image moves; (c) use a base image that already ships git (the Debian Go images do). Recommendation: (a), since the base image itself is pinned by digest.
Model: opus-5-5
Follow-ups to the version-stamp convention (https://git.eeqj.de/sneak/project-management/issues/21), found while rolling it out. Each is small; none blocks the rollout.
For the canonical text on `next`:
1. A build context sent as a tar stream keeps the sender's file owners, and git in the build then refuses the checkout ("detected dubious ownership"), so the version step fails. upaas clones as root and is unaffected; other build hosts are not. Recommendation: `git config --system --add safe.directory /src` in the example's builder stage (webhooker, mfer and currentstat.us already have it).
2. The styleguide's `VERSION ?= $(shell git describe --tags --always)` stamps an empty version outside a git checkout. Recommendation: `$(or $(shell git describe --tags --always),dev)`, so every repo falls back to `dev` the same way.
3. Only the top-level `.git/config` is excluded; a submodule's `.git/modules/*/config` is not.
4. The example's test stage runs `go test -race` on the alpine Go image, where `-race` cannot work (it needs cgo).
5. `make check` prints the yarn warning "package.json: No license field".
Waits on the owner: the example installs `git` with an unpinned `RUN apk add --no-cache git`, while `prompts/REPO_POLICIES.md` says every external reference is pinned by hash, no exceptions (the existing `apk add vips-dev` example has the same gap). Options: (a) allow distribution packages from the pinned base image's own repository unpinned, and say so in the policy; (b) pin package versions (`git=2.x.y-rN`), which breaks whenever the base image moves; (c) use a base image that already ships `git` (the Debian Go images do). Recommendation: (a), since the base image itself is pinned by digest.
Model: opus-5-5
sneak
was assigned by clawbot2026-10-02 14:09:06 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Follow-ups to the version-stamp convention (sneak/project-management#21), found while rolling it out. Each is small; none blocks the rollout.
For the canonical text on
next:git config --system --add safe.directory /srcin the example's builder stage (webhooker, mfer and currentstat.us already have it).VERSION ?= $(shell git describe --tags --always)stamps an empty version outside a git checkout. Recommendation:$(or $(shell git describe --tags --always),dev), so every repo falls back todevthe same way..git/configis excluded; a submodule's.git/modules/*/configis not.go test -raceon the alpine Go image, where-racecannot work (it needs cgo).make checkprints the yarn warning "package.json: No license field".Waits on the owner: the example installs
gitwith an unpinnedRUN apk add --no-cache git, whileprompts/REPO_POLICIES.mdsays every external reference is pinned by hash, no exceptions (the existingapk add vips-devexample has the same gap). Options: (a) allow distribution packages from the pinned base image's own repository unpinned, and say so in the policy; (b) pin package versions (git=2.x.y-rN), which breaks whenever the base image moves; (c) use a base image that already shipsgit(the Debian Go images do). Recommendation: (a), since the base image itself is pinned by digest.Model: opus-5-5