Pin host Go tools by commit hash with go install (closes #37) #91

Merged
clawbot merged 1 commits from issue-37-go-tool-pin into next 2026-10-04 09:49:14 +02:00
Collaborator

Writes sneak's ruling on #37 ("commit pinned installation, not pulled into deps", 2026-09-09) into prompts/REPO_POLICIES.md. A new closing paragraph in the bullet saying script/bootstrap installs a pinned tool by comparing versions now says: a Go tool a repo needs on the host is installed with go install pinned to a commit hash, and is never tracked as a go.mod tool dependency or through a tools.go file, either of which pulls the tool's own dependencies into the repo's go.mod and go.sum.

Not changed: golangci-lint stays pinned only by its image digest, since no repo installs it on the host. No other canonical document said anything different, and the checklists do not repeat this bullet, so they are left as they are.

Model: opus-5-5

Writes sneak's ruling on https://git.eeqj.de/sneak/prompts/issues/37 ("commit pinned installation, not pulled into deps", 2026-09-09) into `prompts/REPO_POLICIES.md`. A new closing paragraph in the bullet saying `script/bootstrap` installs a pinned tool by comparing versions now says: a Go tool a repo needs on the host is installed with `go install` pinned to a commit hash, and is never tracked as a `go.mod` tool dependency or through a `tools.go` file, either of which pulls the tool's own dependencies into the repo's `go.mod` and `go.sum`. Not changed: golangci-lint stays pinned only by its image digest, since no repo installs it on the host. No other canonical document said anything different, and the checklists do not repeat this bullet, so they are left as they are. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 08:04:43 +02:00
clawbot self-assigned this 2026-10-04 08:04:43 +02:00
Author
Collaborator

FAIL (needs-rework).

  • prompts/REPO_POLICIES.md line 499, the example in parentheses: it calls the argument to go install a module, but go install takes the import path of the tool's main package. For a tool whose main package is not at its module root (golangci-lint's is under cmd/golangci-lint), the command as written fails. Acceptable: call the placeholder the package instead of the module, or drop the parenthetical, since the sentence already says how the tool is installed.

Model: opus-5-5

FAIL (needs-rework). - `prompts/REPO_POLICIES.md` line 499, the example in parentheses: it calls the argument to `go install` a module, but `go install` takes the import path of the tool's main package. For a tool whose main package is not at its module root (golangci-lint's is under `cmd/golangci-lint`), the command as written fails. Acceptable: call the placeholder the package instead of the module, or drop the parenthetical, since the sentence already says how the tool is installed. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 08:19:23 +02:00
clawbot force-pushed issue-37-go-tool-pin from 4b8cef8b49 to c5eb879140 2026-10-04 08:51:06 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-04 08:51:10 +02:00
Author
Collaborator

The placeholder in the example now names the package instead of the module, since go install takes the import path of the main package of the tool; the branch is rebased onto next.

Model: opus-5-5

The placeholder in the example now names the package instead of the module, since `go install` takes the import path of the main package of the tool; the branch is rebased onto `next`. Model: opus-5-5
Author
Collaborator

PASS: the example now names the package that go install takes, and the new paragraph states the ruling on #37 as planned, with nothing in the canonical documents saying otherwise.

Model: opus-5-5

PASS: the example now names the package that `go install` takes, and the new paragraph states the ruling on https://git.eeqj.de/sneak/prompts/issues/37 as planned, with nothing in the canonical documents saying otherwise. Model: opus-5-5
clawbot added 1 commit 2026-10-04 09:17:44 +02:00
Writes sneak's 2026-09-09 ruling into the script/bootstrap bullet of
REPO_POLICIES.md: a Go tool a repo needs on the host is installed with
go install pinned to a commit hash, never tracked as a go.mod tool
dependency or through a tools.go file. golangci-lint is unchanged; it
stays pinned only by its image digest.

Model: opus-5-5
clawbot force-pushed issue-37-go-tool-pin from c5eb879140 to ade2b6211b 2026-10-04 09:17:44 +02:00 Compare
Author
Collaborator

Rebased onto current next and resolved the TODO.md conflict by keeping every Completed Steps entry, with this branch's entry first; nothing else changed.

Model: opus-5-5

Rebased onto current `next` and resolved the `TODO.md` conflict by keeping every Completed Steps entry, with this branch's entry first; nothing else changed. Model: opus-5-5
Author
Collaborator

PASS: after the rebase only the TODO.md entry changed position, it keeps Completed Steps newest first, and the script/bootstrap bullet of prompts/REPO_POLICIES.md states the ruling on #37 with nothing in the canonical documents saying otherwise.

Model: opus-5-5

PASS: after the rebase only the `TODO.md` entry changed position, it keeps Completed Steps newest first, and the `script/bootstrap` bullet of `prompts/REPO_POLICIES.md` states the ruling on https://git.eeqj.de/sneak/prompts/issues/37 with nothing in the canonical documents saying otherwise. Model: opus-5-5
clawbot merged commit c43c1f4bca into next 2026-10-04 09:49:14 +02:00
clawbot deleted branch issue-37-go-tool-pin 2026-10-04 09:49:14 +02:00
Sign in to join this conversation.