From ade2b6211b76c27ac2b1744a1d1dc79cb58ed64c Mon Sep 17 00:00:00 2001 From: sneak Date: Sun, 4 Oct 2026 06:03:35 +0000 Subject: [PATCH] Pin host Go tools by commit hash with go install (closes #37) Writes sneak's 2026-09-09 ruling into the script/bootstrap bullet of REPO_POLICIES.md: a Go tool a repo needs on the host is installed with go install pinned to a commit hash, never tracked as a go.mod tool dependency or through a tools.go file. golangci-lint is unchanged; it stays pinned only by its image digest. Model: opus-5-5 --- TODO.md | 4 ++++ prompts/REPO_POLICIES.md | 5 +++++ 2 files changed, 9 insertions(+) diff --git a/TODO.md b/TODO.md index ad4785c..02562bc 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,10 @@ fmt-check, and commit. # Completed Steps +- 2026-10-04: `REPO_POLICIES.md` now says how a Go tool a repo needs on the host + is pinned (issue 37): installed with `go install` pinned to a commit hash, + never tracked as a `go.mod` tool dependency or through a `tools.go` file. + golangci-lint is unaffected, since no repo installs it on the host. - 2026-10-04: The canonical `.gitignore` and `.dockerignore` now also keep out `id_ecdsa_sk` and `id_ed25519_sk`, the private key files `ssh-keygen` writes for keys backed by a hardware security key (issue 81). Their `.pub` halves diff --git a/prompts/REPO_POLICIES.md b/prompts/REPO_POLICIES.md index af0ea80..c66b459 100644 --- a/prompts/REPO_POLICIES.md +++ b/prompts/REPO_POLICIES.md @@ -495,6 +495,11 @@ style conventions are in separate documents: Keep it POSIX sh: no arrays, no `[[`, no `grep -P`. + A Go tool a repo needs on the host is installed with `go install` pinned to + a commit hash (`go install @`). It is never tracked as + a `go.mod` tool dependency or through a `tools.go` file, either of which + pulls the tool's own dependencies into the repo's `go.mod` and `go.sum`. + - When pinning images or packages by hash, add a comment above the reference with the version and date (YYYY-MM-DD). -- 2.54.0