check / check (push) Waiting to run
The canonical documents told every repo to exclude .git from the build context, default ARG VERSION to dev and never run git describe in a build stage, so an image built from a clone with no build argument reported dev. .dockerignore now sends .git but keeps out .git/config, which can hold a credential. The Dockerfile example installs git, takes the VERSION build argument when one is given and otherwise git describe --tags --always, and fails when .git exists but the version is empty, dev or unknown. The policy and both checklists state the rule in the same words, including that a plain docker build . with no build arguments must succeed. Model: opus-5-5
60 lines
1.8 KiB
Docker
60 lines
1.8 KiB
Docker
# Lint phase. The linter is invoked directly rather than through `make
|
|
# lint` or `script/lint`, which are themselves a docker build and would
|
|
# recurse into a daemon that does not exist in a build step.
|
|
#
|
|
# node 22-alpine, 2026-02-22
|
|
FROM node@sha256:e4bf2a82ad0a4037d28035ae71529873c069b13eb0455466ae0bc13363826e34 AS lint
|
|
|
|
WORKDIR /app
|
|
|
|
COPY script/ script/
|
|
COPY package.json yarn.lock ./
|
|
RUN script/bootstrap
|
|
|
|
COPY . .
|
|
|
|
RUN yarn run prettier --check '**/*.md' --tab-width 4 --prose-wrap always
|
|
|
|
# Test phase, same shape and for the same reason.
|
|
#
|
|
# node 22-alpine, 2026-02-22
|
|
FROM node@sha256:e4bf2a82ad0a4037d28035ae71529873c069b13eb0455466ae0bc13363826e34 AS test
|
|
|
|
WORKDIR /app
|
|
|
|
COPY script/ script/
|
|
COPY package.json yarn.lock ./
|
|
RUN script/bootstrap
|
|
|
|
COPY . .
|
|
|
|
RUN echo "No tests defined."
|
|
|
|
# Development environment, and the last stage: a plain `docker build .`
|
|
# names no target and so builds this one. Nothing is wanted from the two
|
|
# phases above; the copies are what make BuildKit build them first, so
|
|
# this image cannot be produced unless lint and test passed. A stage
|
|
# appended after this one would drop all three out of a plain build.
|
|
#
|
|
# node 22-alpine, 2026-02-22
|
|
FROM node@sha256:e4bf2a82ad0a4037d28035ae71529873c069b13eb0455466ae0bc13363826e34
|
|
|
|
WORKDIR /app
|
|
|
|
COPY --from=lint /app/package.json /dev/null
|
|
COPY --from=test /app/package.json /dev/null
|
|
|
|
# script/bootstrap installs all prerequisites. Manifests are copied
|
|
# first so that layer stays cached until dependencies change.
|
|
COPY script/ script/
|
|
COPY package.json yarn.lock ./
|
|
RUN script/bootstrap
|
|
|
|
COPY . .
|
|
|
|
# Nothing here is compiled and a LABEL cannot run git, so the version is
|
|
# the VERSION build argument that script/docker and script/cibuild pass;
|
|
# a plain `docker build .` leaves it empty.
|
|
ARG VERSION
|
|
LABEL org.opencontainers.image.version="${VERSION}"
|