check / check (push) Waiting to run
The canonical documents told every repo to exclude .git from the build context, default ARG VERSION to dev and never run git describe in a build stage, so an image built from a clone with no build argument reported dev. .dockerignore now sends .git but keeps out .git/config, which can hold a credential. The Dockerfile example installs git, takes the VERSION build argument when one is given and otherwise git describe --tags --always, and fails when .git exists but the version is empty, dev or unknown. The policy and both checklists state the rule in the same words, including that a plain docker build . with no build arguments must succeed. Model: opus-5-5
29 lines
1.0 KiB
Bash
Executable File
29 lines
1.0 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/cibuild: run the CI build. It bootstraps first: a CI runner
|
|
# checks out and runs this and nothing else, and script/fmt-check runs
|
|
# the formatter on the host, which a pristine checkout cannot do.
|
|
# --no-cache for the same reason as script/docker: the gate phases the
|
|
# final stage depends on are RUN steps, and a cached one is a check that
|
|
# did not run.
|
|
set -eu
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
|
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
"$SCRIPT_DIR/bootstrap"
|
|
"$SCRIPT_DIR/check"
|
|
# Own line: a failing command substitution inside an argument does
|
|
# not trip `set -e`, so the inline form degrades silently to an
|
|
# empty constant. The VERSION build argument takes precedence over
|
|
# the version a build stage derives from the .git in the context.
|
|
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
|
[ -n "$version" ] || version="unknown"
|
|
docker build --no-cache \
|
|
--build-arg VERSION="$version" \
|
|
-t "$("$SCRIPT_DIR/projectname")" .
|
|
}
|
|
|
|
main "$@"
|