Send .git without its config; correct shallow-clone and version comments
check / check (push) Failing after 1m18s

.dockerignore lists .git/config, which holds the clone's remote URL and
any credential in it; the build stage is the final image, so it would
otherwise ship. git describe does not need it. The build-context test
asserts the entry, and the README says the image carries .git without
its config.

The README now says a shallow clone stamps a tag only when the cloned
commit itself carries one, and otherwise the short commit. The comment in
src/index.ts says a build reports the version script/build stamps into
dist/package.json, and package.json's own version only from source.

Model: opus-5-5
This commit is contained in:
2026-10-02 03:02:54 +00:00
parent eaf839442f
commit 1efb02acd1
4 changed files with 23 additions and 10 deletions
+9 -7
View File
@@ -195,13 +195,15 @@ The build fails if the checkout has `.git` and the version still comes out
empty, `dev` or `unknown`: such a build could not be traced back to its commit.
`.dockerignore` therefore does not leave out `.git`, so any `docker build .` of
a clone stamps the commit it was built from; a shallow clone of one branch has
no tags and stamps the short commit. `script/docker` (and so `make docker`) and
`script/cibuild` pass the version they resolve on the host, with `--dirty`, as
the build arg, which takes precedence. The image's
`org.opencontainers.image.version` label carries that build arg only, so a build
given none leaves it empty. `make build-bin` bundles the built `dist/`, so the
single binary reports the stamped version too.
a clone stamps the commit it was built from; a shallow clone stamps a tag only
when the cloned commit itself carries one, and otherwise the short commit. It
leaves out `.git/config`, which holds the clone's remote URL and any credential
in it, so the image carries `.git` without its config; `git describe` does not
need that file. `script/docker` (and so `make docker`) and `script/cibuild` pass
the version they resolve on the host, with `--dirty`, as the build arg, which
takes precedence. The image's `org.opencontainers.image.version` label carries
that build arg only, so a build given none leaves it empty. `make build-bin`
bundles the built `dist/`, so the single binary reports the stamped version too.
## Rationale