The stage that compiles has git and takes the version from the VERSION build argument when one is given, otherwise from git describe --tags --always (a tag when the commit has one, otherwise the short commit). ARG VERSION has no default.
The build fails if the context carries .git and the version still comes out empty, dev or unknown.
Host-side scripts that already pass --build-arg VERSION=... may keep doing so.
Any buildarch left in the repo goes too (sneak/project-management#19): the architecture is read at run time from runtime.GOARCH.
Definition of done:
A fresh clone, then docker build . with no build arguments, then running the binary: quak --version shows the commit's tag or short commit, never dev, unknown or empty.
docker build --build-arg VERSION=x . stamps x; a context with .git from which no version can be derived fails the build.
make check passes; PR to next; independent review; squash.
Model: opus-5-5
Owner's words (chat, 2026-10-02 ~00:00 UTC; the rollout across repos is https://git.eeqj.de/sneak/project-management/issues/21):
> main.Version on sneak/api is set to "dev" instead of the git hash when being built under upaas, fix that
> audit all other repos for that same bug. "docker build ." should pick up the git short rev or tag
Today: the CLI reports the `version` from `package.json` (`0.0.0`), not the commit, and the image label is `dev`; `.dockerignore` excludes `.git`.
The convention (canonical text: https://git.eeqj.de/sneak/prompts/issues/69; working examples: https://git.eeqj.de/sneak/upaas/pulls/242, https://git.eeqj.de/sneak/webhooker/pulls/410):
- `.dockerignore` lets `.git` into the build context.
- The stage that compiles has `git` and takes the version from the `VERSION` build argument when one is given, otherwise from `git describe --tags --always` (a tag when the commit has one, otherwise the short commit). `ARG VERSION` has no default.
- The build fails if the context carries `.git` and the version still comes out empty, `dev` or `unknown`.
- Host-side scripts that already pass `--build-arg VERSION=...` may keep doing so.
- Any `buildarch` left in the repo goes too (https://git.eeqj.de/sneak/project-management/issues/19): the architecture is read at run time from `runtime.GOARCH`.
Definition of done:
- A fresh clone, then `docker build .` with no build arguments, then running the binary: `quak --version` shows the commit's tag or short commit, never `dev`, `unknown` or empty.
- `docker build --build-arg VERSION=x .` stamps `x`; a context with `.git` from which no version can be derived fails the build.
- `make check` passes; PR to `next`; independent review; squash.
Model: opus-5-5
Where quak's version lives.quak --version prints VERSION, which src/index.ts reads from package.json (0.0.0). tsc copies that file to dist/package.json, and the built CLI reads it from there.
Stamping. After tsc, script/build writes the version into the version field of dist/package.json. The repo's own package.json and the tests are untouched. The version comes from the VERSION environment variable or build argument when one is given. Otherwise it comes from git describe --tags --always, which gives the tag on a tagged commit and the short commit otherwise.
Failing.script/build's existing version check fails the build when .git is present and the version comes out empty, dev or unknown. It also fails if the built CLI does not report the stamped version.
Docker.
.dockerignore stops excluding .git, with one comment saying why it is sent.
The final stage installs git (apk add --no-cache git) and declares ARG VERSION with no default.
script/docker and script/cibuild keep passing the version they compute on the host.
Comments that say .git is excluded are corrected.
make build-bin (the bun single binary) stamps the same way, or the README says plainly what it reports.
Tests and docs. The --version tests cover the stamped version and the failure. README states how the version is set. quak has no buildarch.
Standing rule: quak is pre-1.0, so there is no compatibility shim.
Model: opus-5-5
Plan, following the convention in https://git.eeqj.de/sneak/prompts/issues/69 and the examples in https://git.eeqj.de/sneak/webhooker/pulls/410 and https://git.eeqj.de/sneak/upaas/pulls/242.
- **Where quak's version lives.** `quak --version` prints `VERSION`, which `src/index.ts` reads from `package.json` (`0.0.0`). `tsc` copies that file to `dist/package.json`, and the built CLI reads it from there.
- **Stamping.** After `tsc`, `script/build` writes the version into the `version` field of `dist/package.json`. The repo's own `package.json` and the tests are untouched. The version comes from the `VERSION` environment variable or build argument when one is given. Otherwise it comes from `git describe --tags --always`, which gives the tag on a tagged commit and the short commit otherwise.
- **Failing.** `script/build`'s existing version check fails the build when `.git` is present and the version comes out empty, `dev` or `unknown`. It also fails if the built CLI does not report the stamped version.
- **Docker.**
- `.dockerignore` stops excluding `.git`, with one comment saying why it is sent.
- The final stage installs `git` (`apk add --no-cache git`) and declares `ARG VERSION` with no default.
- `script/docker` and `script/cibuild` keep passing the version they compute on the host.
- Comments that say `.git` is excluded are corrected.
- **`make build-bin`** (the bun single binary) stamps the same way, or the README says plainly what it reports.
- **Tests and docs.** The `--version` tests cover the stamped version and the failure. README states how the version is set. quak has no `buildarch`.
Standing rule: quak is pre-1.0, so there is no compatibility shim.
Model: opus-5-5
clawbot
self-assigned this 2026-10-02 02:22:51 +02:00
.dockerignore lists .git/config: with .git in the build context, a clone whose remote URL carries a credential would otherwise send it into the build, where it stays in the builder stage's layers. git describe does not need that file.
A plain docker build . with no build arguments must succeed (that is how upaas builds); a Dockerfile that refuses an empty build argument drops only that refusal.
Model: opus-5-5
Addendum to the convention (https://git.eeqj.de/sneak/project-management/issues/21):
- `.dockerignore` lists `.git/config`: with `.git` in the build context, a clone whose remote URL carries a credential would otherwise send it into the build, where it stays in the builder stage's layers. `git describe` does not need that file.
- A plain `docker build .` with no build arguments must succeed (that is how upaas builds); a Dockerfile that refuses an empty build argument drops only that refusal.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Owner's words (chat, 2026-10-02 ~00:00 UTC; the rollout across repos is sneak/project-management#21):
Today: the CLI reports the
versionfrompackage.json(0.0.0), not the commit, and the image label isdev;.dockerignoreexcludes.git.The convention (canonical text: sneak/prompts#69; working examples: sneak/upaas#242, sneak/webhooker#410):
.dockerignorelets.gitinto the build context.gitand takes the version from theVERSIONbuild argument when one is given, otherwise fromgit describe --tags --always(a tag when the commit has one, otherwise the short commit).ARG VERSIONhas no default..gitand the version still comes out empty,devorunknown.--build-arg VERSION=...may keep doing so.buildarchleft in the repo goes too (sneak/project-management#19): the architecture is read at run time fromruntime.GOARCH.Definition of done:
docker build .with no build arguments, then running the binary:quak --versionshows the commit's tag or short commit, neverdev,unknownor empty.docker build --build-arg VERSION=x .stampsx; a context with.gitfrom which no version can be derived fails the build.make checkpasses; PR tonext; independent review; squash.Model: opus-5-5
Plan, following the convention in sneak/prompts#69 and the examples in sneak/webhooker#410 and sneak/upaas#242.
quak --versionprintsVERSION, whichsrc/index.tsreads frompackage.json(0.0.0).tsccopies that file todist/package.json, and the built CLI reads it from there.tsc,script/buildwrites the version into theversionfield ofdist/package.json. The repo's ownpackage.jsonand the tests are untouched. The version comes from theVERSIONenvironment variable or build argument when one is given. Otherwise it comes fromgit describe --tags --always, which gives the tag on a tagged commit and the short commit otherwise.script/build's existing version check fails the build when.gitis present and the version comes out empty,devorunknown. It also fails if the built CLI does not report the stamped version..dockerignorestops excluding.git, with one comment saying why it is sent.git(apk add --no-cache git) and declaresARG VERSIONwith no default.script/dockerandscript/cibuildkeep passing the version they compute on the host..gitis excluded are corrected.make build-bin(the bun single binary) stamps the same way, or the README says plainly what it reports.--versiontests cover the stamped version and the failure. README states how the version is set. quak has nobuildarch.Standing rule: quak is pre-1.0, so there is no compatibility shim.
Model: opus-5-5
Addendum to the convention (sneak/project-management#21):
.dockerignorelists.git/config: with.gitin the build context, a clone whose remote URL carries a credential would otherwise send it into the build, where it stays in the builder stage's layers.git describedoes not need that file.docker build .with no build arguments must succeed (that is how upaas builds); a Dockerfile that refuses an empty build argument drops only that refusal.Model: opus-5-5