docker build . stamps the git tag or short commit, not dev (closes #154) #157

Merged
clawbot merged 3 commits from issue-154-version-from-git into next 2026-10-02 06:12:57 +02:00
Collaborator

Closes #154

A plain docker build . labelled the image dev, and quak --version printed 0.0.0.

  • After tsc, script/build writes the version into dist/package.json; the repo's own package.json is untouched. A new script/version decides it: the VERSION environment variable or build arg when one is given, otherwise git describe --tags --always, otherwise package.json's version. git describe gives the tag on a tagged commit; the tag, the commits since it and the short commit on a later commit (v1.2.3-4-gabc1234); the short commit when no tag is reachable.
  • A checkout with .git whose version comes out empty, dev or unknown fails the build, as does a built CLI reporting anything else.
  • .dockerignore sends .git; ARG VERSION has no default. script/docker and script/cibuild keep passing the host's version, which takes precedence.
  • make build-bin bundles the built dist/, so the single binary reports the same version.

Worth knowing:

  • The image carries .git under /app without its config: .dockerignore lists .git/config, so the clone's remote URL and any credential stay out.
  • A shallow clone, as upaas makes, stamps a tag only when the cloned commit itself carries one, otherwise the short commit.
  • The org.opencontainers.image.version label carries only the build arg, so a plain docker build . leaves it empty.

Deviation: the final stage gets git from script/bootstrap, not a second apk add.
Judgement call: the version logic is its own script, so the tests run it without compiling.
Judgement call: the check keys on .git alone, so an explicit VERSION=dev fails too.
Not changed: REPO_POLICIES.md still says ARG VERSION=dev; it copies the shared policy, which sneak/prompts#69 changes first.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/quak/issues/154 A plain `docker build .` labelled the image `dev`, and `quak --version` printed `0.0.0`. - After `tsc`, `script/build` writes the version into `dist/package.json`; the repo's own `package.json` is untouched. A new `script/version` decides it: the `VERSION` environment variable or build arg when one is given, otherwise `git describe --tags --always`, otherwise `package.json`'s version. `git describe` gives the tag on a tagged commit; the tag, the commits since it and the short commit on a later commit (`v1.2.3-4-gabc1234`); the short commit when no tag is reachable. - A checkout with `.git` whose version comes out empty, `dev` or `unknown` fails the build, as does a built CLI reporting anything else. - `.dockerignore` sends `.git`; `ARG VERSION` has no default. `script/docker` and `script/cibuild` keep passing the host's version, which takes precedence. - `make build-bin` bundles the built `dist/`, so the single binary reports the same version. Worth knowing: - The image carries `.git` under `/app` without its config: `.dockerignore` lists `.git/config`, so the clone's remote URL and any credential stay out. - A shallow clone, as upaas makes, stamps a tag only when the cloned commit itself carries one, otherwise the short commit. - The `org.opencontainers.image.version` label carries only the build arg, so a plain `docker build .` leaves it empty. Deviation: the final stage gets `git` from `script/bootstrap`, not a second `apk add`. Judgement call: the version logic is its own script, so the tests run it without compiling. Judgement call: the check keys on `.git` alone, so an explicit `VERSION=dev` fails too. Not changed: `REPO_POLICIES.md` still says `ARG VERSION=dev`; it copies the shared policy, which https://git.eeqj.de/sneak/prompts/issues/69 changes first. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 03:24:51 +02:00
clawbot self-assigned this 2026-10-02 03:24:51 +02:00
Author
Collaborator

Review: fail.

  1. .dockerignore:5: .git/config is not excluded, which the addendum on #154 requires (canonical text: sneak/prompts#71). In webhooker the final image copies only the binary. In quak the build stage is the final image, so /app/.git/config ships in the image itself, along with the clone's remote URL and any credential in it. Acceptable: .dockerignore lists .git/config, and its comment says .git is sent without its config. test/packaging/build-context.test.ts asserts that entry, and the README Version section and the PR body say the image carries .git without its config. git describe works in this image without that file.

  2. README.md:198: "a shallow clone of one branch has no tags and stamps the short commit" is false when the cloned commit is tagged. A --depth 1 --branch clone fetches the tag on its tip and stamps the tag. Acceptable: a shallow clone stamps a tag only when the cloned commit itself carries one, and otherwise the short commit.

  3. src/index.ts:1: the comment "package.json is the one place the version is written" is no longer true. script/build now writes the version a build reports into dist/package.json. Acceptable: the comment says a build reports the version script/build stamps into dist/package.json, and that package.json's own version is reported only when running from source.

  4. TODO.md: conflicts with current next, because both add a Completed Steps entry. Rebase onto next.

Model: opus-5-5

Review: fail. 1. `.dockerignore:5`: `.git/config` is not excluded, which the addendum on https://git.eeqj.de/sneak/quak/issues/154 requires (canonical text: https://git.eeqj.de/sneak/prompts/issues/71). In webhooker the final image copies only the binary. In quak the build stage is the final image, so `/app/.git/config` ships in the image itself, along with the clone's remote URL and any credential in it. Acceptable: `.dockerignore` lists `.git/config`, and its comment says `.git` is sent without its config. `test/packaging/build-context.test.ts` asserts that entry, and the README Version section and the PR body say the image carries `.git` without its config. `git describe` works in this image without that file. 2. `README.md:198`: "a shallow clone of one branch has no tags and stamps the short commit" is false when the cloned commit is tagged. A `--depth 1 --branch` clone fetches the tag on its tip and stamps the tag. Acceptable: a shallow clone stamps a tag only when the cloned commit itself carries one, and otherwise the short commit. 3. `src/index.ts:1`: the comment "package.json is the one place the version is written" is no longer true. `script/build` now writes the version a build reports into `dist/package.json`. Acceptable: the comment says a build reports the version `script/build` stamps into `dist/package.json`, and that `package.json`'s own version is reported only when running from source. 4. `TODO.md`: conflicts with current `next`, because both add a Completed Steps entry. Rebase onto `next`. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-02 04:49:20 +02:00
clawbot force-pushed issue-154-version-from-git from 3c8377cb2c to 1efb02acd1 2026-10-02 05:07:08 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-02 05:07:14 +02:00
Author
Collaborator

Review: fail.

  1. TODO.md:28: conflicts with current next, which added the entry for #156 at the same place in Completed Steps. Acceptable: rebased onto next, keeping both entries.

  2. README.md:190: says git describe --tags --always gives "the tag on a tagged commit, otherwise the short commit". On a commit after a tag it gives the tag, the number of commits since it and the short commit (v1.2.3-4-gabc1234), so once a tag exists, every later build stamps a version this sentence rules out. The same words are in script/version:9 and test/packaging/version.test.ts:4. Acceptable: each place names the three cases, as the shared policy does: the tag on a tagged commit; the tag, the commits since it and the short commit on a later commit; the short commit when no tag is reachable.

Model: opus-5-5

Review: fail. 1. `TODO.md:28`: conflicts with current `next`, which added the entry for https://git.eeqj.de/sneak/quak/issues/156 at the same place in Completed Steps. Acceptable: rebased onto `next`, keeping both entries. 2. `README.md:190`: says `git describe --tags --always` gives "the tag on a tagged commit, otherwise the short commit". On a commit after a tag it gives the tag, the number of commits since it and the short commit (`v1.2.3-4-gabc1234`), so once a tag exists, every later build stamps a version this sentence rules out. The same words are in `script/version:9` and `test/packaging/version.test.ts:4`. Acceptable: each place names the three cases, as the shared policy does: the tag on a tagged commit; the tag, the commits since it and the short commit on a later commit; the short commit when no tag is reachable. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-02 05:50:59 +02:00
clawbot added 3 commits 2026-10-02 05:59:04 +02:00
script/build writes the version script/version prints into
dist/package.json, which quak --version reports: the VERSION environment
variable or build arg when one is given, otherwise git describe --tags
--always, otherwise package.json's version. A checkout with .git whose
version comes out empty, dev or unknown fails the build.

.dockerignore no longer leaves out .git, and ARG VERSION has no default,
so a plain docker build . of a clone stamps its commit. script/docker and
script/cibuild still pass the host's version. make build-bin bundles the
built dist/, so the single binary reports the same version.

Model: opus-5-5
.dockerignore lists .git/config, which holds the clone's remote URL and
any credential in it; the build stage is the final image, so it would
otherwise ship. git describe does not need it. The build-context test
asserts the entry, and the README says the image carries .git without
its config.

The README now says a shallow clone stamps a tag only when the cloned
commit itself carries one, and otherwise the short commit. The comment in
src/index.ts says a build reports the version script/build stamps into
dist/package.json, and package.json's own version only from source.

Model: opus-5-5
README, script/version and the version test's header said git describe
gives the tag or the short commit. On a commit after a tag it gives the
tag, the commits since it and the short commit; each place now names
that case too.

Model: opus-5-5
clawbot force-pushed issue-154-version-from-git from 1efb02acd1 to 29b6a34d13 2026-10-02 05:59:04 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-02 05:59:06 +02:00
Author
Collaborator

Review: pass.

Model: opus-5-5

Review: pass. Model: opus-5-5
clawbot merged commit 9e94542a57 into next 2026-10-02 06:12:57 +02:00
clawbot deleted branch issue-154-version-from-git 2026-10-02 06:12:57 +02:00
Sign in to join this conversation.