REPO_POLICIES.md (the Dockerfile rules, "All Dockerfiles must run make check" and "Dockerfiles must use a separate lint stage") is not met: the Dockerfile only compiles the binary. script/cibuild is docker build ., so today the container build checks nothing, and on the shared development host make lint cannot run at all because the installed golangci-lint was built with an older Go than the host toolchain. Every unit of #3 has to be gated on make check, so the container build must become the place where that gate runs.
Implementer's brief
Follow the standard Go pattern written out in REPO_POLICIES.md: a lint stage based on the golangci/golangci-lint image pinned by @sha256: with a version and date comment, running make fmt-check and make lint; the build stage forced to wait for it with COPY --from=lint /src/go.sum /dev/null; the build stage runs make check (or make test if lint and fmt-check already ran in the lint stage and the policy text allows it; follow the policy text) before the binary is built.
Pick a golangci-lint v2 image whose Go version can analyse this module (go.mod says go 1.24.4; .golangci.yml is version: "2").
Pin the existing base images (golang:1.24-bookworm, debian:bookworm-slim) by @sha256: with a version and date comment, as the policy requires, without changing their versions.
The tests run with -race, which needs cgo and a C compiler in the build stage; the builder already installs what the sqlite driver needs. Tests must not need the network (#4 makes the live test opt-in; this unit lands after it).
If the newly running linter reports problems in existing code: fix them if there are only a dozen or two; if there are many repetitive ones, stop and report on the PR. Do not change .golangci.yml.
Touch only Dockerfile and, if needed, .dockerignore, plus any lint fixes. No change to what the final image contains or how it starts.
Definition of done
make docker runs fmt-check, lint and the tests inside the build and fails when any of them fails.
make docker is green on current next.
All base images pinned by hash with version and date comments.
The final image is unchanged in content and behaviour.
The finishing commit's title ends with (closes #N) referencing this issue.
Model: fable-5-1
`REPO_POLICIES.md` (the Dockerfile rules, "All Dockerfiles must run `make check`" and "Dockerfiles must use a separate lint stage") is not met: the `Dockerfile` only compiles the binary. `script/cibuild` is `docker build .`, so today the container build checks nothing, and on the shared development host `make lint` cannot run at all because the installed `golangci-lint` was built with an older Go than the host toolchain. Every unit of https://git.eeqj.de/sneak/routewatch/issues/3 has to be gated on `make check`, so the container build must become the place where that gate runs.
## Implementer's brief
- Follow the standard Go pattern written out in `REPO_POLICIES.md`: a lint stage based on the `golangci/golangci-lint` image pinned by `@sha256:` with a version and date comment, running `make fmt-check` and `make lint`; the build stage forced to wait for it with `COPY --from=lint /src/go.sum /dev/null`; the build stage runs `make check` (or `make test` if lint and fmt-check already ran in the lint stage and the policy text allows it; follow the policy text) before the binary is built.
- Pick a `golangci-lint` v2 image whose Go version can analyse this module (`go.mod` says go 1.24.4; `.golangci.yml` is `version: "2"`).
- Pin the existing base images (`golang:1.24-bookworm`, `debian:bookworm-slim`) by `@sha256:` with a version and date comment, as the policy requires, without changing their versions.
- The tests run with `-race`, which needs cgo and a C compiler in the build stage; the builder already installs what the sqlite driver needs. Tests must not need the network (https://git.eeqj.de/sneak/routewatch/pulls/4 makes the live test opt-in; this unit lands after it).
- If the newly running linter reports problems in existing code: fix them if there are only a dozen or two; if there are many repetitive ones, stop and report on the PR. Do not change `.golangci.yml`.
- Touch only `Dockerfile` and, if needed, `.dockerignore`, plus any lint fixes. No change to what the final image contains or how it starts.
## Definition of done
1. `make docker` runs fmt-check, lint and the tests inside the build and fails when any of them fails.
2. `make docker` is green on current `next`.
3. All base images pinned by hash with version and date comments.
4. The final image is unchanged in content and behaviour.
The finishing commit's title ends with ` (closes #N)` referencing this issue.
Model: fable-5-1
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
REPO_POLICIES.md(the Dockerfile rules, "All Dockerfiles must runmake check" and "Dockerfiles must use a separate lint stage") is not met: theDockerfileonly compiles the binary.script/cibuildisdocker build ., so today the container build checks nothing, and on the shared development hostmake lintcannot run at all because the installedgolangci-lintwas built with an older Go than the host toolchain. Every unit of #3 has to be gated onmake check, so the container build must become the place where that gate runs.Implementer's brief
REPO_POLICIES.md: a lint stage based on thegolangci/golangci-lintimage pinned by@sha256:with a version and date comment, runningmake fmt-checkandmake lint; the build stage forced to wait for it withCOPY --from=lint /src/go.sum /dev/null; the build stage runsmake check(ormake testif lint and fmt-check already ran in the lint stage and the policy text allows it; follow the policy text) before the binary is built.golangci-lintv2 image whose Go version can analyse this module (go.modsays go 1.24.4;.golangci.ymlisversion: "2").golang:1.24-bookworm,debian:bookworm-slim) by@sha256:with a version and date comment, as the policy requires, without changing their versions.-race, which needs cgo and a C compiler in the build stage; the builder already installs what the sqlite driver needs. Tests must not need the network (#4 makes the live test opt-in; this unit lands after it)..golangci.yml.Dockerfileand, if needed,.dockerignore, plus any lint fixes. No change to what the final image contains or how it starts.Definition of done
make dockerruns fmt-check, lint and the tests inside the build and fails when any of them fails.make dockeris green on currentnext.The finishing commit's title ends with
(closes #N)referencing this issue.Model: fable-5-1
Implemented in #7 (base
next).Model: opus-4-8