Run the checks again on every script/cibuild (closes #54)
check / check (push) Failing after 1s

On an unchanged tree docker served every check step of the Dockerfile
from its build cache, so a second script/cibuild ran no lint, tests or
build and still succeeded.

script/cibuild now passes the current time as the CHECK_EPOCH build
argument. The lint and build stages each declare it after their module
download and before `COPY . .`. A build argument whose value changes
makes every RUN step after its declaration miss the cache, so the
checks run on each build while the base images, the apk install and the
module downloads stay cached.

Model: opus-5-5
This commit is contained in:
2026-10-04 09:33:49 +00:00
parent 4ed77902d1
commit b128da7a85
4 changed files with 23 additions and 2 deletions
+8
View File
@@ -25,6 +25,14 @@ Bring the repo into policy compliance in one commit:
# Completed Steps
- 2026-10-04: `script/cibuild` runs the checks again on an unchanged
tree (https://git.eeqj.de/sneak/secret/issues/54). It passes the
current time as the `CHECK_EPOCH` build argument, which both the lint
and the build stage of the `Dockerfile` declare after their module
download, so every step from `COPY . .` on runs on each build while
the base images and module downloads stay cached. Before, a second run
on the same tree took every check from the build cache and reported
success having run nothing.
- 2026-10-04: `secret get` keeps the secret in locked memory until it
writes it out (https://git.eeqj.de/sneak/secret/issues/37):
`Vault.GetSecret` and `Vault.GetSecretVersion` return a