Run the checks again on every script/cibuild (closes #54)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
On an unchanged tree docker served every check step of the Dockerfile from its build cache, so a second script/cibuild ran no lint, tests or build and still succeeded. script/cibuild now passes the current time as the CHECK_EPOCH build argument. The lint and build stages each declare it after their module download and before `COPY . .`. A build argument whose value changes makes every RUN step after its declaration miss the cache, so the checks run on each build while the base images, the apk install and the module downloads stay cached. Model: opus-5-5
This commit was merged in pull request #92.
This commit is contained in:
@@ -25,6 +25,14 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `script/cibuild` runs the checks again on an unchanged
|
||||
tree (https://git.eeqj.de/sneak/secret/issues/54). It passes the
|
||||
current time as the `CHECK_EPOCH` build argument, which both the lint
|
||||
and the build stage of the `Dockerfile` declare after their module
|
||||
download, so the `RUN` steps below the argument run again on each
|
||||
build while the base images and module downloads stay cached. Before,
|
||||
a second run on the same tree took every check from the build cache
|
||||
and reported success having run nothing.
|
||||
- 2026-10-04: A failed unlocker add no longer leaves a partial unlocker
|
||||
directory (https://git.eeqj.de/sneak/secret/issues/48).
|
||||
`secret unlocker add pgp` resolves the GPG key's fingerprint once, for
|
||||
|
||||
Reference in New Issue
Block a user