Every lint run now happens in docker through script/lint; no host golangci-lint path remains (#55).
New Dockerfile.lint, on the same pinned golangci-lint image as the Dockerfile lint stage: a deps stage downloads the modules, a lint stage copies the tree and runs golangci-lint run --config .golangci.yml ./... as a build step, so a successful build is a clean lint.
script/lint builds it with --no-cache-filter=lint, so the linter runs on every call, an unchanged tree included, while the module download stays cached. --target lint names the same stage, so renaming it fails the build instead of --no-cache-filter silently matching nothing. --output=type=cacheonly keeps no image.
Dockerfile lint stage: make lint is replaced by the same direct golangci-lint run, since make lint now starts a docker build. Stage order and script/cibuild with its memlock ulimit are unchanged, so script/cibuild still lints. The lint image runs no tests and needs no memlock ulimit.
script/bootstrap no longer installs golangci-lint; README.md Entrypoints and TODO.md updated.
golangci-lint config verify is left out: it fetches its JSON schema live over unpinned HTTPS, against the hash-pinning policy, and would fail lint on any network outage.
Deviation: the Dockerfile lint stage no longer runs make lint as the pattern in REPO_POLICIES.md shows; that shared file is left as is.
Unverified: make lint goes to the remote daemon the Makefile sets in DOCKER_HOST; only script/lint against the local daemon was run.
Not here: .golangci.yml (#66), the cached green in script/cibuild (#54).
Model: opus-5-5
Every lint run now happens in docker through `script/lint`; no host golangci-lint path remains (https://git.eeqj.de/sneak/secret/issues/55).
- New `Dockerfile.lint`, on the same pinned golangci-lint image as the `Dockerfile` lint stage: a `deps` stage downloads the modules, a `lint` stage copies the tree and runs `golangci-lint run --config .golangci.yml ./...` as a build step, so a successful build is a clean lint.
- `script/lint` builds it with `--no-cache-filter=lint`, so the linter runs on every call, an unchanged tree included, while the module download stays cached. `--target lint` names the same stage, so renaming it fails the build instead of `--no-cache-filter` silently matching nothing. `--output=type=cacheonly` keeps no image.
- `Dockerfile` lint stage: `make lint` is replaced by the same direct `golangci-lint run`, since `make lint` now starts a docker build. Stage order and `script/cibuild` with its memlock ulimit are unchanged, so `script/cibuild` still lints. The lint image runs no tests and needs no memlock ulimit.
- `script/bootstrap` no longer installs golangci-lint; `README.md` Entrypoints and `TODO.md` updated.
`golangci-lint config verify` is left out: it fetches its JSON schema live over unpinned HTTPS, against the hash-pinning policy, and would fail lint on any network outage.
Deviation: the `Dockerfile` lint stage no longer runs `make lint` as the pattern in `REPO_POLICIES.md` shows; that shared file is left as is.
Unverified: `make lint` goes to the remote daemon the `Makefile` sets in `DOCKER_HOST`; only `script/lint` against the local daemon was run.
Not here: `.golangci.yml` (https://git.eeqj.de/sneak/secret/issues/66), the cached green in `script/cibuild` (https://git.eeqj.de/sneak/secret/issues/54).
Model: opus-5-5
PASS: script/lint now runs golangci-lint only in docker on every run. The main Dockerfile still lints, and nothing installs or runs golangci-lint on the host.
Rebase: TODO.md conflicts with current next. Both sides add a Completed Steps entry, so keep both. I resolved it locally to review the code.
Unverified: make lint against the remote docker daemon the Makefile sets in DOCKER_HOST.
Model: opus-5-5
PASS: `script/lint` now runs golangci-lint only in docker on every run. The main `Dockerfile` still lints, and nothing installs or runs golangci-lint on the host.
- Rebase: `TODO.md` conflicts with current `next`. Both sides add a Completed Steps entry, so keep both. I resolved it locally to review the code.
- Unverified: `make lint` against the remote docker daemon the `Makefile` sets in `DOCKER_HOST`.
Model: opus-5-5
script/lint builds the new Dockerfile.lint, where golangci-lint runs as
a build step. The lint stage is rebuilt on every run, so an unchanged
tree is linted too; the module download stays cached. script/bootstrap
no longer installs golangci-lint. The Dockerfile lint stage calls
golangci-lint directly, since make lint now starts a docker build.
golangci-lint config verify is not run: it fetches its schema live over
unpinned HTTPS.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Every lint run now happens in docker through
script/lint; no host golangci-lint path remains (#55).Dockerfile.lint, on the same pinned golangci-lint image as theDockerfilelint stage: adepsstage downloads the modules, alintstage copies the tree and runsgolangci-lint run --config .golangci.yml ./...as a build step, so a successful build is a clean lint.script/lintbuilds it with--no-cache-filter=lint, so the linter runs on every call, an unchanged tree included, while the module download stays cached.--target lintnames the same stage, so renaming it fails the build instead of--no-cache-filtersilently matching nothing.--output=type=cacheonlykeeps no image.Dockerfilelint stage:make lintis replaced by the same directgolangci-lint run, sincemake lintnow starts a docker build. Stage order andscript/cibuildwith its memlock ulimit are unchanged, soscript/cibuildstill lints. The lint image runs no tests and needs no memlock ulimit.script/bootstrapno longer installs golangci-lint;README.mdEntrypoints andTODO.mdupdated.golangci-lint config verifyis left out: it fetches its JSON schema live over unpinned HTTPS, against the hash-pinning policy, and would fail lint on any network outage.Deviation: the
Dockerfilelint stage no longer runsmake lintas the pattern inREPO_POLICIES.mdshows; that shared file is left as is.Unverified:
make lintgoes to the remote daemon theMakefilesets inDOCKER_HOST; onlyscript/lintagainst the local daemon was run.Not here:
.golangci.yml(#66), the cached green inscript/cibuild(#54).Model: opus-5-5
PASS:
script/lintnow runs golangci-lint only in docker on every run. The mainDockerfilestill lints, and nothing installs or runs golangci-lint on the host.TODO.mdconflicts with currentnext. Both sides add a Completed Steps entry, so keep both. I resolved it locally to review the code.make lintagainst the remote docker daemon theMakefilesets inDOCKER_HOST.Model: opus-5-5
a75dc54b78tofc115f31b5fc115f31b5to9d4259afa3