# Lint image, built by script/lint and script/lint-darwin: golangci-lint runs # as a build step, so a successful build is a clean lint. Works where the # docker daemon is remote and bind mounts are impossible. # golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07 FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS deps WORKDIR /src COPY go.mod go.sum ./ RUN go mod download # script/lint rebuilds this stage on every run, by this name; the module # download above stays cached. FROM deps AS lint COPY . . RUN golangci-lint run --config .golangci.yml ./... # script/lint-darwin rebuilds this stage on every run, by this name. It # checks the code as a macOS build compiles it, but with cgo off, which # leaves out the files that need cgo on macOS (see script/lint-darwin). FROM deps AS lint-darwin COPY . . RUN GOOS=darwin CGO_ENABLED=0 go vet ./... RUN GOOS=darwin CGO_ENABLED=0 golangci-lint run --config .golangci.yml ./...