check / check (push) Failing after 1s
script/lint-darwin (make lint-darwin; run by script/check, and its commands by the Dockerfile lint stage) runs go vet and golangci-lint with GOOS=darwin and cgo off. Compiling cgo for macOS needs Apple's SDK, and keychainunlocker.go uses go-keychain, which is cgo there, so it and its tests are now built only with cgo on macOS, like internal/macse; their stubs serve a macOS build without cgo. checkMacOSAvailable moves to seunlocker_darwin.go. The findings in the newly checked files are fixed, and lines over 88 columns in the unchecked ones are wrapped. Model: opus-5-5
30 lines
1002 B
Docker
30 lines
1002 B
Docker
# Lint image, built by script/lint and script/lint-darwin: golangci-lint runs
|
|
# as a build step, so a successful build is a clean lint. Works where the
|
|
# docker daemon is remote and bind mounts are impossible.
|
|
|
|
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
|
|
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS deps
|
|
|
|
WORKDIR /src
|
|
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
# script/lint rebuilds this stage on every run, by this name; the module
|
|
# download above stays cached.
|
|
FROM deps AS lint
|
|
|
|
COPY . .
|
|
|
|
RUN golangci-lint run --config .golangci.yml ./...
|
|
|
|
# script/lint-darwin rebuilds this stage on every run, by this name. It
|
|
# checks the code as a macOS build compiles it, but with cgo off, which
|
|
# leaves out the files that need cgo on macOS (see script/lint-darwin).
|
|
FROM deps AS lint-darwin
|
|
|
|
COPY . .
|
|
|
|
RUN GOOS=darwin CGO_ENABLED=0 go vet ./...
|
|
RUN GOOS=darwin CGO_ENABLED=0 golangci-lint run --config .golangci.yml ./...
|