From 337b319542cdcaf9c2f445bf26f6aecb102a5487 Mon Sep 17 00:00:00 2001 From: sneak Date: Mon, 10 Aug 2026 14:06:47 +0000 Subject: [PATCH] Normalize the lint-image pin comments and FROM form (closes #25) The `(Debian-based)` parenthetical broke the required `# image:vX.Y.Z, YYYY-MM-DD` form and asserted a base change that never happened (v2.12.1 was Debian too); the tag before the digest left three FROM lines in one file using two conventions. Digest unchanged, in both Dockerfile and Dockerfile.lint. The golang and alpine pin comments already matched the required form. script/verify-lint-image-pin parses these two FROM lines to keep them identical and still matches the tagless form; its advice line drops the now-meaningless "tag and digest". With no tag in either reference a tag-only disagreement cannot arise; a tag reintroduced on one side is caught as a plain mismatch. --- Dockerfile | 4 ++-- Dockerfile.lint | 4 ++-- TODO.md | 12 ++++++++++++ script/verify-lint-image-pin | 6 +++--- 4 files changed, 19 insertions(+), 7 deletions(-) diff --git a/Dockerfile b/Dockerfile index 7e1f610..a6009f2 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ # Lint stage — fast feedback on formatting and lint issues -# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07 -FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint +# golangci/golangci-lint:v2.12.2, 2026-08-07 +FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint WORKDIR /src COPY go.mod go.sum ./ RUN go mod download diff --git a/Dockerfile.lint b/Dockerfile.lint index 836c725..aac1cb9 100644 --- a/Dockerfile.lint +++ b/Dockerfile.lint @@ -9,8 +9,8 @@ # stage of the main Dockerfile because script/lint must not depend on # the rest of that build; the two FROM lines are kept identical by # script/verify-lint-image-pin, run as a gate below. -# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07 -FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 +# golangci/golangci-lint:v2.12.2, 2026-08-07 +FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 WORKDIR /src diff --git a/TODO.md b/TODO.md index 235101c..3da0b6c 100644 --- a/TODO.md +++ b/TODO.md @@ -29,6 +29,18 @@ # Completed Steps +- fix the lint-image pin comments and `FROM` form in `Dockerfile` and + `Dockerfile.lint` (2026-08-10, branch `next`, closes + https://git.eeqj.de/sneak/sfdupes/issues/25): dropped the false + `(Debian-based)` parenthetical (v2.12.1 was Debian too) and the + redundant tag, so both pins are the policy `# image:vX.Y.Z, + YYYY-MM-DD` comment over a bare `FROM image@sha256:...`. Digest + unchanged. `script/verify-lint-image-pin` parses those `FROM` lines + and still matches the tagless form; its advice line lost the now + meaningless "tag and digest". With no tag in either reference, a + tag-only disagreement no longer exists — a one-sided tag is caught as + a plain mismatch. + - run all linting in Docker via `Dockerfile.lint` and `script/lint` (2026-08-10, branch `next`, closes https://git.eeqj.de/sneak/sfdupes/issues/46): per the owner ruling, the diff --git a/script/verify-lint-image-pin b/script/verify-lint-image-pin index ca6e488..fa30722 100755 --- a/script/verify-lint-image-pin +++ b/script/verify-lint-image-pin @@ -71,9 +71,9 @@ main() { "the two pins disagree:" >&2 echo "verify-lint-image-pin: $LINT_DOCKERFILE: $lint_ref" >&2 echo "verify-lint-image-pin: $MAIN_DOCKERFILE: $main_ref" >&2 - echo "verify-lint-image-pin: bump both FROM lines together, tag and" \ - "digest, so script/lint and the Dockerfile lint stage keep" \ - "running the same linter" >&2 + echo "verify-lint-image-pin: bump both FROM lines together so" \ + "script/lint and the Dockerfile lint stage keep running the" \ + "same linter" >&2 exit 1 fi