Normalize the lint-image pin comments and FROM form (closes #25)
All checks were successful
check / check (push) Successful in 1m9s
All checks were successful
check / check (push) Successful in 1m9s
The `(Debian-based)` parenthetical broke the required `# image:vX.Y.Z, YYYY-MM-DD` form and asserted a base change that never happened (v2.12.1 was Debian too); the tag before the digest left three FROM lines in one file using two conventions. Digest unchanged, in both Dockerfile and Dockerfile.lint. The golang and alpine pin comments already matched the required form. script/verify-lint-image-pin parses these two FROM lines to keep them identical and still matches the tagless form; its advice line drops the now-meaningless "tag and digest". With no tag in either reference a tag-only disagreement cannot arise; a tag reintroduced on one side is caught as a plain mismatch.
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
# Lint stage — fast feedback on formatting and lint issues
|
# Lint stage — fast feedback on formatting and lint issues
|
||||||
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
|
# golangci/golangci-lint:v2.12.2, 2026-08-07
|
||||||
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
|
FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -9,8 +9,8 @@
|
|||||||
# stage of the main Dockerfile because script/lint must not depend on
|
# stage of the main Dockerfile because script/lint must not depend on
|
||||||
# the rest of that build; the two FROM lines are kept identical by
|
# the rest of that build; the two FROM lines are kept identical by
|
||||||
# script/verify-lint-image-pin, run as a gate below.
|
# script/verify-lint-image-pin, run as a gate below.
|
||||||
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
|
# golangci/golangci-lint:v2.12.2, 2026-08-07
|
||||||
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240
|
FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240
|
||||||
|
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
|
|
||||||
|
|||||||
12
TODO.md
12
TODO.md
@@ -29,6 +29,18 @@
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- fix the lint-image pin comments and `FROM` form in `Dockerfile` and
|
||||||
|
`Dockerfile.lint` (2026-08-10, branch `next`, closes
|
||||||
|
https://git.eeqj.de/sneak/sfdupes/issues/25): dropped the false
|
||||||
|
`(Debian-based)` parenthetical (v2.12.1 was Debian too) and the
|
||||||
|
redundant tag, so both pins are the policy `# image:vX.Y.Z,
|
||||||
|
YYYY-MM-DD` comment over a bare `FROM image@sha256:...`. Digest
|
||||||
|
unchanged. `script/verify-lint-image-pin` parses those `FROM` lines
|
||||||
|
and still matches the tagless form; its advice line lost the now
|
||||||
|
meaningless "tag and digest". With no tag in either reference, a
|
||||||
|
tag-only disagreement no longer exists — a one-sided tag is caught as
|
||||||
|
a plain mismatch.
|
||||||
|
|
||||||
- run all linting in Docker via `Dockerfile.lint` and `script/lint`
|
- run all linting in Docker via `Dockerfile.lint` and `script/lint`
|
||||||
(2026-08-10, branch `next`, closes
|
(2026-08-10, branch `next`, closes
|
||||||
https://git.eeqj.de/sneak/sfdupes/issues/46): per the owner ruling, the
|
https://git.eeqj.de/sneak/sfdupes/issues/46): per the owner ruling, the
|
||||||
|
|||||||
@@ -71,9 +71,9 @@ main() {
|
|||||||
"the two pins disagree:" >&2
|
"the two pins disagree:" >&2
|
||||||
echo "verify-lint-image-pin: $LINT_DOCKERFILE: $lint_ref" >&2
|
echo "verify-lint-image-pin: $LINT_DOCKERFILE: $lint_ref" >&2
|
||||||
echo "verify-lint-image-pin: $MAIN_DOCKERFILE: $main_ref" >&2
|
echo "verify-lint-image-pin: $MAIN_DOCKERFILE: $main_ref" >&2
|
||||||
echo "verify-lint-image-pin: bump both FROM lines together, tag and" \
|
echo "verify-lint-image-pin: bump both FROM lines together so" \
|
||||||
"digest, so script/lint and the Dockerfile lint stage keep" \
|
"script/lint and the Dockerfile lint stage keep running the" \
|
||||||
"running the same linter" >&2
|
"same linter" >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user