From b4d013cb3461b7d30e044e4f36ae30d888480cd9 Mon Sep 17 00:00:00 2001 From: sneak Date: Thu, 23 Jul 2026 06:42:11 +0700 Subject: [PATCH] Add hash-pinned Dockerfile, .dockerignore, and Gitea CI workflow Multistage build per policy: a fail-fast lint stage on the pinned golangci-lint image runs fmt-check and lint, the builder stage reuses its linter binary (which also forces stage ordering), runs make check, and builds; the runtime stage is pinned alpine with just the binary. CI runs docker build . on push with the checkout action pinned by commit SHA. All image references pinned by sha256 digest with version/date comments. --- .dockerignore | 8 ++++++++ .gitea/workflows/check.yml | 9 +++++++++ Dockerfile | 38 ++++++++++++++++++++++++++++++++++++++ 3 files changed, 55 insertions(+) create mode 100644 .dockerignore create mode 100644 .gitea/workflows/check.yml create mode 100644 Dockerfile diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..3522d5b --- /dev/null +++ b/.dockerignore @@ -0,0 +1,8 @@ +.git +.claude +.DS_Store +sfdupes +files.dat +*.log +*.out +*.test diff --git a/.gitea/workflows/check.yml b/.gitea/workflows/check.yml new file mode 100644 index 0000000..aca7a51 --- /dev/null +++ b/.gitea/workflows/check.yml @@ -0,0 +1,9 @@ +name: check +on: [push] +jobs: + check: + runs-on: ubuntu-latest + steps: + # actions/checkout v4.2.2, 2026-02-22 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 + - run: docker build . diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..99711b7 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,38 @@ +# Lint stage — fast feedback on formatting and lint issues +# golangci/golangci-lint:v2.12.1, 2026-07-23 +FROM golangci/golangci-lint@sha256:c9843d374ca80ecbac86081ec4dd7fe2bb6187b03224f59a0cc2f80759e1845b AS lint +WORKDIR /src +COPY go.mod go.sum ./ +RUN go mod download +COPY . . +RUN make fmt-check +RUN make lint + +# Build stage +# golang:1.25-alpine, 2026-07-23 +FROM golang@sha256:56961d79ea8129efddcc0b8643fd8a5416b4e6228cfd477e3fd61deb2672c587 AS builder + +RUN apk add --no-cache make + +WORKDIR /src + +# Reuse the linter binary from the lint stage; the copy also forces +# BuildKit to complete linting before this stage proceeds. +COPY --from=lint /usr/bin/golangci-lint /usr/local/bin/golangci-lint + +COPY go.mod go.sum ./ +RUN go mod download +COPY . . + +# Fail the build unless the branch is green. +RUN make check + +RUN make build + +# Runtime stage +# alpine:3.22, 2026-07-23 +FROM alpine@sha256:14358309a308569c32bdc37e2e0e9694be33a9d99e68afb0f5ff33cc1f695dce + +COPY --from=builder /src/sfdupes /usr/local/bin/sfdupes + +ENTRYPOINT ["sfdupes"]