Add hash-pinned Dockerfile, .dockerignore, and Gitea CI workflow
Multistage build per policy: a fail-fast lint stage on the pinned golangci-lint image runs fmt-check and lint, the builder stage reuses its linter binary (which also forces stage ordering), runs make check, and builds; the runtime stage is pinned alpine with just the binary. CI runs docker build . on push with the checkout action pinned by commit SHA. All image references pinned by sha256 digest with version/date comments.
This commit is contained in:
8
.dockerignore
Normal file
8
.dockerignore
Normal file
@@ -0,0 +1,8 @@
|
||||
.git
|
||||
.claude
|
||||
.DS_Store
|
||||
sfdupes
|
||||
files.dat
|
||||
*.log
|
||||
*.out
|
||||
*.test
|
||||
Reference in New Issue
Block a user