Add hash-pinned Dockerfile, .dockerignore, and Gitea CI workflow

Multistage build per policy: a fail-fast lint stage on the pinned
golangci-lint image runs fmt-check and lint, the builder stage reuses
its linter binary (which also forces stage ordering), runs make check,
and builds; the runtime stage is pinned alpine with just the binary.
CI runs docker build . on push with the checkout action pinned by
commit SHA. All image references pinned by sha256 digest with
version/date comments.
此提交包含在:
2026-07-23 06:42:11 +07:00
父節點 7a6adae0d2
當前提交 b4d013cb34
共有 3 個檔案被更改,包括 55 行新增0 行删除
+8
查看文件
@@ -0,0 +1,8 @@
.git
.claude
.DS_Store
sfdupes
files.dat
*.log
*.out
*.test