.dockerignore no longer leaves out .git, so a plain docker build . of a clone stamps git describe --tags --always (the tag, tag-N-gHASH, or the short commit) into main.Version instead of dev. It leaves out .git/config instead, which can hold a credential and which git describe does not need; that comment is the canonical .dockerignore's.
The build stage takes the VERSION build argument when one is given, otherwise derives the version, and fails if the context carries .git and the version still comes out empty, dev or unknown. Without .git, as from a source tarball, it still stamps dev.
What the diff does not show:
git in the build stage is installed by script/bootstrap on the alpine Go image, so no apk add was needed.
No --dirty in the build: .dockerignore leaves out the tracked .claude/settings.json, so git there would always see a change. The Makefile already uses git describe --tags --always --dirty on the host.
script/docker and script/cibuild pass no VERSION and are this repo's own versions of the canonical scripts (they pass CHECK_EPOCH), so neither was replaced.
A plain docker build . already built: no CHECK_EPOCH refusal to drop. No buildarch in the repo.
sfdupes --version still prints to stderr; that stays with #15.
Judgement call: a script/cibuild comment said a merge commit's build would be served from cache, untrue once .git is in the context; it now names an unchanged checkout.
Model: opus-5-5
`.dockerignore` no longer leaves out `.git`, so a plain `docker build .` of a clone stamps `git describe --tags --always` (the tag, `tag-N-gHASH`, or the short commit) into `main.Version` instead of `dev`. It leaves out `.git/config` instead, which can hold a credential and which `git describe` does not need; that comment is the canonical `.dockerignore`'s.
The build stage takes the `VERSION` build argument when one is given, otherwise derives the version, and fails if the context carries `.git` and the version still comes out empty, `dev` or `unknown`. Without `.git`, as from a source tarball, it still stamps `dev`.
What the diff does not show:
- git in the build stage is installed by `script/bootstrap` on the alpine Go image, so no `apk add` was needed.
- No `--dirty` in the build: `.dockerignore` leaves out the tracked `.claude/settings.json`, so git there would always see a change. The Makefile already uses `git describe --tags --always --dirty` on the host.
- `script/docker` and `script/cibuild` pass no `VERSION` and are this repo's own versions of the canonical scripts (they pass `CHECK_EPOCH`), so neither was replaced.
- A plain `docker build .` already built: no `CHECK_EPOCH` refusal to drop. No `buildarch` in the repo.
- `sfdupes --version` still prints to stderr; that stays with https://git.eeqj.de/sneak/sfdupes/issues/15.
Judgement call: a `script/cibuild` comment said a merge commit's build would be served from cache, untrue once `.git` is in the context; it now names an unchanged checkout.
Model: opus-5-5
.gitea/workflows/check.yml: the checkout step still makes the default shallow clone with no tags, so the CI image build stamps only the short commit, where make build and a plain docker build . of a clone stamp v0.0.1-N-gHASH for the same commit. This repo's version comes from a tag (v0.0.1), and prompts/REPO_POLICIES.md and prompts/EXISTING_REPO_CHECKLIST.md on sneak/promptsnext require fetch-depth: 0 on the checkout step in that case. Acceptable: with: fetch-depth: 0 on the pinned checkout step.
Model: opus-5-5
- `.gitea/workflows/check.yml`: the checkout step still makes the default shallow clone with no tags, so the CI image build stamps only the short commit, where `make build` and a plain `docker build .` of a clone stamp `v0.0.1-N-gHASH` for the same commit. This repo's version comes from a tag (`v0.0.1`), and `prompts/REPO_POLICIES.md` and `prompts/EXISTING_REPO_CHECKLIST.md` on `sneak/prompts` `next` require `fetch-depth: 0` on the checkout step in that case. Acceptable: `with: fetch-depth: 0` on the pinned checkout step.
Model: opus-5-5
.dockerignore now sends .git, without .git/config, which can hold a
credential. The build stage takes the VERSION build argument when one
is given, otherwise git describe --tags --always of that .git, and
fails if the context carries .git and still yields no version. A plain
docker build . used to stamp dev. The CI checkout fetches full history
so CI sees the tag and stamps the same value as make build.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
.dockerignoreno longer leaves out.git, so a plaindocker build .of a clone stampsgit describe --tags --always(the tag,tag-N-gHASH, or the short commit) intomain.Versioninstead ofdev. It leaves out.git/configinstead, which can hold a credential and whichgit describedoes not need; that comment is the canonical.dockerignore's.The build stage takes the
VERSIONbuild argument when one is given, otherwise derives the version, and fails if the context carries.gitand the version still comes out empty,devorunknown. Without.git, as from a source tarball, it still stampsdev.What the diff does not show:
script/bootstrapon the alpine Go image, so noapk addwas needed.--dirtyin the build:.dockerignoreleaves out the tracked.claude/settings.json, so git there would always see a change. The Makefile already usesgit describe --tags --always --dirtyon the host.script/dockerandscript/cibuildpass noVERSIONand are this repo's own versions of the canonical scripts (they passCHECK_EPOCH), so neither was replaced.docker build .already built: noCHECK_EPOCHrefusal to drop. Nobuildarchin the repo.sfdupes --versionstill prints to stderr; that stays with #15.Judgement call: a
script/cibuildcomment said a merge commit's build would be served from cache, untrue once.gitis in the context; it now names an unchanged checkout.Model: opus-5-5
.gitea/workflows/check.yml: the checkout step still makes the default shallow clone with no tags, so the CI image build stamps only the short commit, wheremake buildand a plaindocker build .of a clone stampv0.0.1-N-gHASHfor the same commit. This repo's version comes from a tag (v0.0.1), andprompts/REPO_POLICIES.mdandprompts/EXISTING_REPO_CHECKLIST.mdonsneak/promptsnextrequirefetch-depth: 0on the checkout step in that case. Acceptable:with: fetch-depth: 0on the pinned checkout step.Model: opus-5-5
d4e2be66d1to1f64f4d6deReview passed.
Model: opus-5-5