Stamp the git tag or short commit in a plain docker build (closes #67) #68

Merged
clawbot merged 1 commits from issue-67-docker-version into next 2026-10-02 08:49:04 +02:00
Collaborator

.dockerignore no longer leaves out .git, so a plain docker build . of a clone stamps git describe --tags --always (the tag, tag-N-gHASH, or the short commit) into main.Version instead of dev. It leaves out .git/config instead, which can hold a credential and which git describe does not need; that comment is the canonical .dockerignore's.

The build stage takes the VERSION build argument when one is given, otherwise derives the version, and fails if the context carries .git and the version still comes out empty, dev or unknown. Without .git, as from a source tarball, it still stamps dev.

What the diff does not show:

  • git in the build stage is installed by script/bootstrap on the alpine Go image, so no apk add was needed.
  • No --dirty in the build: .dockerignore leaves out the tracked .claude/settings.json, so git there would always see a change. The Makefile already uses git describe --tags --always --dirty on the host.
  • script/docker and script/cibuild pass no VERSION and are this repo's own versions of the canonical scripts (they pass CHECK_EPOCH), so neither was replaced.
  • A plain docker build . already built: no CHECK_EPOCH refusal to drop. No buildarch in the repo.
  • sfdupes --version still prints to stderr; that stays with #15.

Judgement call: a script/cibuild comment said a merge commit's build would be served from cache, untrue once .git is in the context; it now names an unchanged checkout.

Model: opus-5-5

`.dockerignore` no longer leaves out `.git`, so a plain `docker build .` of a clone stamps `git describe --tags --always` (the tag, `tag-N-gHASH`, or the short commit) into `main.Version` instead of `dev`. It leaves out `.git/config` instead, which can hold a credential and which `git describe` does not need; that comment is the canonical `.dockerignore`'s. The build stage takes the `VERSION` build argument when one is given, otherwise derives the version, and fails if the context carries `.git` and the version still comes out empty, `dev` or `unknown`. Without `.git`, as from a source tarball, it still stamps `dev`. What the diff does not show: - git in the build stage is installed by `script/bootstrap` on the alpine Go image, so no `apk add` was needed. - No `--dirty` in the build: `.dockerignore` leaves out the tracked `.claude/settings.json`, so git there would always see a change. The Makefile already uses `git describe --tags --always --dirty` on the host. - `script/docker` and `script/cibuild` pass no `VERSION` and are this repo's own versions of the canonical scripts (they pass `CHECK_EPOCH`), so neither was replaced. - A plain `docker build .` already built: no `CHECK_EPOCH` refusal to drop. No `buildarch` in the repo. - `sfdupes --version` still prints to stderr; that stays with https://git.eeqj.de/sneak/sfdupes/issues/15. Judgement call: a `script/cibuild` comment said a merge commit's build would be served from cache, untrue once `.git` is in the context; it now names an unchanged checkout. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 07:19:21 +02:00
clawbot self-assigned this 2026-10-02 07:19:21 +02:00
Author
Collaborator
  • .gitea/workflows/check.yml: the checkout step still makes the default shallow clone with no tags, so the CI image build stamps only the short commit, where make build and a plain docker build . of a clone stamp v0.0.1-N-gHASH for the same commit. This repo's version comes from a tag (v0.0.1), and prompts/REPO_POLICIES.md and prompts/EXISTING_REPO_CHECKLIST.md on sneak/prompts next require fetch-depth: 0 on the checkout step in that case. Acceptable: with: fetch-depth: 0 on the pinned checkout step.

Model: opus-5-5

- `.gitea/workflows/check.yml`: the checkout step still makes the default shallow clone with no tags, so the CI image build stamps only the short commit, where `make build` and a plain `docker build .` of a clone stamp `v0.0.1-N-gHASH` for the same commit. This repo's version comes from a tag (`v0.0.1`), and `prompts/REPO_POLICIES.md` and `prompts/EXISTING_REPO_CHECKLIST.md` on `sneak/prompts` `next` require `fetch-depth: 0` on the checkout step in that case. Acceptable: `with: fetch-depth: 0` on the pinned checkout step. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-02 08:15:16 +02:00
clawbot added 1 commit 2026-10-02 08:34:36 +02:00
.dockerignore now sends .git, without .git/config, which can hold a
credential. The build stage takes the VERSION build argument when one
is given, otherwise git describe --tags --always of that .git, and
fails if the context carries .git and still yields no version. A plain
docker build . used to stamp dev. The CI checkout fetches full history
so CI sees the tag and stamps the same value as make build.

Model: opus-5-5
clawbot force-pushed issue-67-docker-version from d4e2be66d1 to 1f64f4d6de 2026-10-02 08:34:36 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-02 08:34:39 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit c9bf22d483 into next 2026-10-02 08:49:04 +02:00
clawbot deleted branch issue-67-docker-version 2026-10-02 08:49:04 +02:00
Sign in to join this conversation.