# Lint stage — fast feedback on formatting and lint issues # golangci/golangci-lint:v2.12.1, 2026-07-23 FROM golangci/golangci-lint@sha256:c9843d374ca80ecbac86081ec4dd7fe2bb6187b03224f59a0cc2f80759e1845b AS lint WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . RUN make fmt-check RUN make lint # Build stage # golang:1.25-alpine, 2026-07-23 FROM golang@sha256:56961d79ea8129efddcc0b8643fd8a5416b4e6228cfd477e3fd61deb2672c587 AS builder RUN apk add --no-cache make # We never build or run as root. Create an unprivileged user and point # HOME and the Go caches at its home so go build/test and golangci-lint # can write their caches when we drop to it below. RUN adduser -D -u 1000 builder ENV HOME=/home/builder ENV GOPATH=/home/builder/go ENV GOCACHE=/home/builder/.cache/go-build WORKDIR /src # Reuse the linter binary from the lint stage; the copy also forces # BuildKit to complete linting before this stage proceeds. COPY --from=lint /usr/bin/golangci-lint /usr/local/bin/golangci-lint COPY go.mod go.sum ./ RUN go mod download COPY . . # Hand the sources and caches to the unprivileged user, then drop root # before running any checks or builds. RUN chown -R builder:builder /src /home/builder USER builder # Fail the build unless the branch is green. Runs as non-root so the # permission-denied test paths are exercised legitimately (root would # bypass the chmod(0) the tests rely on). RUN make check RUN make build # Runtime stage # alpine:3.22, 2026-07-23 FROM alpine@sha256:14358309a308569c32bdc37e2e0e9694be33a9d99e68afb0f5ff33cc1f695dce COPY --from=builder /src/sfdupes /usr/local/bin/sfdupes ENTRYPOINT ["sfdupes"]