Multistage build per policy: a fail-fast lint stage on the pinned golangci-lint image runs fmt-check and lint, the builder stage reuses its linter binary (which also forces stage ordering), runs make check, and builds; the runtime stage is pinned alpine with just the binary. CI runs docker build . on push with the checkout action pinned by commit SHA. All image references pinned by sha256 digest with version/date comments.
9 lines
60 B
Plaintext
9 lines
60 B
Plaintext
.git
|
|
.claude
|
|
.DS_Store
|
|
sfdupes
|
|
files.dat
|
|
*.log
|
|
*.out
|
|
*.test
|