# Check stage: the full verification suite (fmt-check + lint + test) via
# `make check`, so any check failure fails the image build.
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS check
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN make check

# Build stage: compile on the Go toolchain the module targets. Copying
# from the check stage makes the build depend on it, so `docker build .`
# runs the checks first and only then builds.
# golang 1.22.12 (2025-02-04)
FROM golang@sha256:1cf6c45ba39db9fd6db16922041d074a63c935556a05c5ccb62d181034df7f02 AS build
COPY --from=check /src/go.sum /dev/null
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN go build ./... && go build -o /out/example ./cmd/example
