Run the linter only in Docker (closes #20)
check / check (push) Successful in 56s
check / check (pull_request) Successful in 51s

script/lint now builds the new Dockerfile.lint, whose last step runs
golangci-lint. The build cache is off, so every run executes the
linter, and no image is kept. The Dockerfile lint stage calls
golangci-lint directly, since make lint is now a docker build of its
own. script/fmt no longer runs golangci-lint --fix, and
script/bootstrap no longer installs it. golangci-lint config verify is
left out: it fetches its schema over the network, unpinned. The README,
TODO.md and the script/cibuild comment say what now runs.

Model: opus-5-5
This commit is contained in:
2026-10-06 03:11:54 +00:00
parent b28c0dca0c
commit 6932e3adce
8 changed files with 32 additions and 17 deletions
+1 -6
View File
@@ -54,12 +54,7 @@ main() {
if missing git; then pkg_install git git git git; fi
if missing go; then pkg_install go golang go go; fi
# golangci-lint is packaged in nix, brew, and apk; there is no apt
# package (on apt hosts, install it from a hash-verified GitHub
# release archive manually, never curl | sh).
if missing golangci-lint; then
pkg_install golangci-lint golangci-lint golangci-lint golangci-lint
fi
# golangci-lint is not installed: it runs only in docker (script/lint).
go mod download
+2 -2
View File
@@ -1,6 +1,6 @@
#!/bin/sh
# script/cibuild: run the CI build. The Dockerfile runs script/check, so
# a successful build implies all checks pass.
# script/cibuild: run the CI build. The Dockerfile runs the format check,
# the linter and the tests, so a successful build means they all pass.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
-1
View File
@@ -7,7 +7,6 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
goimports -l -w .
golangci-lint run --fix
}
main "$@"
+5 -2
View File
@@ -1,12 +1,15 @@
#!/bin/sh
# script/lint: run the linter.
# script/lint: run the linter, in docker only, by building Dockerfile.lint;
# the build fails on any finding. --no-cache makes every run execute the
# linter: a cached build of an unchanged tree succeeds without linting
# anything. --output type=cacheonly keeps no image.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
golangci-lint run
docker build --no-cache --output type=cacheonly -f Dockerfile.lint .
}
main "$@"