script/lint now builds the new Dockerfile.lint, whose last step runs
golangci-lint. The build cache is off, so every run executes the
linter, and no image is kept. The Dockerfile lint stage calls
golangci-lint directly, since make lint is now a docker build of its
own. script/fmt no longer runs golangci-lint --fix, and
script/bootstrap no longer installs it. golangci-lint config verify is
left out: it fetches its schema over the network, unpinned. The README,
TODO.md and the script/cibuild comment say what now runs.
Model: opus-5-5