Stamp the tag or short commit in a plain docker build (closes #21)
check / check (push) Successful in 1m9s

A plain `docker build .` of a clone stamped `dev`: `.dockerignore` left
out `.git` and the build stage declared `ARG VERSION=dev`. `.git` now
reaches the build context without `.git/config`, which can hold a
credential, and the build stage takes the VERSION build argument when
given, otherwise `git describe --tags --always`. A context that carries
`.git` but yields no version fails the build.

`script/docker` is replaced with the current canonical copy, which
passes the version it derives on the host.

Model: opus-5-5
This commit is contained in:
clawbot
2026-10-02 04:24:43 +00:00
parent fa2aa09769
commit 1b7a939c11
4 changed files with 37 additions and 7 deletions
+6 -1
View File
@@ -3,7 +3,6 @@
# an exclusion here makes them pass over a tree that is missing a
# package. script/assert-context-complete exists to catch exactly that,
# and will fail the build rather than let it happen silently.
.git/
.gitea/
bin/
data/
@@ -24,3 +23,9 @@ LICENSE
.vscode/
tmp/
temp/
# .git is sent without its config. Without a VERSION build argument the
# stage that compiles runs `git describe --tags --always` on .git, which
# does not need .git/config; that file can hold a credential, such as a
# password in a remote URL or the token the CI checkout step stores there.
.git/config