Run all linting in Docker via Dockerfile.lint (closes #188)
Check / check (pull_request) Skipped
Check / check (pull_request) Skipped
golangci-lint now runs only in Docker. New Dockerfile.lint (pinned golangci-lint v2.12.2) COPYs the tree and runs the linter as a build step; script/lint just builds it. A GATE_RUN build arg differs every run, so the lint layer always executes -- a cached build would exit 0 having linted nothing. config verify is deliberately omitted: it fetches its JSON schema over an unpinned live HTTPS call, which REPO_POLICIES.md forbids. script/bootstrap no longer installs golangci-lint (goimports kept). The main Dockerfile lint stage now invokes golangci-lint directly rather than make lint, so building it is not docker-in-docker. Model: opus-4-8
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
# Lint image — runs golangci-lint inside a container so every lint uses
|
||||
# the pinned linter, never a host binary. Linting is a build step, so a
|
||||
# successful build is a clean lint. Built by script/lint.
|
||||
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
|
||||
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY . .
|
||||
|
||||
# Caching is waived for linting: on an unchanged tree a cached build runs
|
||||
# no linter and still exits 0 in under a second. script/lint passes a
|
||||
# fresh GATE_RUN every time, and referencing it here forces this step to
|
||||
# re-run, so the linter always executes.
|
||||
#
|
||||
# `golangci-lint config verify` is deliberately NOT run: it fetches its
|
||||
# JSON schema over an unpinned live HTTPS call, which REPO_POLICIES.md
|
||||
# forbids (all external references must be pinned by hash).
|
||||
ARG GATE_RUN
|
||||
RUN echo "lint run: ${GATE_RUN}"; golangci-lint run --config .golangci.yml ./...
|
||||
Reference in New Issue
Block a user