Run all linting in Docker via Dockerfile.lint (closes #188)
Check / check (pull_request) Successful in 1m29s
Check / check (pull_request) Successful in 1m29s
Per the owner ruling, linting now runs only inside Docker with the pinned golangci-lint (v2.12.2). A root Dockerfile.lint runs the linter as a build step; script/lint just builds it. A GATE_RUN build arg forces the lint layer to execute every run so a cached build cannot report a false clean. script/bootstrap no longer installs golangci-lint (the goimports install stays). The main Dockerfile lint stage calls golangci-lint directly (no docker-in-docker) and still gates the build. config verify is omitted because it fetches its schema over an unpinned HTTPS call. Model: opus-4-8
This commit was merged in pull request #200.
This commit is contained in:
+14
-2
@@ -1,12 +1,24 @@
|
||||
#!/bin/sh
|
||||
# script/lint: run the linter.
|
||||
# script/lint: run golangci-lint. The linter is never installed on the
|
||||
# host; it runs only inside Docker, from the pinned image in
|
||||
# Dockerfile.lint, so every run uses the same linter version everywhere.
|
||||
# Linting is a build step there, so a successful build is a clean lint.
|
||||
#
|
||||
# GATE_RUN differs every run so the lint layer always executes; a cached
|
||||
# build would otherwise exit 0 in under a second having linted nothing.
|
||||
# --output=type=cacheonly discards the image and keeps only build cache,
|
||||
# so no tagged image is left behind.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
golangci-lint run --config .golangci.yml ./...
|
||||
docker build \
|
||||
--build-arg GATE_RUN="$(date +%s)-$$" \
|
||||
--output=type=cacheonly \
|
||||
-f Dockerfile.lint \
|
||||
.
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
Reference in New Issue
Block a user