golangci-lint now runs only in Docker. New Dockerfile.lint (pinned
golangci-lint v2.12.2) COPYs the tree and runs the linter as a build
step; script/lint just builds it. A GATE_RUN build arg differs every
run, so the lint layer always executes -- a cached build would exit 0
having linted nothing.
config verify is deliberately omitted: it fetches its JSON schema over
an unpinned live HTTPS call, which REPO_POLICIES.md forbids.
script/bootstrap no longer installs golangci-lint (goimports kept). The
main Dockerfile lint stage now invokes golangci-lint directly rather
than make lint, so building it is not docker-in-docker.
Model: opus-4-8