Check / check (pull_request) Successful in 1m29s
Per the owner ruling, linting now runs only inside Docker with the pinned golangci-lint (v2.12.2). A root Dockerfile.lint runs the linter as a build step; script/lint just builds it. A GATE_RUN build arg forces the lint layer to execute every run so a cached build cannot report a false clean. script/bootstrap no longer installs golangci-lint (the goimports install stays). The main Dockerfile lint stage calls golangci-lint directly (no docker-in-docker) and still gates the build. config verify is omitted because it fetches its schema over an unpinned HTTPS call. Model: opus-4-8