Check / check (pull_request) Skipped
golangci-lint now runs only in Docker. New Dockerfile.lint (pinned golangci-lint v2.12.2) COPYs the tree and runs the linter as a build step; script/lint just builds it. A GATE_RUN build arg differs every run, so the lint layer always executes -- a cached build would exit 0 having linted nothing. config verify is deliberately omitted: it fetches its JSON schema over an unpinned live HTTPS call, which REPO_POLICIES.md forbids. script/bootstrap no longer installs golangci-lint (goimports kept). The main Dockerfile lint stage now invokes golangci-lint directly rather than make lint, so building it is not docker-in-docker. Model: opus-4-8