Re-vendor the canonical files from sneak/prompts at dd4027b (closes #213)
check / check (push) Successful in 18m13s

Linting and testing become the lint and test phases of the Dockerfile,
and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and
the tests that checked them are removed. Every docker build in script/
passes --no-cache, and script/cibuild runs script/bootstrap first. A
host without Go gets the go.mod version from script/install-go in
.tool/go, where script/fmt and script/fmt-check also look; fmt-check
reads only the Go files git lists. The image takes its version from the
VERSION build arg or git describe, dev without .git. This repo's own
entries follow the canonical content in .gitignore and .editorconfig.
The golangci-lint v2.14.0 findings are fixed. The rules in CLAUDE.md
move into AGENTS.md. IsDevVersion counts "unknown".

Model: opus-5-5
This commit is contained in:
2026-10-06 04:27:37 +00:00
parent 713be502bd
commit d98b1a55db
38 changed files with 848 additions and 1204 deletions
+9 -8
View File
@@ -4,12 +4,13 @@
# own extension to scripts-to-rule-them-all. Idempotent: exits at once
# when the pinned toolchain is already installed.
#
# Only .gitea/workflows/release.yml calls this. goreleaser is not a
# .gitea/workflows/release.yml calls this, and so does script/bootstrap
# when the host has no Go, as on the check runner. goreleaser is not a
# compiler: it shells out to `go` for the `before:` hook and for every
# one of the four cross-compiles, so the release runner needs a Go
# toolchain on PATH. check.yml never does -- it builds inside the
# digest-pinned Dockerfile images -- so this is the release path's only
# host Go, and per REPO_POLICIES.md it must be pinned by hash.
# toolchain on PATH. The check runner compiles nothing on the host; it
# uses this Go only for bootstrap's `go mod download` and for gofmt in
# script/fmt-check. Per REPO_POLICIES.md a host Go is pinned by hash.
# actions/setup-go exposes no checksum input, so Go is installed the way
# script/install-goreleaser installs goreleaser: download the exact
# archive from go.dev and refuse it unless its sha256 matches the value
@@ -18,11 +19,11 @@
# The version is go.mod's `go` directive, the single source of truth for
# the toolchain. GO_VERSION below MUST equal it, and this script fails
# when they disagree -- so bumping Go is one reviewed change touching
# go.mod, the checksum here, and the Dockerfile golang digest together.
# go.mod, the checksum here, and the Dockerfile's two golang digests
# together.
#
# Linux only, because that is what the release runner is. A darwin dev
# building a snapshot uses their own Go; supporting an OS means adding
# its checksums.
# Linux only, because that is what both runners are. A darwin dev uses
# their own Go; supporting an OS means adding its checksums.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"