All checks were successful
check / check (push) Successful in 6s
script/lint ran bare golangci-lint from PATH while CI and the Dockerfile pinned v2.12.2 by digest, so make lint and CI could disagree about findings. That drift ran both directions: it produced two false green claims during the lint remediation, and on an ambient 2.10.1 it also reported four gosec findings on a tree CI linted clean. script/lint now extracts the image reference - tag and digest - from the Dockerfile lint stage FROM line and runs that exact image under docker. The Dockerfile FROM line is the single source of truth for the linter version; the duplicate pins in the Makefile deps target and in script/bootstrap are removed rather than kept in sync. A golangci-lint on PATH is used only when its version exactly equals the pin, which is what makes the in-container lint stage work (the Dockerfile runs make lint inside the pinned image, where there is no docker daemon). Any other version, or none, goes through docker. When docker is unavailable the script fails with an actionable message and never falls back to a different linter version. script/lint-fix delegates to script/lint --fix so autofixes come from the pinned linter too. The container mounts persistent build and module caches and runs as the invoking uid/gid. Verified by reinstating the four historical nolint directives that 2.10.1 requires and 2.12.2 reports as unused: the old script passed on that tree and the new one fails with four nolintlint findings.
98 lines
2.4 KiB
Makefile
98 lines
2.4 KiB
Makefile
.PHONY: all bootstrap setup check test lint lint-fix fmt fmt-check build clean deps test-coverage test-integration local install release release-snapshot docker hooks
|
||
|
||
# Version number
|
||
VERSION := 1.0.0-rc.1
|
||
|
||
# Build variables
|
||
GIT_REVISION := $(shell git rev-parse HEAD 2>/dev/null || echo "unknown")
|
||
GIT_COMMIT_DATE := $(shell git show -s --format=%cs HEAD 2>/dev/null || echo "unknown")
|
||
|
||
# Linker flags
|
||
LDFLAGS := -X 'sneak.berlin/go/vaultik/internal/globals.Version=$(VERSION)' \
|
||
-X 'sneak.berlin/go/vaultik/internal/globals.Commit=$(GIT_REVISION)' \
|
||
-X 'sneak.berlin/go/vaultik/internal/globals.CommitDate=$(GIT_COMMIT_DATE)'
|
||
|
||
# Default target
|
||
all: vaultik
|
||
|
||
# Install all development dependencies.
|
||
bootstrap:
|
||
@script/bootstrap
|
||
|
||
# Prepare a fresh clone: bootstrap plus pre-commit hook.
|
||
setup:
|
||
@script/setup
|
||
|
||
# Combined pre-commit/CI gate: tests, lint, format check.
|
||
check:
|
||
@script/check
|
||
|
||
# Run tests only.
|
||
test:
|
||
@script/test
|
||
|
||
# Check if code is formatted (read-only).
|
||
fmt-check:
|
||
@script/fmt-check
|
||
|
||
# Format code.
|
||
fmt:
|
||
@script/fmt
|
||
|
||
# Run linter only.
|
||
lint:
|
||
@script/lint
|
||
|
||
# Apply the linter's autofixes (rewrites files).
|
||
lint-fix:
|
||
@script/lint-fix
|
||
|
||
# Build binary.
|
||
vaultik: internal/*/*.go cmd/vaultik/*.go
|
||
go build -ldflags "$(LDFLAGS)" -o $@ ./cmd/vaultik
|
||
|
||
# Clean build artifacts.
|
||
clean:
|
||
rm -f vaultik
|
||
go clean
|
||
|
||
# Install dependencies. The linter is deliberately not installed here:
|
||
# script/lint runs the digest-pinned golangci-lint image declared by the
|
||
# Dockerfile's lint stage, which is the single source of truth for the
|
||
# linter version. A second, separately pinned copy on PATH could drift
|
||
# from it and make a local `make lint` disagree with CI.
|
||
deps:
|
||
go mod download
|
||
|
||
# Run tests with coverage.
|
||
test-coverage:
|
||
go test -v -coverprofile=coverage.out ./...
|
||
go tool cover -html=coverage.out -o coverage.html
|
||
|
||
# Run integration tests.
|
||
test-integration:
|
||
go test -v -tags=integration ./...
|
||
|
||
local:
|
||
VAULTIK_CONFIG=$(HOME)/etc/vaultik/config.yml ./vaultik snapshot --debug list 2>&1
|
||
VAULTIK_CONFIG=$(HOME)/etc/vaultik/config.yml ./vaultik snapshot --debug create 2>&1
|
||
|
||
install: vaultik
|
||
cp ./vaultik $(HOME)/bin/
|
||
|
||
# Build and publish release artifacts (linux/darwin × amd64/arm64) via goreleaser.
|
||
release:
|
||
goreleaser release --clean
|
||
|
||
# Dry-run a release build without publishing or tagging.
|
||
release-snapshot:
|
||
goreleaser release --clean --snapshot
|
||
|
||
# Build Docker image.
|
||
docker:
|
||
@script/docker
|
||
|
||
# Install pre-commit hook.
|
||
hooks:
|
||
@script/install-precommit
|