check / check (pull_request) Failing after 1s
The guard test's shell scanner was weaker than its commit message claimed. Two holes are closed. shellCode now treats `<<` as a here-document only when it is a real redirection: outside single and double quotes, not past an unquoted word-initial `#` that begins an inline comment, and followed by a delimiter word. A `<<` inside a quoted string or an inline comment no longer opens a phantom here-document that swallows the rest of the file -- including the silent case where the fake terminator recurs later as a line of its own -- and a here-document still open at end of file is a loud error rather than a silent truncation. assertLinterIsContainerised now cuts the joined line into the simple commands the shell would run -- on `;`, `&&`, `||` and `|` -- and requires the command that names the linter to begin with docker. So `docker info; golangci-lint run` and `docker info || golangci-lint run` are rejected, while script/lint-fix's `docker run ... golangci-lint` still passes. The scanner comment now names the inline-comment exception alongside the quoted-string and arithmetic ones, and the inherent limits of a text scan. Dockerfile.lint's citation is corrected from `lll` to `revive`, the finding the recorded evidence actually named. model: claude-opus-4-8