Commit Graph
4 Commits
Author SHA1 Message Date
clawbot 3bba2df314 Re-vendor the shared files from sneak/prompts at dd4027b (closes #504)
check / check (push) Failing after 6s
Fetches the shared files unchanged from sneak/prompts commit dd4027b and
adds .prettierignore; .dockerignore keeps this repository's anchored host
artifacts at its end.

Linting moves into the Dockerfile's lint phase on the golangci-lint
v2.14.0 image, which also runs the js-lint stage, and Dockerfile.lint is
gone. Tests move into a test phase on the golang bookworm image.
script/lint, test, docker and cibuild are the model scripts, every docker
build in script/ passes --no-cache, and the .ci-fingerprint barrier is
gone. The workflow no longer calls script/ci-mark-superseded, so it and
its tests are removed. make build passes -trimpath and -s -w.

Model: opus-5-5
2026-10-06 01:27:27 +00:00
clawbot 74a96b2226 Lint static/js/ with ESLint in Docker (closes #120)
check / check (push) Successful in 3m50s
`REPO_POLICIES.md` binds the repo to a JavaScript styleguide, but nothing checked `static/js/`. ESLint, pinned by `package.json` and `yarn.lock`, now lints it with the styleguide's two checkable rules, `no-var` and `prefer-const`. It runs only in Docker on a digest-pinned node image: a `js-deps` stage installs ESLint and stays cached until the manifests change, and a `js-lint` stage runs it. `script/lint` builds `js-lint`, so `make lint` and `make check` fail on a violation, and the image build depends on it as on the repo's other checks. ESLint, node and yarn are not prerequisites, and `make lint` never uses a host copy.

Model: opus-5-5
2026-10-03 04:24:11 +02:00
clawbot 992b3c68f5 Run all linting in Docker via Dockerfile.lint (closes #109)
check / check (push) Successful in 2m45s
golangci-lint no longer runs on the host. script/lint builds
Dockerfile.lint, which copies the repo into the digest-pinned linter
image, so the container holds only this repo and the cross-worktree
cache contamination of #106 becomes structurally impossible rather than
filtered after the fact. Five workers hit that contamination in one
evening, in both directions.

Three properties are load-bearing. --no-cache-filter=lint forces the
lint stage to re-execute while deps keeps its cache, because a cached
build lints nothing in 0.27s and exits 0. script/lint does not trust
that flag, since Docker silently ignores an unmatched stage name: it
asserts golangci-lint's own summary line appears, so no summary means no
lint whatever the exit code says. And both lint steps run
--network=none, which enforces rather than assumes that config verify
does not fetch its schema — verify is kept, because golangci-lint run
silently ignores unrecognized config keys and it is the only thing that
catches a typo that disables a setting.

Independently reviewed four times. Three passed the behaviour; the
remaining rounds were a README merge against #151, whose premise was
that the file contains no false statements. Six statements this change
falsified were found and corrected across those rounds — the last
reviewer re-derived every countable claim against the tree rather than
reading for plausibility, and found no seventh.

Supersedes #106.
2026-08-18 01:07:16 +02:00
sneak 2cc8723997 scripts-to-rule-them-all (#59)
check / check (push) Successful in 4s
Reviewed-on: #59
Co-authored-by: sneak <sneak@sneak.berlin>
Co-committed-by: sneak <sneak@sneak.berlin>
2026-07-07 02:14:09 +02:00