ESLint, pinned by package.json and yarn.lock, runs in a new js-lint
stage of the Dockerfile on the pinned node 24 LTS image. script/lint
builds that stage after the Go lint, and the build stage depends on it,
so make check and the image build both fail on a violation.
eslint.config.mjs turns on the styleguide's checkable rules: no-var and
prefer-const.
Model: opus-5-5