# Browser test image, built by script/test-browser (make test-browser). It # runs the test in internal/server that loads the pages in a headless # browser under the real Content-Security-Policy. That test is built only # with the browser build tag, so make test leaves it out. Here the browser # comes from a digest-pinned image, and if it is missing the test fails. # golang:1.26.1-bookworm, 2026-03-17: the builder stage's image in Dockerfile. FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a3492282a6c820bf4755fd64a4 AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . # The test binary embeds the templates and static files, so the browser # stage needs nothing else. -p 4 keeps the compile's memory down, as in # script/test. RUN make assets && go test -c -p 4 -tags browser -o /browser.test ./internal/server # chromedp/headless-shell:151.0.7922.109 (Debian trixie), 2026-08-11. The # browser is on PATH as headless-shell, where the test's browser library # looks for it. FROM chromedp/headless-shell:151.0.7922.109@sha256:2d349b544a1ea6b5b5fd7c0fe99215ff662339c57407ee2e8c0a11af93516b04 AS browser COPY --from=build /browser.test /browser.test RUN /browser.test -test.v -test.timeout 90s -test.run '^TestAlpineRunsUnderTheSecurityPolicy$'