repo: add LICENSE, THIRD_PARTY.md, .dockerignore, hadolint lint, IDEAS backlog
Repo/CI hygiene batch (none base-affecting; image contents unchanged): - LICENSE: actual MIT file (repo previously declared MIT only in prose). - THIRD_PARTY.md: notes bundled software + licenses (pi/pi-fork/pi-obsmem/ pi-studio MIT, gosu Apache-2.0, Debian packages under their own terms). - .dockerignore: trims build context to what the Dockerfiles COPY (rootfs/ + entrypoint*.sh); keeps .git/docs/scripts/compose out. Verified it excludes none of the required COPY sources. - lint.yml: new hadolint job (pinned v2.14.0) lints both Dockerfiles; .hadolint.yaml grandfathers deliberate choices (DL3008/DL3016/DL4006/DL3003/ SC2086, mirroring the shellcheck excludes), fails on anything new at warning+. Verified hadolint exit 0 and the repo shell-guard passes with the new job. - IDEAS.md: parks deferred follow-ups (SHA-pin actions, trivy, buildx SBOM/ provenance, Makefile, renovate). - README/DOCKER_HUB License sections now link LICENSE + THIRD_PARTY.md. No tag.
This commit is contained in:
@@ -33,6 +33,29 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
|
||||
overridden per-user (`:set notermguicolors`, or your own init). Base-affecting
|
||||
(`Dockerfile.base` apt package + COPY), rebuilds `base-<hash>`.
|
||||
|
||||
- **Repository hygiene: `LICENSE`, `THIRD_PARTY.md`, and `.dockerignore`.** The
|
||||
repo declared MIT only in prose; it now ships an actual `LICENSE` file (MIT,
|
||||
© Joakim Persson) plus `THIRD_PARTY.md` recording that the published images
|
||||
bundle third-party software under its own terms (pi, pi-fork,
|
||||
pi-observational-memory, pi-studio — all MIT; gosu Apache-2.0; Debian packages
|
||||
under their respective licenses). A new `.dockerignore` trims the build
|
||||
context to what the Dockerfiles actually `COPY` (`rootfs/` + `entrypoint*.sh`),
|
||||
keeping `.git`, docs, `scripts/`, and compose files out — cheaper context and
|
||||
no risk of a future broad `COPY` pulling in `.git`. Not base-affecting (the
|
||||
base hash covers only `Dockerfile.base` + `rootfs/` + `entrypoint*.sh`);
|
||||
image contents are byte-identical.
|
||||
|
||||
- **Dockerfile linting (`hadolint`) in CI, plus an `IDEAS.md` backlog.** The
|
||||
lint workflow already ran actionlint + shellcheck on `run:` steps but never
|
||||
looked at the two Dockerfiles that are the heart of the project. A new
|
||||
`hadolint` job (pinned v2.14.0, same download-pin pattern as actionlint) lints
|
||||
`Dockerfile.base` and `Dockerfile.variant`; `.hadolint.yaml` grandfathers the
|
||||
deliberate choices (unpinned apt/npm, `cd`-in-`RUN`, `SC2086` — mirroring the
|
||||
existing shellcheck excludes) and fails on anything new at `warning`+.
|
||||
`IDEAS.md` parks the vetted-but-unscheduled follow-ups (SHA-pin CI actions,
|
||||
trivy scanning, buildx SBOM/provenance attestations, a local `Makefile`,
|
||||
renovate). Repo/CI only — not baked into the image.
|
||||
|
||||
### Changed
|
||||
|
||||
- **`-studio` images now pin pi-studio to its newest *semver tag* instead of
|
||||
|
||||
Reference in New Issue
Block a user