diff --git a/Dockerfile b/Dockerfile index aa67919..86356dc 100644 --- a/Dockerfile +++ b/Dockerfile @@ -37,6 +37,15 @@ FROM golang:alpine AS go-toolchain # Build Go tools natively on the host platform using Go's cross-compilation. # This avoids QEMU emulation for arm64 and reduces compile time from hours to minutes. +# +# staticcheck is pinned to @master, not @latest, as a temporary measure: the +# latest tagged release (2026.2.1) bundles an x/tools importer that only reads +# export-data format up to version 4, but the latest Go release now emits +# version 5, so the tagged binary fails every run with "export data version 5 +# is greater than maximum supported version 4". go-tools' master branch +# already has the fix (bumped its x/tools dependency to v0.51.0 for unified v5 +# export data support) but no new tag has shipped yet. Switch this back to +# staticcheck@latest once dominikh/go-tools cuts a release containing that fix. FROM --platform=$BUILDPLATFORM golang:alpine AS go-tools ARG TARGETOS=linux ARG TARGETARCH @@ -53,7 +62,8 @@ RUN GOOS=${TARGETOS} GOARCH=${TARGETARCH} go install golang.org/x/tools/cmd/goim GOOS=${TARGETOS} GOARCH=${TARGETARCH} go install google.golang.org/protobuf/cmd/protoc-gen-go@latest && \ GOOS=${TARGETOS} GOARCH=${TARGETARCH} go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest && \ GOOS=${TARGETOS} GOARCH=${TARGETARCH} go install github.com/google/go-licenses@latest && \ - GOOS=${TARGETOS} GOARCH=${TARGETARCH} go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest + GOOS=${TARGETOS} GOARCH=${TARGETARCH} go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest && \ + GOOS=${TARGETOS} GOARCH=${TARGETARCH} go install honnef.co/go/tools/cmd/staticcheck@master FROM ${PULL_URL}:${DISTRO_VERSION} AS build ARG TZ diff --git a/rootfs/root/docker/setup/05-custom.sh b/rootfs/root/docker/setup/05-custom.sh index 9db6485..87391e5 100755 --- a/rootfs/root/docker/setup/05-custom.sh +++ b/rootfs/root/docker/setup/05-custom.sh @@ -156,12 +156,6 @@ __install_tar \ curl -fsSL https://raw.githubusercontent.com/golangci/golangci-lint/HEAD/install.sh \ | sh -s -- -b "${CUSTOM_GOBIN_DIR}" latest -# staticcheck — standalone advanced static analyser (linux_amd64 / linux_arm64) -_SC_VER="$(__gh_latest dominikh/go-tools)" -__install_tar \ - "https://github.com/dominikh/go-tools/releases/download/${_SC_VER}/staticcheck_linux_${_GOARCH}.tar.gz" \ - "staticcheck" - # gofumpt — stricter formatter; asset name includes version: gofumpt_v0.x.y_linux_amd64 _GF_VER="$(__gh_latest mvdan/gofumpt)" __install_bin \ @@ -202,9 +196,10 @@ __install_bin \ "goose" # go install tools (goimports, stringer, gopls, govulncheck, dlv, gops, benchstat, -# wire, mockgen, protoc-gen-go, protoc-gen-go-grpc) are cross-compiled natively on -# the build platform in the Dockerfile go-tools stage and copied to /usr/local/bin -# before this script runs — no QEMU-emulated compilation needed here. +# wire, mockgen, protoc-gen-go, protoc-gen-go-grpc, go-licenses, cyclonedx-gomod, +# staticcheck) are cross-compiled natively on the build platform in the Dockerfile +# go-tools stage and copied to /usr/local/bin before this script runs — no +# QEMU-emulated compilation needed here. # Strip the module download cache and ephemeral build cache from this layer go clean -modcache