fix(node-go): install golangci-lint directly, bypass install.sh checksum bug
node-go image / build (arm64) (push) Successful in 14s
node-go image / build (amd64) (push) Failing after 0s
node-go image / amend-manifest (push) Skipped

The official install.sh (master branch) fails checksum verification because it
matches the .tar.gz line against the .sbom.json checksum (the tarball filename
is a prefix of the sbom filename). The downloaded tarball is NOT corrupt - its
real sha256 matches the checksums file - install.sh just picks the wrong line.

Replace install.sh with a direct tarball download + extract, reusing the
existing go_arch variable. Consistent with how Go itself is installed in this
Dockerfile (no checksum verification either).

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-08-11 15:29:22 +07:00
co-authored by Claude
parent 5d37cee6af
commit ae32c66e82
+6 -4
View File
@@ -24,10 +24,12 @@ RUN set -eux; \
rm -rf /usr/local/go; \
tar -C /usr/local -xzf /tmp/go.tgz; \
rm -f /tmp/go.tgz; \
curl -fsSL -o /tmp/golangci-lint-install.sh \
"https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh"; \
sh /tmp/golangci-lint-install.sh -b /usr/local/bin "${GOLANGCI_LINT_VERSION}"; \
rm -f /tmp/golangci-lint-install.sh; \
gcl_ver="${GOLANGCI_LINT_VERSION#v}"; \
curl -fsSL -o /tmp/gcl.tgz \
"https://github.com/golangci/golangci-lint/releases/download/${GOLANGCI_LINT_VERSION}/golangci-lint-${gcl_ver}-${go_arch}.tar.gz"; \
tar -C /tmp -xzf /tmp/gcl.tgz; \
install -m 0755 "/tmp/golangci-lint-${gcl_ver}-${go_arch}/golangci-lint" /usr/local/bin/golangci-lint; \
rm -rf /tmp/gcl.tgz "/tmp/golangci-lint-${gcl_ver}-${go_arch}"; \
rm -rf /var/lib/apt/lists/*
WORKDIR /app