Skip to content

ci(pre-commit): protect main and versions/ branches from direct commits - #93

Merged
nstarman merged 5 commits into
mainfrom
add-no-commit-to-branch
Sep 15, 2026
Merged

nstarman merged 5 commits into
mainfrom
add-no-commit-to-branch

Conversation

@nstarman

Copy link
Copy Markdown
Contributor

Summary

  • Adds the no-commit-to-branch hook from pre-commit-hooks to .pre-commit-config.yaml
  • Protects main (--branch main) and any versions/* maintenance branch (--pattern ^versions/.*) from direct commits
  • Runs both locally (pre-commit run) and on pre-commit.ci

Test plan

🤖 Generated with Claude Code

Adds the no-commit-to-branch hook from pre-commit-hooks, blocking
direct commits to main and any versions/* branch. Runs on pre-commit.ci
and locally via `pre-commit run`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 15, 2026 14:24
@codspeed

codspeed Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 12 untouched benchmarks


Comparing add-no-commit-to-branch (6fa7ba1) with main (506f353)

Open in CodSpeed

@codecov

codecov Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (506f353) to head (6fa7ba1).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff            @@
##              main       #93   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           12        12           
  Lines          290       290           
=========================================
  Hits           290       290           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is a minimal, low-risk pre-commit configuration update with no evident correctness or maintenance issues.

Pull request overview

Adds a pre-commit guard to prevent accidental direct commits to protected branches, reinforcing the project’s branching workflow via local pre-commit and pre-commit.ci configuration.

Changes:

  • Added the no-commit-to-branch hook from pre-commit-hooks.
  • Configured it to block commits directly to main and any versions/* branch via a regex pattern.
File summaries
File Description
.pre-commit-config.yaml Adds no-commit-to-branch hook to prevent direct commits to main and versions/* branches.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

nstarman and others added 2 commits September 15, 2026 10:33
always_run is already the hook's shipped default, but setting it
explicitly documents that this hook intentionally ignores any
files/exclude/types filtering (and would still allow --allow-empty
commits through).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
no-commit-to-branch would otherwise fail every push to main once this
merges: CI checks out a real local branch literally named `main` for
push events, so the hook would always fire. It's a client-side guard
for a human running `git commit`/`git push` locally (or via installed
git hooks) -- not something a full "run every hook" CI invocation
should re-evaluate after the fact. Skips it there via
SKIP=no-commit-to-branch; the hook itself is untouched and still fully
active locally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the 🔧 Add / update configuration Add or update configuration files. label Sep 15, 2026
nstarman and others added 2 commits September 15, 2026 11:43
…anch

Appends no-commit-to-branch to any SKIP a developer already has set
(e.g. via their shell) rather than overwriting it wholesale, matching
the same fix applied in response to Copilot review feedback on
GalacticDynamics/coordinax#885.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addresses Copilot review feedback on GalacticDynamics/galax#847: the
comment said "CI checks out the real main branch," but the skip
applies unconditionally, including local `nox -s lint` runs -- which
is correct (a CI-only skip would leave the same false failure for any
local dev running the full suite while on `main`). Fixes the wording
to match the actual, intended behavior instead of narrowing it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nstarman nstarman added this to the v0.10.0 milestone Sep 15, 2026
@nstarman
nstarman merged commit 1d78fb7 into main Sep 15, 2026
26 checks passed
@nstarman
nstarman deleted the add-no-commit-to-branch branch September 15, 2026 20:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🔧 Add / update configuration Add or update configuration files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants