Skip to content

ci(pre-commit): protect main and versions/ branches from direct commits - #845

Merged
nstarman merged 2 commits into
mainfrom
add-no-commit-to-branch
Sep 15, 2026
Merged

nstarman merged 2 commits into
mainfrom
add-no-commit-to-branch

Conversation

@nstarman

Copy link
Copy Markdown
Contributor

Summary

  • Adds the no-commit-to-branch hook from pre-commit-hooks to .pre-commit-config.yaml
  • Protects main (--branch main) and any versions/* maintenance branch (--pattern ^versions/.*) from direct commits
  • Runs both locally (pre-commit run) and on pre-commit.ci

Test plan

🤖 Generated with Claude Code

Adds the no-commit-to-branch hook from pre-commit-hooks, blocking
direct commits to main and any versions/* branch. Runs on pre-commit.ci
and locally via `pre-commit run`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 15, 2026 14:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is minimal, correctly scoped to the pre-commit-hooks repo at a recent pinned rev, and introduces no behavioral risk beyond the intended branch-commit protection.

Pull request overview

Adds a pre-commit safeguard to prevent developers from making direct local commits onto protected branches (main and versions/*), aligning local workflows with typical branch protection policies and reducing accidental bypass of PR review.

Changes:

  • Add no-commit-to-branch hook (from pre-commit-hooks) to block direct commits to main.
  • Extend the protection to any maintenance branch matching ^versions/.*.
  • Ensure this runs both locally via pre-commit and in pre-commit.ci runs.
File summaries
File Description
.pre-commit-config.yaml Adds no-commit-to-branch hook args to protect main and versions/* branches from direct commits.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

always_run is already the hook's shipped default, but setting it
explicitly documents that this hook intentionally ignores any
files/exclude/types filtering (and would still allow --allow-empty
commits through).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 15, 2026 14:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is a small, correctly-scoped pre-commit configuration update with low risk and clear intent.

Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@nstarman nstarman added this to the v0.1.0 milestone Sep 15, 2026
@nstarman
nstarman merged commit 22bec59 into main Sep 15, 2026
16 checks passed
@nstarman
nstarman deleted the add-no-commit-to-branch branch September 15, 2026 14:50
@codecov

codecov Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.32%. Comparing base (4d42faf) to head (d47dadf).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #845   +/-   ##
=======================================
  Coverage   96.32%   96.32%           
=======================================
  Files         164      164           
  Lines        6769     6769           
=======================================
  Hits         6520     6520           
  Misses        249      249           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants