Skip to content

ci(pre-commit): protect main and versions/ branches from direct commits - #54

Merged
nstarman merged 7 commits into
mainfrom
add-no-commit-to-branch
Sep 15, 2026
Merged

nstarman merged 7 commits into
mainfrom
add-no-commit-to-branch

Conversation

@nstarman

Copy link
Copy Markdown
Contributor

Summary

  • Adds the no-commit-to-branch hook from pre-commit-hooks to .pre-commit-config.yaml
  • Protects main (--branch main) and any versions/* maintenance branch (--pattern ^versions/.*) from direct commits
  • Runs both locally (pre-commit run) and on pre-commit.ci

Test plan

🤖 Generated with Claude Code

Adds the no-commit-to-branch hook from pre-commit-hooks, blocking
direct commits to main and any versions/* branch. Runs on pre-commit.ci
and locally via `pre-commit run`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 15, 2026 14:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is minimal, correctly configured for the existing pre-commit-hooks repo entry, and matches the stated PR intent without introducing code/runtime risk.

Pull request overview

This PR strengthens contributor workflow safeguards by adding a pre-commit hook that blocks direct commits to protected branches, aligning with the repository’s CI + local pre-commit usage.

Changes:

  • Add no-commit-to-branch (from pre-commit-hooks) to prevent committing directly to main.
  • Extend branch protection to maintenance branches matching versions/* via a regex pattern.
File summaries
File Description
.pre-commit-config.yaml Adds no-commit-to-branch hook configured to protect main and versions/* branches from direct commits.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

nstarman and others added 6 commits September 15, 2026 10:33
always_run is already the hook's shipped default, but setting it
explicitly documents that this hook intentionally ignores any
files/exclude/types filtering (and would still allow --allow-empty
commits through).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
no-commit-to-branch would otherwise fail every push to main once this
merges: CI checks out a real local branch literally named `main` for
push events, so the hook would always fire. It's a client-side guard
for a human running `git commit`/`git push` locally (or via installed
git hooks) -- not something a full "run every hook" CI invocation
should re-evaluate after the fact. Skips it there via
SKIP=no-commit-to-branch; the hook itself is untouched and still fully
active locally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…anch

Appends no-commit-to-branch to any SKIP a developer already has set
(e.g. via their shell) rather than overwriting it wholesale, matching
the same fix applied in response to Copilot review feedback on
GalacticDynamics/coordinax#885.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
With default_stages: [pre-commit, pre-push] set repo-wide, this hook
would also run on pre-push. It checks the currently checked-out
branch, not the ref being pushed, so a maintainer sitting on main and
pushing a release tag (or anything else) would be blocked even though
they aren't committing to main. Restricting to stages: [pre-commit]
keeps the guard at the point it's meant for -- a local `git commit` --
without touching pre-push at all.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addresses Copilot review feedback on GalacticDynamics/galax#847: the
comment said "CI checks out the real main branch," but the skip
applies unconditionally, including local `nox -s lint` runs -- which
is correct (a CI-only skip would leave the same false failure for any
local dev running the full suite while on `main`). Fixes the wording
to match the actual, intended behavior instead of narrowing it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The archaeology (why pre-commit's nodeenv/pyyaml floors mattered, why
--skip clobbers, the full CI-checkout explanation) belongs in commit
history, not permanently inline. Keeps just enough to orient a future
reader without re-litigating the whole investigation.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nstarman nstarman added this to the v0.4.0 milestone Sep 15, 2026
@nstarman
nstarman merged commit c208ced into main Sep 15, 2026
17 checks passed
@nstarman
nstarman deleted the add-no-commit-to-branch branch September 15, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants