Skip to content

ci(prek): protect main and versions/ branches from direct commits - #64

Merged
nstarman merged 11 commits into
mainfrom
add-no-commit-to-branch-prek
Sep 15, 2026
Merged

nstarman merged 11 commits into
mainfrom
add-no-commit-to-branch-prek

Conversation

@nstarman

Copy link
Copy Markdown
Contributor

Summary

  • Adds the no-commit-to-branch hook from pre-commit-hooks to .pre-commit-config.yaml
  • Protects main (--branch main) and any versions/* maintenance branch (--pattern ^versions/.*) from direct commits

Test plan

  • Verified locally with prek run no-commit-to-branch --all-files on branches named main and versions/vTest (fails as expected) and on a feature branch (passes)

🤖 Generated with Claude Code

Adds the no-commit-to-branch hook from pre-commit-hooks, blocking
direct commits to main and any versions/* branch.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nstarman nstarman added this to the v0.6.0 milestone Sep 15, 2026
This was referenced Sep 15, 2026
always_run is already the hook's shipped default, but setting it
explicitly documents that this hook intentionally ignores any
files/exclude/types filtering (and would still allow --allow-empty
commits through).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@github-actions github-actions Bot added 👷 Add / update CI build system Add or update CI build system. 🔧 Add / update configuration Add or update configuration files. labels Sep 15, 2026
no-commit-to-branch would otherwise fail every push to main once this
merges: CI checks out a real local branch literally named `main` for
push events, so the hook would always fire. It's a client-side guard
for a human running `git commit`/`git push` locally (or via installed
git hooks) -- not something a full "run every hook" CI invocation
should re-evaluate after the fact. Skips it there via
SKIP=no-commit-to-branch; the hook itself is untouched and still fully
active locally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nstarman
nstarman force-pushed the add-no-commit-to-branch-prek branch from 7ed7f84 to 3cefbba Compare September 15, 2026 15:28
nstarman and others added 8 commits September 15, 2026 11:40
…anch

Appends no-commit-to-branch to any SKIP a developer already has set
(e.g. via their shell) rather than overwriting it wholesale, matching
the same fix applied in response to Copilot review feedback on
GalacticDynamics/coordinax#885.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
With default_stages: [pre-commit, pre-push] set repo-wide, this hook
would also run on pre-push. It checks the currently checked-out
branch, not the ref being pushed, so a maintainer sitting on main and
pushing a release tag (or anything else) would be blocked even though
they aren't committing to main. Restricting to stages: [pre-commit]
keeps the guard at the point it's meant for -- a local `git commit` --
without touching pre-push at all.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
prek's --skip flag replaces the SKIP env var rather than merging with
it (verified: `SKIP=x prek run --skip y` runs x's hooks anyway), so it
can silently drop a SKIP a caller already set -- the same clobbering
bug already fixed for the SKIP env var itself. Standardizes on SKIP
everywhere in the org (nox sessions and CI steps alike) instead of
mixing the two mechanisms.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addresses Copilot review feedback on GalacticDynamics/galax#847: the
comment said "CI checks out the real main branch," but the skip
applies unconditionally, including local `nox -s lint` runs -- which
is correct (a CI-only skip would leave the same false failure for any
local dev running the full suite while on `main`). Fixes the wording
to match the actual, intended behavior instead of narrowing it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addresses Copilot review feedback on GalacticDynamics/galax#847: this
comment still said no-commit-to-branch guards `git push`, but the
earlier stages: [pre-commit] fix means it no longer runs on push at
all. Clarifies that explicitly instead of leaving stale wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addresses Copilot review feedback on GalacticDynamics/galax#847: this
comment still said no-commit-to-branch guards `git push`, but the
earlier stages: [pre-commit] fix means it no longer runs on push at
all. Clarifies that explicitly instead of leaving stale wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
… trigger

Addresses Copilot review feedback on GalacticDynamics/galax#847: "it
never fires on push" reads as a claim about this workflow's own
`on: push:` trigger (which is false -- that's why the SKIP exists at
all), when it actually means the git pre-push hook stage. Spells that
out explicitly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The archaeology (why pre-commit's nodeenv/pyyaml floors mattered, why
--skip clobbers, the full CI-checkout explanation) belongs in commit
history, not permanently inline. Keeps just enough to orient a future
reader without re-litigating the whole investigation.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nstarman
nstarman merged commit a22cd0e into main Sep 15, 2026
23 checks passed
@nstarman
nstarman deleted the add-no-commit-to-branch-prek branch September 15, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

👷 Add / update CI build system Add or update CI build system. 🔧 Add / update configuration Add or update configuration files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant