Problem
The detect-secrets pre-commit hook added in #16300 (.pre-commit-config.yaml:615-619) doesn't set require_serial: true, and neither does upstream's hook manifest (Yelp/detect-secrets v1.5.0 .pre-commit-hooks.yaml: id, name, entry: detect-secrets-hook, language: python, files: .*, nothing more).
pre-commit therefore runs detect-secrets-hook in parallel batches. Each batch process reads .secrets.baseline, updates the line numbers for its files, and writes the whole file back. The writers race, the last one wins, and every other batch's updates are lost. The hook then fails with "Please git add .secrets.baseline", and each retry keeps only a fraction of the needed updates.
Evidence (2026-09-11)
A base merge into #16199's branch, touching hundreds of files after #16300 regenerated the baseline, failed on this hook on every commit attempt:
- The pending rewrite shrank on each retry, from 167 lines to 111 lines, instead of settling in one pass. That's the signature of partial writes.
- Every rewrite changed only
line_number fields relative to base's baseline: no hashed secret, filename or type. So the rewrites were correct, just lost to the race.
- Any commit touching many baselined files, including every base merge, hits it. Smaller commits usually land in a single batch and pass.
Fix
Add require_serial: true to the detect-secrets hook entry in .pre-commit-config.yaml, which overrides upstream's manifest. It's one line, and it costs a little speed on large commits.
Acceptance criteria
Problem
The
detect-secretspre-commit hook added in #16300 (.pre-commit-config.yaml:615-619) doesn't setrequire_serial: true, and neither does upstream's hook manifest (Yelp/detect-secretsv1.5.0.pre-commit-hooks.yaml:id,name,entry: detect-secrets-hook,language: python,files: .*, nothing more).pre-commit therefore runs
detect-secrets-hookin parallel batches. Each batch process reads.secrets.baseline, updates the line numbers for its files, and writes the whole file back. The writers race, the last one wins, and every other batch's updates are lost. The hook then fails with "Pleasegit add .secrets.baseline", and each retry keeps only a fraction of the needed updates.Evidence (2026-09-11)
A base merge into #16199's branch, touching hundreds of files after #16300 regenerated the baseline, failed on this hook on every commit attempt:
line_numberfields relative to base's baseline: no hashed secret, filename or type. So the rewrites were correct, just lost to the race.Fix
Add
require_serial: trueto thedetect-secretshook entry in.pre-commit-config.yaml, which overrides upstream's manifest. It's one line, and it costs a little speed on large commits.Acceptance criteria
detect-secretshook entry hasrequire_serial: true..secrets.baselinein a single pass. Show it with a base merge that commits on its first attempt after staging the baseline once.require_serial: trueon any hook that rewrites a shared file (at leastdetect-secrets), so the setting can't be dropped silently.